CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2013-0340: libexpat before 2.4.0 (exclusive); +6 more affected products

CVE-2013-0340. CVSS 2.0 base score 6.8 (MEDIUM, NVD). EPSS 0.19433 (percentile 0.97303), scored 2026-10-08.

Affected technology

libexpat · before 2.4.0 (exclusive)
libexpat project

python · from 3.6.0 (inclusive), before 3.6.15 (exclusive)
python

python · from 3.7.0 (inclusive), before 3.7.12 (exclusive)
python

python · from 3.8.0 (inclusive), before 3.8.12 (exclusive)
python

python · from 3.9.0 (inclusive), before 3.9.7 (exclusive)
python

ipados · before 14.8 (exclusive)
apple

iphone os · before 14.8 (exclusive)
apple

macos · before 11.6 (exclusive)
apple

tvos · before 15.0 (exclusive)
apple

watchos · before 8.0 (exclusive)
apple

Product not specified by the source · 0 to before 2.4.0
Vendor not specified by the source

Description’s affected range: before version 2.4.0 does not properly handle entities expansion unless an application developer uses the XML_SetEntityDeclHandler function

Component: Not specified by the source

Attack conditions (NVD, CVSS 2.0): Network (remote)

What an attacker can do

Remote attackers can cause a denial of service (resource consumption), send HTTP requests to intranet servers, or read arbitrary files via a crafted XML document, aka an XML External Entity (XXE) issue. NVD’s CVSS 2.0 assessment (base score 6.8/10) rates confidentiality, integrity and availability impact as partial.

Published

CWE
CWE-611
CCR priority
32.1 /100 (P4)
CVSS 2.0
6.8 /10 · CVSS:2.0/AV:N/AC:M/Au:N/C:P/I:P/A:P · NVD
EPSS
0.19433 · percentile 0.97305 · 2026-10-09
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2013-0340.html