Skip to content
Appaloosa Scout

Vulnerability · NVD

CVE-2015-1283

LOW Vendor bulletin scale — NVD CVSS pending

Multiple integer overflows in the XML_GetBuffer function in Expat through 2.1.0, as used in Google Chrome before 44.0.2403.89 and other products, allow remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted XML data, a related issue to CVE-2015-2716.

EPSS 19.07% moderate exploit risk percentile 97.0%

Tracked apps referencing this CVE

For each app: the affected range, the fixing version, and where the tracked app stands today.

NVD references 13 distinct products for this CVE — only those tracked by Scout (mobile and desktop catalog apps) are listed above. Libraries, servers and out-of-scope products do not appear here. Full list on NVD ↗

OS versions that fix this CVE

This CVE is resolved by the following OS security releases. Update the OS to at least the listed version.

Vulnerable CPE configurations (4)
Vendor Product Versions
python python
All platforms (wildcard)
≥2.7.0 <2.7.12
python python
All platforms (wildcard)
≥3.3.0 <3.3.7
python python
All platforms (wildcard)
≥3.4.0 <3.4.5
python python
All platforms (wildcard)
≥3.5.0 <3.5.2
View on NVD ↗