libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memory condition.
Weakness
The product dereferences a pointer that it expects to be valid but is NULL.
Potential Mitigations
References