Skip to content
Noroxi

tinyxml2 project records

3 published records for vendor tinyxml2 project.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
33.3%
Median publish → KEV
No record has entered KEV

Records by year

  1. 18
  2. 24

Bar: total · dark part: CISA KEV.

Recurring classes

The weakness classes this vendor ships most often: where to look.

CWE

All records

3 records
  • TinyXML2 6.2.0 has a heap-based buffer over-read in the XMLDocument::Parse function in libtinyxml2.so.

    CriticalCVSS 9.8No exploitEPSS 2%

    tinyxml2 project · tinyxml2May 16, 2018

  • TinyXML2 through 10.0.0 has a reachable assertion for UINT_MAX/16, that may lead to application exit, in tinyxml2.cpp XMLUtil::GetCharacterR

    MediumCVSS 6.5No exploitEPSS 0%

    tinyxml2 project · tinyxml2Oct 27, 2024

  • TinyXML2 through 10.0.0 has a reachable assertion for UINT_MAX/digit, that may lead to application exit, in tinyxml2.cpp XMLUtil::GetCharact

    MediumCVSS 6.5No exploitEPSS 0%

    tinyxml2 project · tinyxml2Oct 27, 2024