Expat, when used in a parser that has not called XML_SetHashSalt or passed it a seed of 0, makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms via vectors involving use of the srand function.
CVSS Details
- CVSS 3.1 Base Score: 5.9
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade expat | Sep 20, 2017 | Jun 16, 2016 |
| Apple Itunes | — | Upgrade Apple iTunes to the latest version | Mar 24, 2017 | Jun 16, 2016 |
| Debian | — | Upgrade expat | Jun 7, 2016 | Jun 7, 2016 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Sep 6, 2016 |
| Freebsd | — | Upgrade expat | Dec 10, 2025 | Jun 9, 2016 |
| Gentoo Linux | — | Upgrade dev-libs/expat. | Oct 30, 2017 | Jun 16, 2016 |
| Huawei Euleros 2_0_sp2 | — | Upgrade xulrunner | Jun 17, 2020 | Jun 16, 2016 |
| Red Hat Jboss Eap | — | — | Sep 19, 2024 | Feb 27, 2015 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Feb 27, 2015 |
| Suse | — | Upgrade libexpat1-debuginfoUpgrade expat-debuginfo-32bitUpgrade libexpat1Upgrade libexpat-develUpgrade expat-debuginfoUpgrade expat-debugsourceUpgrade libexpat1-x86Upgrade libexpat-devel-32bitUpgrade libexpat1-32bitUpgrade libexpat1-debuginfo-32bitUpgrade expat | Apr 26, 2018 | Jun 16, 2016 |
| Ubuntu | — | Upgrade libxmlrpc-c++4Upgrade libexpat1Upgrade lib64expat1Upgrade libxmlrpc-core-c3 | Jun 20, 2016 | Jun 16, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub