Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown

CVE-2021-33391

Disclosure Date: February 17, 2023 (last updated October 08, 2023)
An issue in HTACG HTML Tidy v5.7.28 allows attacker to execute arbitrary code via the -g option of the CleanNode() function in gdoc.c.
Attacker Value
Unknown

CVE-2017-17497

Disclosure Date: December 10, 2017 (last updated November 26, 2024)
In Tidy 5.7.0, the prvTidyTidyMetaCharset function in clean.c allows attackers to cause a denial of service (Segmentation Fault), because the currentNode variable in the "children of the head" processing feature is modified in the loop without validating the new value.
Attacker Value
Unknown

CVE-2017-13692

Disclosure Date: August 25, 2017 (last updated November 26, 2024)
In Tidy 5.5.31, the IsURLCodePoint function in attrs.c allows attackers to cause a denial of service (Segmentation Fault), as demonstrated by an invalid ISALNUM argument.
0
Attacker Value
Unknown

CVE-2015-5523

Disclosure Date: August 11, 2015 (last updated October 05, 2023)
The ParseValue function in lexer.c in tidy before 4.9.31 allows remote attackers to cause a denial of service (crash) via vectors involving multiple whitespace characters before an empty href, which triggers a large memory allocation.
0
Attacker Value
Unknown

CVE-2015-5522

Disclosure Date: August 11, 2015 (last updated October 05, 2023)
Heap-based buffer overflow in the ParseValue function in lexer.c in tidy before 4.9.31 allows remote attackers to cause a denial of service (crash) via vectors involving a command character in an href.
0