Loading
Generated remediation guidance and an executive summary. No account required.
In libexpat before 2.2.8, crafted XML input could fool the parser into changing from DTD parsing to document parsing too early; a consecutive call to XML_GetCurrentLineNumber (or XML_GetCurrentColumnNumber) then resulted in a heap-based buffer over-read.
Cite this page
CVE-2019-15903. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2019-15903
Use CWE-125, Libexpat Project vendor hub and Libexpat product page to widen CVE-2019-15903 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2024-45492, CVE-2024-45491 and CVE-2025-59375 for nearby disclosures in the same product family.