Htmldoc Project
Products
1- 23 CVEs
Recent CVEs
23| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-20308 | Cri | 0.64 | 9.8 | 0.02 | Apr 5, 2021 | Integer overflow in the htmldoc 1.9.11 and before may allow attackers to execute arbitrary code and cause a denial of service that is similar to CVE-2017-9181. | ||
| CVE-2021-26948 | Hig | 0.51 | 7.8 | 0.01 | Mar 3, 2022 | Null pointer dereference in the htmldoc v1.9.11 and before may allow attackers to execute arbitrary code and cause a denial of service via a crafted html file. | ||
| CVE-2021-26252 | Hig | 0.51 | 7.8 | 0.01 | Feb 24, 2022 | A flaw was found in htmldoc in v1.9.12. Heap buffer overflow in pspdf_prepare_page(),in ps-pdf.cxx may lead to execute arbitrary code and denial of service. | ||
| CVE-2019-19630 | Hig | 0.51 | 7.8 | 0.01 | Dec 8, 2019 | HTMLDOC 1.9.7 allows a stack-based buffer overflow in the hd_strlcpy() function in string.c (when called from render_contents in ps-pdf.cxx) via a crafted HTML document. | ||
| CVE-2022-24191 | Med | 0.36 | 5.5 | 0.01 | Apr 4, 2022 | In HTMLDOC 1.9.14, an infinite loop in the gif_read_lzw function can lead to a pointer arbitrarily pointing to heap memory and resulting in a buffer overflow. | ||
| CVE-2021-43579 | Hig | 0.04 | 7.8 | 0.07 | Jan 10, 2022 | A stack-based buffer overflow in image_load_bmp() in HTMLDOC <= 1.9.13 results in remote code execution if the victim converts an HTML document linking to a crafted BMP file. | ||
| CVE-2024-46478 | Cri | 0.00 | 9.8 | 0.01 | Oct 24, 2024 | HTMLDOC v1.9.18 contains a buffer overflow in parse_pre function,ps-pdf.cxx:5681. | ||
| CVE-2024-45508 | Cri | 0.00 | 9.8 | 0.01 | Sep 1, 2024 | HTMLDOC before 1.9.19 has an out-of-bounds write in parse_paragraph in ps-pdf.cxx because of an attempt to strip leading whitespace from a whitespace-only node. | ||
| CVE-2021-34121 | Hig | 0.00 | 7.8 | 0.00 | Jul 18, 2023 | An Out of Bounds flaw was discovered in htmodoc 1.9.12 in function parse_tree() in toc.cxx, this possibly leads to memory layout information leaking in the data. This might be used in a chain of vulnerability in order to reach code execution. | ||
| CVE-2021-34119 | Hig | 0.00 | 7.8 | 0.00 | Jul 18, 2023 | A flaw was discovered in htmodoc 1.9.12 in function parse_paragraph in ps-pdf.cxx ,this flaw possibly allows possible code execution and a denial of service via a crafted file. | ||
| CVE-2022-0137 | Hig | 0.00 | 7.5 | 0.01 | Nov 14, 2022 | A heap buffer overflow in image_set_mask function of HTMLDOC before 1.9.15 allows an attacker to write outside the buffer boundaries. | ||
| CVE-2022-34035 | Hig | 0.00 | 7.5 | 0.02 | Jul 18, 2022 | HTMLDoc v1.9.12 and below was discovered to contain a heap overflow via e_node htmldoc/htmldoc/html.cxx:588. | ||
| CVE-2022-34033 | Hig | 0.00 | 7.5 | 0.02 | Jul 18, 2022 | HTMLDoc v1.9.15 was discovered to contain a heap overflow via (write_header) /htmldoc/htmldoc/html.cxx:273. | ||
| CVE-2022-27114 | Med | 0.00 | 5.5 | 0.01 | May 9, 2022 | There is a vulnerability in htmldoc 1.9.16. In image_load_jpeg function image.cxx when it calls malloc,'img->width' and 'img->height' they are large enough to cause an integer overflow. So, the malloc function may return a heap blosmaller than the expected size, and it will… | ||
| CVE-2022-28085 | Hig | 0.00 | 7.8 | 0.01 | Apr 27, 2022 | A flaw was found in htmldoc commit 31f7804. A heap buffer overflow in the function pdf_write_names in ps-pdf.cxx may lead to arbitrary code execution and Denial of Service (DoS). | ||
| CVE-2021-23165 | Cri | 0.00 | 9.8 | 0.04 | Mar 16, 2022 | A flaw was found in htmldoc before v1.9.12. Heap buffer overflow in pspdf_prepare_outpages(), in ps-pdf.cxx may lead to execute arbitrary code and denial of service. | ||
| CVE-2021-23158 | Cri | 0.00 | 9.8 | 0.02 | Mar 16, 2022 | A flaw was found in htmldoc in v1.9.12. Double-free in function pspdf_export(),in ps-pdf.cxx may result in a write-what-where condition, allowing an attacker to execute arbitrary code and denial of service. | ||
| CVE-2021-26259 | Hig | 0.00 | 7.8 | 0.01 | Mar 3, 2022 | A flaw was found in htmldoc in v1.9.12. Heap buffer overflow in render_table_row(),in ps-pdf.cxx may lead to arbitrary code execution and denial of service. | ||
| CVE-2021-23206 | Hig | 0.00 | 7.8 | 0.01 | Mar 2, 2022 | A flaw was found in htmldoc in v1.9.12 and prior. A stack buffer overflow in parse_table() in ps-pdf.cxx may lead to execute arbitrary code and denial of service. | ||
| CVE-2021-23191 | Hig | 0.00 | 7.8 | 0.01 | Mar 2, 2022 | A security issue was found in htmldoc v1.9.12 and before. A NULL pointer dereference in the function image_load_jpeg() in image.cxx may result in denial of service. |
- risk 0.64cvss 9.8epss 0.02
Integer overflow in the htmldoc 1.9.11 and before may allow attackers to execute arbitrary code and cause a denial of service that is similar to CVE-2017-9181.
