汇总 htmldoc_project 相关全部产品的 CVE 与安全漏洞情报,包括 CVSS、EPSS、公开时间与漏洞情报数据。
历史漏洞主要涉及 内存损坏与缓冲区溢出 等问题,部分漏洞可能导致 内存损坏,并影响 软件部署与生产负载 相关场景。
相关漏洞数据主要来源于公开漏洞披露与安全公告,可用于评估历史漏洞暴露面与修复优先级。
| CVE | 摘要 | 来源 | 最高 CVSS | EPSS % | 公开时间 | 更新时间 |
|---|---|---|---|---|---|---|
| CVE-2024-46478 | HTMLDOC v1.9.18 contains a buffer overflow in parse_pre function,ps-pdf.cxx:5681. | [email protected] | 9.8 | 0.27% | 2024-10-24 | 2025-06-24 |
| CVE-2024-45508 | HTMLDOC before 1.9.19 has an out-of-bounds write in parse_paragraph in ps-pdf.cxx because of an attempt to strip leading whitespace from a whitespace-only node. | [email protected] | 9.8 | 0.29% | 2024-09-01 | 2024-09-04 |
| CVE-2021-34121 | An Out of Bounds flaw was discovered in htmodoc 1.9.12 in function parse_tree() in toc.cxx, this possibly leads to memory layout information leaking in the data. This might be used in a chain of vulnerability in order to reach code execution. | [email protected] | 7.8 | 0.02% | 2023-07-18 | 2024-11-21 |
| CVE-2021-34119 | A flaw was discovered in htmodoc 1.9.12 in function parse_paragraph in ps-pdf.cxx ,this flaw possibly allows possible code execution and a denial of service via a crafted file. | [email protected] | 7.8 | 0.02% | 2023-07-18 | 2024-11-21 |
| CVE-2022-0137 | A heap buffer overflow in image_set_mask function of HTMLDOC before 1.9.15 allows an attacker to write outside the buffer boundaries. | [email protected] | 7.5 | 0.07% | 2022-11-14 | 2024-11-21 |
| CVE-2022-34035 | HTMLDoc v1.9.12 and below was discovered to contain a heap overflow via e_node htmldoc/htmldoc/html.cxx:588. | [email protected] | 7.5 | 0.15% | 2022-07-18 | 2024-11-21 |
| CVE-2022-34033 | HTMLDoc v1.9.15 was discovered to contain a heap overflow via (write_header) /htmldoc/htmldoc/html.cxx:273. | [email protected] | 7.5 | 0.15% | 2022-07-18 | 2024-11-21 |
| CVE-2022-27114 | There is a vulnerability in htmldoc 1.9.16. In image_load_jpeg function image.cxx when it calls malloc,'img->width' and 'img->height' they are large enough to cause an integer overflow. So, the malloc function may return a heap blosmaller than the expected size, and it will cause a buffer overflow/Address boundary error in the jpeg_read_scanlines function. | [email protected] | 5.5 | 0.20% | 2022-05-09 | 2024-11-21 |
| CVE-2022-28085 | A flaw was found in htmldoc commit 31f7804. A heap buffer overflow in the function pdf_write_names in ps-pdf.cxx may lead to arbitrary code execution and Denial of Service (DoS). | [email protected] | 7.8 | 0.22% | 2022-04-27 | 2025-02-05 |
| CVE-2022-24191 | In HTMLDOC 1.9.14, an infinite loop in the gif_read_lzw function can lead to a pointer arbitrarily pointing to heap memory and resulting in a buffer overflow. | [email protected] | 5.5 | 0.08% | 2022-04-04 | 2024-11-21 |
| CVE-2021-23165 | A flaw was found in htmldoc before v1.9.12. Heap buffer overflow in pspdf_prepare_outpages(), in ps-pdf.cxx may lead to execute arbitrary code and denial of service. | [email protected] | 9.8 | 0.41% | 2022-03-16 | 2025-02-05 |
| CVE-2021-23158 | A flaw was found in htmldoc in v1.9.12. Double-free in function pspdf_export(),in ps-pdf.cxx may result in a write-what-where condition, allowing an attacker to execute arbitrary code and denial of service. | [email protected] | 9.8 | 0.33% | 2022-03-16 | 2024-11-21 |
| CVE-2021-26948 | Null pointer dereference in the htmldoc v1.9.11 and before may allow attackers to execute arbitrary code and cause a denial of service via a crafted html file. | [email protected] | 7.8 | 0.10% | 2022-03-03 | 2024-11-21 |
| CVE-2021-26259 | A flaw was found in htmldoc in v1.9.12. Heap buffer overflow in render_table_row(),in ps-pdf.cxx may lead to arbitrary code execution and denial of service. | [email protected] | 7.8 | 0.17% | 2022-03-03 | 2024-11-21 |
| CVE-2021-23206 | A flaw was found in htmldoc in v1.9.12 and prior. A stack buffer overflow in parse_table() in ps-pdf.cxx may lead to execute arbitrary code and denial of service. | [email protected] | 7.8 | 0.34% | 2022-03-02 | 2024-11-21 |
| CVE-2021-23191 | A security issue was found in htmldoc v1.9.12 and before. A NULL pointer dereference in the function image_load_jpeg() in image.cxx may result in denial of service. | [email protected] | 7.8 | 0.21% | 2022-03-02 | 2024-11-21 |
| CVE-2021-23180 | A flaw was found in htmldoc in v1.9.12 and before. Null pointer dereference in file_extension(),in file.c may lead to execute arbitrary code and denial of service. | [email protected] | 7.8 | 0.28% | 2022-03-02 | 2024-11-21 |
| CVE-2021-26252 | A flaw was found in htmldoc in v1.9.12. Heap buffer overflow in pspdf_prepare_page(),in ps-pdf.cxx may lead to execute arbitrary code and denial of service. | [email protected] | 7.8 | 0.26% | 2022-02-24 | 2024-11-21 |
| CVE-2022-0534 | A vulnerability was found in htmldoc version 1.9.15 where the stack out-of-bounds read takes place in gif_get_code() and occurs when opening a malicious GIF file, which can result in a crash (segmentation fault). | [email protected] | 5.5 | 0.14% | 2022-02-09 | 2024-11-21 |
| CVE-2021-43579 | A stack-based buffer overflow in image_load_bmp() in HTMLDOC <= 1.9.13 results in remote code execution if the victim converts an HTML document linking to a crafted BMP file. | [email protected] | 7.8 | 5.62% | 2022-01-10 | 2024-11-21 |