Generated remediation guidance and an executive summary. No account required.
The overflow protection in Expat is removed by compilers with certain optimization settings, which allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via crafted XML data. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-1283 and CVE-2015-2716.
Cite this page
CVE-2016-4472. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2016-4472
Use CWE-119, Libexpat Project vendor hub and Libexpat product page to widen CVE-2016-4472 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2024-45492, CVE-2024-45491 and CVE-2025-59375 for nearby disclosures in the same product family.