ZeroHour

Vulnerabilities

23 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-46478
HTMLDOC v1.9.18 contains a buffer overflow in parse_pre function,ps-pdf.cxx:5681.

HTMLDOC v1.9.18 contains a buffer overflow in parse_pre function,ps-pdf.cxx:5681.

NVD description · AI analysis pending
9.8<1% PoC
  • htmldoc project htmldoc
CVE-2024-45508
HTMLDOC before 1.9.19 has an out-of-bounds write in parse_paragraph in ps-pdf.cxx because of an attempt to strip leading whitespace from a whitespace-only node.

HTMLDOC before 1.9.19 has an out-of-bounds write in parse_paragraph in ps-pdf.cxx because of an attempt to strip leading whitespace from a whitespace-only node.

NVD description · AI analysis pending
9.8<1% PoC
  • htmldoc project htmldoc
CVE-2021-34121
+1 in the same advisory: …34119
An Out of Bounds flaw was discovered in htmodoc 1.9.12 in function parse_tree() in toc.cxx, this possibly leads to memory layout information leaking in the data.

An Out of Bounds flaw was discovered in htmodoc 1.9.12 in function parse_tree() in toc.cxx, this possibly leads to memory layout information leaking in the data. This might be used in a chain of vulnerability in order to reach code execution.

NVD description · AI analysis pending
7.8<1% PoC
  • htmldoc project htmldoc
CVE-2022-0137
A heap buffer overflow in image_set_mask function of HTMLDOC before 1.9.15 allows an attacker to write outside the buffer boundaries.

A heap buffer overflow in image_set_mask function of HTMLDOC before 1.9.15 allows an attacker to write outside the buffer boundaries.

NVD description · AI analysis pending
5.5<1% PoC
  • htmldoc project htmldoc
CVE-2022-34035
+1 in the same advisory: …34033
HTMLDoc v1.9.12 and below was discovered to contain a heap overflow via e_node htmldoc/htmldoc/html.cxx:588.

HTMLDoc v1.9.12 and below was discovered to contain a heap overflow via e_node htmldoc/htmldoc/html.cxx:588.

NVD description · AI analysis pending
7.52% PoC
  • htmldoc project htmldoc
CVE-2022-27114
There is a vulnerability in htmldoc 1.9.16.

There is a vulnerability in htmldoc 1.9.16. In image_load_jpeg function image.cxx when it calls malloc,'img->width' and 'img->height' they are large enough to cause an integer overflow. So, the malloc function may return a heap blosmaller than the expected size, and it will cause a buffer overflow/Address boundary error in the jpeg_read_scanlines function.

NVD description · AI analysis pending
5.5<1% PoC
  • htmldoc project htmldoc
  • htmldoc project debian linux
CVE-2022-28085
A flaw was found in htmldoc commit 31f7804.

A flaw was found in htmldoc commit 31f7804. A heap buffer overflow in the function pdf_write_names in ps-pdf.cxx may lead to arbitrary code execution and Denial of Service (DoS).

NVD description · AI analysis pending
7.81% PoC
  • htmldoc project htmldoc
CVE-2022-24191
In HTMLDOC 1.9.14, an infinite loop in the gif_read_lzw function can lead to a pointer arbitrarily pointing to heap memory and resulting in a buffer overflow.

In HTMLDOC 1.9.14, an infinite loop in the gif_read_lzw function can lead to a pointer arbitrarily pointing to heap memory and resulting in a buffer overflow.

NVD description · AI analysis pending
5.5<1% PoC
  • htmldoc project htmldoc
  • htmldoc project fedora
CVE-2021-23165
+1 in the same advisory: …23158
A flaw was found in htmldoc before v1.9.12.

A flaw was found in htmldoc before v1.9.12. Heap buffer overflow in pspdf_prepare_outpages(), in ps-pdf.cxx may lead to execute arbitrary code and denial of service.

NVD description · AI analysis pending
9.84% PoC ×2
  • htmldoc project htmldoc
CVE-2021-26259
+1 in the same advisory: …26948
A flaw was found in htmldoc in v1.9.12.

A flaw was found in htmldoc in v1.9.12. Heap buffer overflow in render_table_row(),in ps-pdf.cxx may lead to arbitrary code execution and denial of service.

NVD description · AI analysis pending
7.81% PoC
  • htmldoc project htmldoc
CVE-2021-23206
+2 in the same advisory: …23180 …23191
A flaw was found in htmldoc in v1.9.12 and prior.

A flaw was found in htmldoc in v1.9.12 and prior. A stack buffer overflow in parse_table() in ps-pdf.cxx may lead to execute arbitrary code and denial of service.

NVD description · AI analysis pending
7.81% PoC
  • htmldoc project htmldoc
CVE-2021-26252
A flaw was found in htmldoc in v1.9.12.

A flaw was found in htmldoc in v1.9.12. Heap buffer overflow in pspdf_prepare_page(),in ps-pdf.cxx may lead to execute arbitrary code and denial of service.

NVD description · AI analysis pending
7.8<1%
  • htmldoc project htmldoc
  • htmldoc project enterprise linux
  • htmldoc project fedora
CVE-2022-0534
A vulnerability was found in htmldoc version 1.9.15 where the stack out-of-bounds read takes place in gif_get_code() and occurs when opening a malicious GIF fil

A vulnerability was found in htmldoc version 1.9.15 where the stack out-of-bounds read takes place in gif_get_code() and occurs when opening a malicious GIF file, which can result in a crash (segmentation fault).

NVD description · AI analysis pending
5.5<1% PoC
  • htmldoc project htmldoc
  • htmldoc project debian linux
CVE-2021-43579
A stack-based buffer overflow in image_load_bmp() in HTMLDOC <= 1.9.13 results in remote code execution if the victim converts an HTML document linking to a cra

A stack-based buffer overflow in image_load_bmp() in HTMLDOC <= 1.9.13 results in remote code execution if the victim converts an HTML document linking to a crafted BMP file.

NVD description · AI analysis pending
7.87% PoC ×2
  • htmldoc project htmldoc
  • htmldoc project debian linux
CVE-2021-40985
A stack-based buffer under-read in htmldoc before 1.9.12, allows attackers to cause a denial of service via a crafted BMP image to image_load_bmp.

A stack-based buffer under-read in htmldoc before 1.9.12, allows attackers to cause a denial of service via a crafted BMP image to image_load_bmp.

NVD description · AI analysis pending
5.5<1% PoC
  • htmldoc project htmldoc
  • htmldoc project debian linux
CVE-2021-20308
Integer overflow in the htmldoc 1.9.11 and before may allow attackers to execute arbitrary code and cause a denial of service that is similar to CVE-2017-9181.

Integer overflow in the htmldoc 1.9.11 and before may allow attackers to execute arbitrary code and cause a denial of service that is similar to CVE-2017-9181.

NVD description · AI analysis pending
9.82% PoC ×2
  • htmldoc project htmldoc
  • htmldoc project debian linux
CVE-2019-19630
HTMLDOC 1.9.7 allows a stack-based buffer overflow in the hd_strlcpy() function in string.c (when called from render_contents in ps-pdf.cxx) via a crafted HTML

HTMLDOC 1.9.7 allows a stack-based buffer overflow in the hd_strlcpy() function in string.c (when called from render_contents in ps-pdf.cxx) via a crafted HTML document.

NVD description · AI analysis pending
7.81% PoC
  • htmldoc project htmldoc
  • htmldoc project debian linux
  • htmldoc project fedora