md4c_project CVE Vulnerabilities & CVE List (8)

Products (CPE): — CVEs: 8

md4c_project vulnerability overview

Aggregates CVE and security vulnerability intelligence across all md4c_project-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Historical issues mainly involve vendor risk buffer overflow and vendor risk memory corruption and related problems; some flaws may lead to vendor impact application crash and vendor impact memory corruption.

Vulnerability distribution trend (last 24 months)

Showing 18 of 8 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2021-30027 md_analyze_line in md4c.c in md4c 0.4.7 allows attackers to trigger use of uninitialized memory, and cause a denial of service via a malformed Markdown document. [email protected] 5.5 0.27% 2021-04-29 2024-11-21
CVE-2020-26148 md_push_block_bytes in md4c.c in md4c 0.4.5 allows attackers to trigger use of uninitialized memory, and cause a denial of service (e.g., assertion failure) via a malformed Markdown document. [email protected] 7.5 0.36% 2020-09-30 2024-11-21
CVE-2018-12112 md_build_attribute in md4c.c in md4c 0.2.6 allows remote attackers to cause a denial of service (Segmentation fault and application crash) or possibly have unspecified other impact via a crafted file. [email protected] 7.8 0.23% 2018-06-11 2024-11-21
CVE-2018-12102 md4c 0.2.6 has a NULL pointer dereference in the function md_process_line in md4c.c, related to ctx->current_block. [email protected] 5.5 0.06% 2018-06-11 2024-11-21
CVE-2018-11547 md_is_link_reference_definition_helper in md4c 0.2.5 has a heap-based buffer over-read because md_is_link_label mishandles loop termination. [email protected] 9.8 0.43% 2018-05-29 2024-11-21
CVE-2018-11546 md4c 0.2.5 has a heap-based buffer over-read because md_is_named_entity_contents has an off-by-one error. [email protected] 9.8 0.43% 2018-05-29 2024-11-21
CVE-2018-11545 md4c 0.2.5 has a heap-based buffer overflow in md_merge_lines because md_is_link_label mishandles the case of a link label composed solely of backslash escapes. [email protected] 9.8 0.44% 2018-05-29 2024-11-21
CVE-2018-11536 md4c before 0.2.5 has a heap-based buffer overflow because md_split_simple_pairing_mark mishandles splits. [email protected] 9.8 0.44% 2018-05-29 2024-11-21
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence