8.1
CVSSv3

CVE-2021-26222

Published: 08/02/2021 Updated: 10/02/2021
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.1 | Impact Score: 5.2 | Exploitability Score: 2.8
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:P

Vulnerability Summary

The ezxml_new function in ezXML 0.8.6 and previous versions is vulnerable to OOB write when opening XML file after exhausting the memory pool.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ezxml project ezxml

Vendor Advisories

Debian Bug report logs - #989361 netcdf-parallel: Multiple security issues in ezxml Package: src:netcdf-parallel; Maintainer for src:netcdf-parallel is Alastair McKinstry <mckinstry@debianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Tue, 1 Jun 2021 19:57:04 UTC Severity: important Tags: security ...
Debian Bug report logs - #989360 netcdf: Multiple security issues in ezxml Package: src:netcdf; Maintainer for src:netcdf is Debian GIS Project <pkg-grass-devel@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Tue, 1 Jun 2021 19:57:02 UTC Severity: important Tags: security Reply ...