Show filters
8 Total Results
Displaying 1-8 of 8
Sort by:
Attacker Value
Unknown
CVE-2021-42860
Disclosure Date: May 26, 2022 (last updated February 23, 2025)
A stack buffer overflow exists in Mini-XML v3.2. When inputting an unformed XML string to the mxmlLoadString API, it will cause a stack-buffer-overflow in mxml_string_getc:2611. NOTE: it is unclear whether this input is allowed by the API specification
0
Attacker Value
Unknown
CVE-2021-42859
Disclosure Date: May 26, 2022 (last updated February 23, 2025)
A memory leak issue was discovered in Mini-XML v3.2 that could cause a denial of service. NOTE: testing reports are inconsistent, with some testers seeing the issue in both the 3.2 release and in the October 2021 development code, but others not seeing the issue in the 3.2 release
0
Attacker Value
Unknown
CVE-2018-20592
Disclosure Date: December 30, 2018 (last updated November 08, 2023)
In Mini-XML (aka mxml) v2.12, there is a use-after-free in the mxmlAdd function of the mxml-node.c file. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted xml file, as demonstrated by mxmldoc.
0
Attacker Value
Unknown
CVE-2018-20593
Disclosure Date: December 30, 2018 (last updated November 08, 2023)
In Mini-XML (aka mxml) v2.12, there is stack-based buffer overflow in the scan_file function in mxmldoc.c.
0
Attacker Value
Unknown
CVE-2018-20005
Disclosure Date: December 10, 2018 (last updated November 08, 2023)
An issue has been found in Mini-XML (aka mxml) 2.12. It is a use-after-free in mxmlWalkNext in mxml-search.c, as demonstrated by mxmldoc.
0
Attacker Value
Unknown
CVE-2018-20004
Disclosure Date: December 10, 2018 (last updated November 08, 2023)
An issue has been found in Mini-XML (aka mxml) 2.12. It is a stack-based buffer overflow in mxml_write_node in mxml-file.c via vectors involving a double-precision floating point number and the '<order type="real">' substring, as demonstrated by testmxml.
0
Attacker Value
Unknown
CVE-2016-4570
Disclosure Date: February 03, 2017 (last updated November 25, 2024)
The mxmlDelete function in mxml-node.c in mxml 2.9, 2.7, and possibly earlier allows remote attackers to cause a denial of service (stack consumption) via crafted xml file.
0
Attacker Value
Unknown
CVE-2016-4571
Disclosure Date: February 03, 2017 (last updated November 25, 2024)
The mxml_write_node function in mxml-file.c in mxml 2.9, 2.7, and possibly earlier allows remote attackers to cause a denial of service (stack consumption) via crafted xml file.
0