Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3064▲ 561 respecto a la semana anterior
Críticas / altas1461▲ 283 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Sin puntuar | 0.15% | — | Mini-xmlAI | 24/9/2026 | 24/9/2026 | Mini-XML 4.0.5 contains a memory leak vulnerability in mxml_load_data() during malformed XML parsing. Specially crafted XML input can cause text nodes allocated by mxmlNewText() to become unlinked before a parse error transfers control to the cleanup path. These orphaned nodes are not released, resulting in a… | |
| Modificada | Alta (7.5) | 1.0% | — | Mini-xml Project Mini-xml | 26/5/2022 | 17/6/2026 | A stack buffer overflow exists in Mini-XML v3.2. When inputting an unformed XML string to the mxmlLoadString API, it will cause a stack-buffer-overflow in mxml_string_getc:2611. NOTE: it is unclear whether this input is allowed by the API specification | |
| Modificada | Alta (7.5) | 1.0% | — | Mini-xml Project Mini-xml | 26/5/2022 | 17/6/2026 | A memory leak issue was discovered in Mini-XML v3.2 that could cause a denial of service. NOTE: testing reports are inconsistent, with some testers seeing the issue in both the 3.2 release and in the October 2021 development code, but others not seeing the issue in the 3.2 release | |
| Modificada | Media (5.5) | 1.3% | — | Msweet Mini-xmlFedoraproject Fedora | 30/12/2018 | 17/6/2026 | In Mini-XML (aka mxml) v2.12, there is stack-based buffer overflow in the scan_file function in mxmldoc.c. | |
| Modificada | Media (5.5) | 1.5% | — | Msweet Mini-xmlFedoraproject Fedora | 30/12/2018 | 17/6/2026 | In Mini-XML (aka mxml) v2.12, there is a use-after-free in the mxmlAdd function of the mxml-node.c file. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted xml file, as demonstrated by mxmldoc. | |
| Modificada | Media (5.5) | 1.1% | — | Msweet Mini-xmlFedoraproject Fedora | 10/12/2018 | 17/6/2026 | An issue has been found in Mini-XML (aka mxml) 2.12. It is a use-after-free in mxmlWalkNext in mxml-search.c, as demonstrated by mxmldoc. | |
| Modificada | Alta (8.8) | 2.0% | — | Mini-xml Project Mini-xmlDebian LinuxFedoraproject Fedora | 10/12/2018 | 17/6/2026 | An issue has been found in Mini-XML (aka mxml) 2.12. It is a stack-based buffer overflow in mxml_write_node in mxml-file.c via vectors involving a double-precision floating point number and the '<order type="real">' substring, as demonstrated by testmxml. | |
| Modificada | Media (5.5) | 1.6% | — | Mini-xml Project Mini-xmlDebian Linux | 3/2/2017 | 17/6/2026 | The mxml_write_node function in mxml-file.c in mxml 2.9, 2.7, and possibly earlier allows remote attackers to cause a denial of service (stack consumption) via crafted xml file. | |
| Modificada | Media (5.5) | 1.6% | — | Mini-xml Project Mini-xmlDebian Linux | 3/2/2017 | 17/6/2026 | The mxmlDelete function in mxml-node.c in mxml 2.9, 2.7, and possibly earlier allows remote attackers to cause a denial of service (stack consumption) via crafted xml file. |