Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2009-3627

Опубликовано: 29 окт. 2009
Источник: nvd
CVSS2: 4.3
EPSS Низкий

Описание

The decode_entities function in util.c in HTML-Parser before 3.63 allows context-dependent attackers to cause a denial of service (infinite loop) via an incomplete SGML numeric character reference, which triggers generation of an invalid UTF-8 character.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:derrick_oswald:html-parser:*:*:*:*:*:*:*:*
Версия до 3.54 (включая)
cpe:2.3:a:derrick_oswald:html-parser:1.00:*:*:*:*:*:*:*
cpe:2.3:a:derrick_oswald:html-parser:1.1:*:*:*:*:*:*:*
cpe:2.3:a:derrick_oswald:html-parser:1.2:*:*:*:*:*:*:*
cpe:2.3:a:derrick_oswald:html-parser:1.3:*:*:*:*:*:*:*
cpe:2.3:a:derrick_oswald:html-parser:1.4:*:*:*:*:*:*:*
cpe:2.3:a:derrick_oswald:html-parser:1.5:*:*:*:*:*:*:*
cpe:2.3:a:derrick_oswald:html-parser:1.6:*:*:*:*:*:*:*
cpe:2.3:a:derrick_oswald:html-parser:1.41:*:*:*:*:*:*:*
cpe:2.3:a:derrick_oswald:html-parser:1.42:*:*:*:*:*:*:*

EPSS

Процентиль: 72%
0.00726
Низкий

4.3 Medium

CVSS2

Дефекты

CWE-20

Связанные уязвимости

ubuntu
около 16 лет назад

The decode_entities function in util.c in HTML-Parser before 3.63 allows context-dependent attackers to cause a denial of service (infinite loop) via an incomplete SGML numeric character reference, which triggers generation of an invalid UTF-8 character.

redhat
около 16 лет назад

The decode_entities function in util.c in HTML-Parser before 3.63 allows context-dependent attackers to cause a denial of service (infinite loop) via an incomplete SGML numeric character reference, which triggers generation of an invalid UTF-8 character.

debian
около 16 лет назад

The decode_entities function in util.c in HTML-Parser before 3.63 allo ...

github
больше 3 лет назад

The decode_entities function in util.c in HTML-Parser before 3.63 allows context-dependent attackers to cause a denial of service (infinite loop) via an incomplete SGML numeric character reference, which triggers generation of an invalid UTF-8 character.

EPSS

Процентиль: 72%
0.00726
Низкий

4.3 Medium

CVSS2

Дефекты

CWE-20