Multiple integer overflows in the XML_GetBuffer function in Expat through 2.1.0, as used in Google Chrome before 44.0.2403.89 and other products, allow remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted XML data, a related issue to CVE-2015-2716.
CVSS Details
- CVSS 3.1 Base Score: 7.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade expat | Sep 20, 2017 | Jul 22, 2015 |
| Apple Itunes | — | Upgrade Apple iTunes to the latest version | Mar 24, 2017 | Jul 22, 2015 |
| Debian | — | Upgrade expat | Jul 30, 2024 | Jul 23, 2015 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Oct 11, 2016 |
| Freebsd | — | Upgrade chromium-npapiUpgrade FreeBSDUpgrade chromium-pulseUpgrade chromium | Dec 10, 2025 | Jul 25, 2015 |
| Gentoo Linux | — | Upgrade dev-libs/expat.Upgrade www-client/chromium. | Oct 30, 2017 | Jul 22, 2015 |
| Google Chrome | — | Upgrade to the latest version of Google Chrome | Jul 27, 2015 | Jul 21, 2015 |
| Huawei Euleros 2_0_sp2 | — | Upgrade expat-develUpgrade expat | Jul 23, 2019 | Jul 23, 2015 |
| Huawei Euleros 2_0_sp3 | — | Upgrade expat-develUpgrade expat | Sep 25, 2019 | Jul 23, 2015 |
| Huawei Euleros 2_0_sp5 | — | Upgrade expat-develUpgrade expat | Jun 27, 2019 | Jul 23, 2015 |
| Ibm Http_server | — | Apply IBM HTTP Server version 8.0.0.12 or laterApply IBM HTTP Server version 8.5.5.7 or laterApply IBM HTTP Server version 7.0.0.39 or laterApply IBM HTTP Server Interim Fix PI45596Apply IBM HTTP Server version 6.1.0.48 or later | Sep 7, 2022 | Sep 7, 2022 |
| Oracle Solaris | — | Upgrade library/expat to version 2.2.0-0.175.3.11.0.4.0 on Solaris 11.3 | May 29, 2017 | Jul 22, 2015 |
| Suse | — | Upgrade libexpat1-32bitUpgrade sles12sp1-docker-imageUpgrade libexpat1-x86Upgrade chromiumUpgrade libexpat-develUpgrade sles12-docker-imageUpgrade expatUpgrade libexpat1 | Dec 18, 2015 | Jul 22, 2015 |
| Ubuntu | — | Upgrade libexpat1Upgrade liboxideqtcore0Upgrade libxmltok1t64 (Ubuntu Pro)Upgrade libxmlrpc-core-c3Upgrade xvnc4viewer (Ubuntu Pro)Upgrade vnc4server (Ubuntu Pro)Upgrade libxmltok1t64Upgrade lib64expat1Upgrade libxmltok1 (Ubuntu Pro)Upgrade libxmlrpc-c++4 | Jun 20, 2016 | Jul 22, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub