Vulnerabilities
5 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-42860 +1 in the same advisory: …42859 | A stack buffer overflow exists in Mini-XML v3.2. A stack buffer overflow exists in Mini-XML v3.2. When inputting an unformed XML string to the mxmlLoadString API, it will cause a stack-buffer-overflow in mxml_string_getc:2611. NOTE: it is unclear whether this input is allowed by the API specification NVD description · AI analysis pending | 7.5 | 1% | PoC |
| — | |
| CVE-2018-20004 | An issue has been found in Mini-XML (aka mxml) 2.12. An issue has been found in Mini-XML (aka mxml) 2.12. It is a stack-based buffer overflow in mxml_write_node in mxml-file.c via vectors involving a double-precision floating point number and the ' ' substring, as demonstrated by testmxml. NVD description · AI analysis pending | 8.8 | 2% | PoC ×2 |
| — | |
| CVE-2016-4571 +1 in the same advisory: …4570 | The mxml_write_node function in mxml-file.c in mxml 2.9, 2.7, and possibly earlier allows remote attackers to cause a denial of service (stack consumption) via The mxml_write_node function in mxml-file.c in mxml 2.9, 2.7, and possibly earlier allows remote attackers to cause a denial of service (stack consumption) via crafted xml file. NVD description · AI analysis pending | 5.5 | 2% |
| — |