Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-11210

Опубликовано: 16 мая 2018
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Низкий

Описание

TinyXML2 6.2.0 has a heap-based buffer over-read in the XMLDocument::Parse function in libtinyxml2.so. NOTE: The tinyxml2 developers have determined that the reported overflow is due to improper use of the library and not a vulnerability in tinyxml2

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:tinyxml2_project:tinyxml2:6.2.0:*:*:*:*:*:*:*

EPSS

Процентиль: 47%
0.00243
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-125

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 7 лет назад

TinyXML2 6.2.0 has a heap-based buffer over-read in the XMLDocument::Parse function in libtinyxml2.so. NOTE: The tinyxml2 developers have determined that the reported overflow is due to improper use of the library and not a vulnerability in tinyxml2

CVSS3: 4.4
redhat
больше 7 лет назад

TinyXML2 6.2.0 has a heap-based buffer over-read in the XMLDocument::Parse function in libtinyxml2.so. NOTE: The tinyxml2 developers have determined that the reported overflow is due to improper use of the library and not a vulnerability in tinyxml2

CVSS3: 9.8
debian
больше 7 лет назад

TinyXML2 6.2.0 has a heap-based buffer over-read in the XMLDocument::P ...

CVSS3: 9.8
github
больше 3 лет назад

** DISPUTED ** TinyXML2 6.2.0 has a heap-based buffer over-read in the XMLDocument::Parse function in libtinyxml2.so. NOTE: The tinyxml2 developers have determined that the reported overflow is due to improper use of the library and not a vulnerability in tinyxml2.

EPSS

Процентиль: 47%
0.00243
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-125