- risk 0.51cvss 7.8epss 0.01
Null pointer dereference in the htmldoc v1.9.11 and before may allow attackers to execute arbitrary code and cause a denial of service via a crafted html file.
- risk 0.51cvss 7.8epss 0.01
A flaw was found in htmldoc in v1.9.12. Heap buffer overflow in pspdf_prepare_page(),in ps-pdf.cxx may lead to execute arbitrary code and denial of service.
- risk 0.51cvss 7.8epss 0.01
HTMLDOC 1.9.7 allows a stack-based buffer overflow in the hd_strlcpy() function in string.c (when called from render_contents in ps-pdf.cxx) via a crafted HTML document.
- risk 0.36cvss 5.5epss 0.01
In HTMLDOC 1.9.14, an infinite loop in the gif_read_lzw function can lead to a pointer arbitrarily pointing to heap memory and resulting in a buffer overflow.
- risk 0.04cvss 7.8epss 0.07
A stack-based buffer overflow in image_load_bmp() in HTMLDOC <= 1.9.13 results in remote code execution if the victim converts an HTML document linking to a crafted BMP file.
- risk 0.00cvss 9.8epss 0.01
HTMLDOC v1.9.18 contains a buffer overflow in parse_pre function,ps-pdf.cxx:5681.
- risk 0.00cvss 9.8epss 0.01
HTMLDOC before 1.9.19 has an out-of-bounds write in parse_paragraph in ps-pdf.cxx because of an attempt to strip leading whitespace from a whitespace-only node.
- risk 0.00cvss 7.8epss 0.00
An Out of Bounds flaw was discovered in htmodoc 1.9.12 in function parse_tree() in toc.cxx, this possibly leads to memory layout information leaking in the data. This might be used in a chain of vulnerability in order to reach code execution.
- risk 0.00cvss 7.8epss 0.00
A flaw was discovered in htmodoc 1.9.12 in function parse_paragraph in ps-pdf.cxx ,this flaw possibly allows possible code execution and a denial of service via a crafted file.
- risk 0.00cvss 7.5epss 0.01
A heap buffer overflow in image_set_mask function of HTMLDOC before 1.9.15 allows an attacker to write outside the buffer boundaries.
- risk 0.00cvss 7.5epss 0.02
HTMLDoc v1.9.12 and below was discovered to contain a heap overflow via e_node htmldoc/htmldoc/html.cxx:588.
- risk 0.00cvss 7.5epss 0.02
HTMLDoc v1.9.15 was discovered to contain a heap overflow via (write_header) /htmldoc/htmldoc/html.cxx:273.
- risk 0.00cvss 5.5epss 0.01
There is a vulnerability in htmldoc 1.9.16. In image_load_jpeg function image.cxx when it calls malloc,'img->width' and 'img->height' they are large enough to cause an integer overflow. So, the malloc function may return a heap blosmaller than the expected size, and it will…
- risk 0.00cvss 7.8epss 0.01
A flaw was found in htmldoc commit 31f7804. A heap buffer overflow in the function pdf_write_names in ps-pdf.cxx may lead to arbitrary code execution and Denial of Service (DoS).
- risk 0.00cvss 9.8epss 0.04
A flaw was found in htmldoc before v1.9.12. Heap buffer overflow in pspdf_prepare_outpages(), in ps-pdf.cxx may lead to execute arbitrary code and denial of service.
- risk 0.00cvss 9.8epss 0.02
A flaw was found in htmldoc in v1.9.12. Double-free in function pspdf_export(),in ps-pdf.cxx may result in a write-what-where condition, allowing an attacker to execute arbitrary code and denial of service.
- risk 0.00cvss 7.8epss 0.01
A flaw was found in htmldoc in v1.9.12. Heap buffer overflow in render_table_row(),in ps-pdf.cxx may lead to arbitrary code execution and denial of service.
- risk 0.00cvss 7.8epss 0.01
A flaw was found in htmldoc in v1.9.12 and prior. A stack buffer overflow in parse_table() in ps-pdf.cxx may lead to execute arbitrary code and denial of service.
- risk 0.00cvss 7.8epss 0.01
A security issue was found in htmldoc v1.9.12 and before. A NULL pointer dereference in the function image_load_jpeg() in image.cxx may result in denial of service.