Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2748▲ 38 respecto a la semana anterior
Críticas / altas1479▲ 369 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
17 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.97% | — | Ezxml Project Ezxml | 17/5/2022 | 17/6/2026 | An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_decode() performs incorrect memory handling while parsing crafted XML files, leading to a heap out-of-bounds read. | |
| Modificada | Alta (7.5) | 1.3% | — | Ezxml Project EzxmlDebian Linux | 24/4/2021 | 17/6/2026 | An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_decode() performs incorrect memory handling while parsing crafted XML files, leading to a heap-based buffer overflow. | |
| Modificada | Media (6.5) | 1.1% | — | Ezxml Project EzxmlDebian Linux | 16/4/2021 | 17/6/2026 | An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_parse_str() performs incorrect memory handling while parsing crafted XML files (out-of-bounds read after a certain strcspn failure). | |
| Modificada | Media (6.5) | 1.1% | — | Ezxml Project EzxmlDebian Linux | 16/4/2021 | 17/6/2026 | An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_parse_str() performs incorrect memory handling while parsing crafted XML files (writing outside a memory region created by mmap). | |
| Modificada | Media (6.5) | 0.99% | — | Ezxml Project EzxmlDebian Linux | 15/4/2021 | 17/6/2026 | An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_internal_dtd() performs incorrect memory handling while parsing crafted XML files, which leads to an out-of-bounds write of a one byte constant. | |
| Modificada | Media (6.5) | 1.1% | — | Ezxml Project EzxmlDebian Linux | 11/4/2021 | 17/6/2026 | An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_internal_dtd(), while parsing a crafted XML file, performs incorrect memory handling, leading to a NULL pointer dereference while running strcmp() on a NULL pointer. | |
| Modificada | Alta (8.1) | 1.2% | — | Ezxml Project Ezxml | 8/2/2021 | 17/6/2026 | The ezxml_new function in ezXML 0.8.6 and earlier is vulnerable to OOB write when opening XML file after exhausting the memory pool. | |
| Modificada | Alta (8.1) | 1.2% | — | Ezxml Project Ezxml | 8/2/2021 | 17/6/2026 | The ezxml_new function in ezXML 0.8.6 and earlier is vulnerable to OOB write when opening XML file after exhausting the memory pool. | |
| Modificada | Alta (8.1) | 1.2% | — | Ezxml Project Ezxml | 8/2/2021 | 17/6/2026 | The ezxml_toxml function in ezxml 0.8.6 and earlier is vulnerable to OOB write when opening XML file after exhausting the memory pool. | |
| Modificada | Media (6.5) | 1.1% | — | Ezxml Project Ezxml | 31/12/2019 | 17/6/2026 | An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxml_char_content() tries to use realloc on a block that was not allocated, leading to an invalid free and segmentation fault. | |
| Modificada | Media (6.5) | 1.1% | — | Ezxml Project Ezxml | 31/12/2019 | 17/6/2026 | An issue was discovered in ezXML 0.8.3 through 0.8.6. The ezxml_parse_* functions mishandle XML entities, leading to an infinite loop in which memory allocations occur. | |
| Modificada | Media (6.5) | 1.1% | — | Ezxml Project Ezxml | 31/12/2019 | 17/6/2026 | An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxml_decode, while parsing crafted a XML file, performs incorrect memory handling, leading to a heap-based buffer over-read in the "normalize line endings" feature. | |
| Modificada | Media (6.5) | 1.1% | — | Ezxml Project Ezxml | 31/12/2019 | 17/6/2026 | An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxml_decode, while parsing a crafted XML file, performs incorrect memory handling, leading to NULL pointer dereference while running strlen() on a NULL pointer. | |
| Modificada | Media (6.5) | 1.1% | — | Ezxml Project Ezxml | 31/12/2019 | 17/6/2026 | An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxml_ent_ok() mishandles recursion, leading to stack consumption for a crafted XML file. | |
| Modificada | Media (6.5) | 1.2% | — | Ezxml Project Ezxml | 26/12/2019 | 17/6/2026 | An issue was discovered in ezXML 0.8.2 through 0.8.6. The function ezxml_str2utf8, while parsing a crafted XML file, performs zero-length reallocation in ezxml.c, leading to returning a NULL pointer (in some compilers). After this, the function ezxml_parse_str does not check whether the s variable is not NULL in… | |
| Modificada | Alta (7.5) | 1.5% | — | Ezxml Project Ezxml | 26/12/2019 | 17/6/2026 | An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxml_char_content puts a pointer to the internal address of a larger block as xml->txt. This is later deallocated (using free), leading to a segmentation fault. | |
| Modificada | Media (6.5) | 1.1% | — | Ezxml Project Ezxml | 26/12/2019 | 17/6/2026 | An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxml_decode, while parsing a crafted XML file, performs incorrect memory handling, leading to a heap-based buffer over-read while running strchr() starting with a pointer after a '\0' character (where the processing of a string was finished). |