CVE-2024-35333

May 29, 2024, 7:50 p.m.

None
No Score

Description

A stack-buffer-overflow vulnerability exists in the read_charset_decl function of html2xhtml 1.3. This vulnerability occurs due to improper bounds checking when copying data into a fixed-size stack buffer. An attacker can exploit this vulnerability by providing a specially crafted input to the vulnerable function, causing a buffer overflow and potentially leading to arbitrary code execution, denial of service, or data corruption.

Product(s) Impacted

Product Versions
html2xhtml
  • ['1.3']

Weaknesses

Common security weaknesses mapped to this vulnerability.

Timeline

Published: May 29, 2024, 4:15 p.m.
Last Modified: May 29, 2024, 7:50 p.m.

Status : Awaiting Analysis

CVE has been recently published to the CVE List and has been received by the NVD.

More info

Source

cve@mitre.org

*Disclaimer: Some vulnerabilities do not have an associated CPE. To enhance the data, we use AI to infer CPEs based on CVE details. This is an automated process and might not always be accurate.