Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-58472

Опубликовано: 07 июл. 2026
Источник: nvd
CVSS3: 5.9
CVSS3: 7.1
EPSS Низкий

Описание

GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string() function in src/convert.c that allows a remote attacker to trigger memory corruption by supplying a crafted HTML attribute with a large number of characters requiring entity encoding. A server-supplied HTML attribute causes a signed integer counter to overflow during output size accumulation, resulting in an undersized heap allocation and subsequent heap buffer overflow during the copy phase.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:gnu:wget:*:*:*:*:*:*:*:*
Версия до 1.25.0 (включая)

EPSS

Процентиль: 13%
0.00221
Низкий

5.9 Medium

CVSS3

7.1 High

CVSS3

Дефекты

CWE-190

Связанные уязвимости

CVSS3: 5.9
ubuntu
27 дней назад

GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string() function in src/convert.c that allows a remote attacker to trigger memory corruption by supplying a crafted HTML attribute with a large number of characters requiring entity encoding. A server-supplied HTML attribute causes a signed integer counter to overflow during output size accumulation, resulting in an undersized heap allocation and subsequent heap buffer overflow during the copy phase.

CVSS3: 5.9
redhat
27 дней назад

GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string() function in src/convert.c that allows a remote attacker to trigger memory corruption by supplying a crafted HTML attribute with a large number of characters requiring entity encoding. A server-supplied HTML attribute causes a signed integer counter to overflow during output size accumulation, resulting in an undersized heap allocation and subsequent heap buffer overflow during the copy phase.

CVSS3: 5.9
debian
27 дней назад

GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buff ...

CVSS3: 5.9
github
27 дней назад

GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string() function in src/convert.c that allows a remote attacker to trigger memory corruption by supplying a crafted HTML attribute with a large number of characters requiring entity encoding. A server-supplied HTML attribute causes a signed integer counter to overflow during output size accumulation, resulting in an undersized heap allocation and subsequent heap buffer overflow during the copy phase.

suse-cvrf
12 дней назад

Security update for wget

EPSS

Процентиль: 13%
0.00221
Низкий

5.9 Medium

CVSS3

7.1 High

CVSS3

Дефекты

CWE-190