ZeroHour

Vulnerabilities

5 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-42860
+1 in the same advisory: …42859
A stack buffer overflow exists in Mini-XML v3.2.

A stack buffer overflow exists in Mini-XML v3.2. When inputting an unformed XML string to the mxmlLoadString API, it will cause a stack-buffer-overflow in mxml_string_getc:2611. NOTE: it is unclear whether this input is allowed by the API specification

NVD description · AI analysis pending
7.51% PoC
  • mini-xml project mini-xml
CVE-2018-20004
An issue has been found in Mini-XML (aka mxml) 2.12.

An issue has been found in Mini-XML (aka mxml) 2.12. It is a stack-based buffer overflow in mxml_write_node in mxml-file.c via vectors involving a double-precision floating point number and the ' ' substring, as demonstrated by testmxml.

NVD description · AI analysis pending
8.82% PoC ×2
  • mini-xml project mini-xml
  • mini-xml project debian linux
  • mini-xml project fedora
CVE-2016-4571
+1 in the same advisory: …4570
The mxml_write_node function in mxml-file.c in mxml 2.9, 2.7, and possibly earlier allows remote attackers to cause a denial of service (stack consumption) via

The mxml_write_node function in mxml-file.c in mxml 2.9, 2.7, and possibly earlier allows remote attackers to cause a denial of service (stack consumption) via crafted xml file.

NVD description · AI analysis pending
5.52%
  • mini-xml project mini-xml
  • mini-xml project debian linux