AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2012-1148

MEDIUM · CVSS 5 EPSS 3.56%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2012-07-03 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

CVE
CVE-2012-1148
Severity
MEDIUM
CVSS
5
EPSS
3.56%

Original Filing — NVD Description

Memory leak in the poolGrow function in expat/lib/xmlparse.c in expat before 2.1.0 allows context-dependent attackers to cause a denial of service (memory consumption) via a large number of crafted XML files that cause improperly-handled reallocation failures when expanding entities.