AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2009-3720

MEDIUM · CVSS 5 EPSS 27.92%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2009-11-03 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2009-3720
Severity
MEDIUM
CVSS
5
EPSS
27.92%

Original NVD Description

The updatePosition function in lib/xmltok_impl.c in libexpat in Expat 2.0.1, as used in Python, PyXML, w3c-libwww, and other software, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with crafted UTF-8 sequences that trigger a buffer over-read, a different vulnerability than CVE-2009-2625.