CVE-2012-1148: Apple Mac OS X
Medium severity, CVSS 5.0. EPSS: 3.6% chance of exploitation in the next 30 days.
Memory leak in the poolGrow function in expat/lib/xmlparse.c in expat before 2.1.0 allows context-dependent attackers to cause a denial of service (memory consumption) via a large number of crafted XML files that cause improperly-handled reallocation failures when expanding entities.
Affected products
- Apple Mac OS X: up to and including 10.11.1
- Libexpat Project Libexpat: up to and including 2.0.1; version 1.95.1 only; version 1.95.2 only; version 1.95.4 only; version 1.95.5 only; version 1.95.6 only; …
Published 2012-07-03. Last modified 2026-06-16.