4.3
CVSSv2

CVE-2018-0499

Published: 02/07/2018 Updated: 28/08/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

A cross-site scripting vulnerability in queryparser/termgenerator_internal.cc in Xapian xapian-core prior to 1.4.6 exists due to incomplete HTML escaping by Xapian::MSet::snippet().

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

xapian xapian-core

canonical ubuntu linux 17.10

canonical ubuntu linux 18.04

Vendor Advisories

Debian Bug report logs - #902886 CVE-2018-0499: HTML escaping bug Package: libxapian30; Maintainer for libxapian30 is Olly Betts <olly@survexcom>; Source for libxapian30 is src:xapian-core (PTS, buildd, popcon) Reported by: Olly Betts <olly@survexcom> Date: Mon, 2 Jul 2018 21:42:02 UTC Severity: important Tags: p ...
Xapian-core could be made to execute arbitrary code if it received a specially crafted file ...