Get real-time updates on Telegram
CVE-2013-0340: libexpat before 2.4.0 (exclusive); +6 more affected products
CVE-2013-0340. CVSS 2.0 base score 6.8 (MEDIUM, NVD). EPSS 0.19433 (percentile 0.97303), scored 2026-10-08.
Affected technology
libexpat · before 2.4.0 (exclusive)
libexpat project
python · from 3.6.0 (inclusive), before 3.6.15 (exclusive)
python
python · from 3.7.0 (inclusive), before 3.7.12 (exclusive)
python
python · from 3.8.0 (inclusive), before 3.8.12 (exclusive)
python
python · from 3.9.0 (inclusive), before 3.9.7 (exclusive)
python
ipados · before 14.8 (exclusive)
apple
iphone os · before 14.8 (exclusive)
apple
macos · before 11.6 (exclusive)
apple
tvos · before 15.0 (exclusive)
apple
watchos · before 8.0 (exclusive)
apple
Product not specified by the source · 0 to before 2.4.0
Vendor not specified by the source
Description’s affected range: before version 2.4.0 does not properly handle entities expansion unless an application developer uses the XML_SetEntityDeclHandler function
Component: Not specified by the source
Attack conditions (NVD, CVSS 2.0): Network (remote)
What an attacker can do
Remote attackers can cause a denial of service (resource consumption), send HTTP requests to intranet servers, or read arbitrary files via a crafted XML document, aka an XML External Entity (XXE) issue. NVD’s CVSS 2.0 assessment (base score 6.8/10) rates confidentiality, integrity and availability impact as partial.
- CWE
- CWE-611
- CCR priority
- 32.1 /100 (P4)
- CVSS 2.0
- 6.8 /10 · CVSS:2.0/AV:N/AC:M/Au:N/C:P/I:P/A:P · NVD
- EPSS
- 0.19433 · percentile 0.97305 · 2026-10-09
- KEV
- no
Provenance
- FIRST EPSS daily exploit-probability · Source record · observed 2026-10-09 21:11:27.988868+00:00 UTC
- NVD CVE API 2.0 · Source record · observed 2026-10-09 21:08:49.498434+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2013-0340.html