CVE-2022-43680
HIGHlibexpat < 2.4.9 - Use-After-Free in XML_ExternalEntityParserCreate
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2022-43680. PoCs published by nidhihcl, Trinadh465.
AI-analyzed exploit summary This repository contains the Expat library version 2.1.0, which is vulnerable to CVE-2022-43680. The provided files include source code, build scripts, and documentation, but no explicit exploit code or proof-of-concept is present.
Description
In libexpat through 2.4.9, there is a use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations.
Exploits (2)
This repository contains the Expat library version 2.1.0, which is vulnerable to CVE-2022-43680. The provided files include source code, build scripts, and documentation, but no explicit exploit code or proof-of-concept is present.
This repository contains the source code for Expat 2.1.0, a C library for parsing XML, and includes documentation and build instructions. It does not contain exploit code or a proof-of-concept for CVE-2022-43680.
References (15)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H