CVE-2022-23852
CRITICALlibexpat < 2.4.4 - Integer Overflow in XML_GetBuffer
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2022-23852. PoCs published by Satheesh575555.
AI-analyzed exploit summary This repository appears to be a fork or snapshot of the Expat library (version 2.2.6) with references to CVE-2022-23852, but it lacks actual exploit code or a proof-of-concept. The files included are standard library and build configuration files.
Description
Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_CONTEXT_BYTES.
Exploits (1)
This repository appears to be a fork or snapshot of the Expat library (version 2.2.6) with references to CVE-2022-23852, but it lacks actual exploit code or a proof-of-concept. The files included are standard library and build configuration files.
References (8)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H