← Back to CVE List
Vulnerability Intelligence Report

CVE-2021-45960

In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbehavior (e.g., allocating too few bytes, or only freeing memory).

No Active Exploit Signals
CVSS Base Score
8.8
HIGH
Exploitability:2.9
Impact Score:5.9
EPSS Probability:4.20%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-682 ↗CWE-682 Incorrect Calculation

Affected Products & Versions

Vendor Product Affected Versions
libexpat_project libexpat all
tenable nessus all
debian debian_linux 10.0, 11.0
siemens sinema_remote_connect_server all
netapp active_iq_unified_manager all
netapp hci_baseboard_management_controller h610c, h610s, h615c
netapp oncommand_workflow_automation all
netapp solidfire_\&_hci_management_node all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
4.200%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2022-01-01T00:00:00
Published2022-01-01T18:47:46
Last Updated2025-05-05T16:45:11

LINK COPIED TO CLIPBOARD