Записи HTACG
6 опубликованных записей вендора htacg.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 66,7 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer3
- CWE-20 Improper Input Validation1
- CWE-401 Missing Release of Memory after Effective Lifetime1
- CWE-416 Use After Free1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
6 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2021-33391Эксплойта нет | An issue in HTACG HTML Tidy v5.7.28 allows attacker to execute arbitrary code via the -g option of the CleanNode() function in gdoc.c.htacg · tidy · CWE-416 | Критическая9,8 | — | 1,1 % | 17 февр. 2023 г. |
30Наблюдать | CVE-2017-17497Эксплойта нет | In Tidy 5.7.0, the prvTidyTidyMetaCharset function in clean.c allows attackers to cause a denial of service (Segmentation Fault), because thhtacg · tidy · CWE-119 | Высокая7,5 | — | 1,4 % | 10 дек. 2017 г. |
30Наблюдать | CVE-2017-13692Эксплойта нет | In Tidy 5.5.31, the IsURLCodePoint function in attrs.c allows attackers to cause a denial of service (Segmentation Fault), as demonstrated bhtacg · tidy · CWE-20 | Высокая7,5 | — | 1,2 % | 25 авг. 2017 г. |
28Наблюдать | CVE-2015-5522Эксплойта нет | Heap-based buffer overflow in the ParseValue function in lexer.c in tidy before 4.9.31 allows remote attackers to cause a denial of service htacg · tidy · CWE-119 | Средняя6,8 | — | 4,7 % | 11 авг. 2015 г. |
18Наблюдать | CVE-2015-5523Эксплойта нет | The ParseValue function in lexer.c in tidy before 4.9.31 allows remote attackers to cause a denial of service (crash) via vectors involving canonical · ubuntu linux · CWE-119 | Средняя4,3 | — | 3,8 % | 11 авг. 2015 г. |
7Наблюдать | CVE-2025-6498Эксплойта нет | HTACG tidy-html5 alloc.c defaultAlloc memory leakhtacg · tidy · CWE-401 | Низкая1,9 | — | 0,2 % | 22 июн. 2025 г. |
- CVE-2021-3339139Наблюдать
An issue in HTACG HTML Tidy v5.7.28 allows attacker to execute arbitrary code via the -g option of the CleanNode() function in gdoc.c.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %htacg · tidy17 февр. 2023 г.
- CVE-2017-1749730Наблюдать
In Tidy 5.7.0, the prvTidyTidyMetaCharset function in clean.c allows attackers to cause a denial of service (Segmentation Fault), because th
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %htacg · tidy10 дек. 2017 г.
- CVE-2017-1369230Наблюдать
In Tidy 5.5.31, the IsURLCodePoint function in attrs.c allows attackers to cause a denial of service (Segmentation Fault), as demonstrated b
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %htacg · tidy25 авг. 2017 г.
- CVE-2015-552228Наблюдать
Heap-based buffer overflow in the ParseValue function in lexer.c in tidy before 4.9.31 allows remote attackers to cause a denial of service
СредняяCVSS 6,8Эксплойта нетEPSS 5 %htacg · tidy11 авг. 2015 г.
- CVE-2015-552318Наблюдать
The ParseValue function in lexer.c in tidy before 4.9.31 allows remote attackers to cause a denial of service (crash) via vectors involving
СредняяCVSS 4,3Эксплойта нетEPSS 4 %canonical · ubuntu linux11 авг. 2015 г.
- CVE-2025-64987Наблюдать
HTACG tidy-html5 alloc.c defaultAlloc memory leak
НизкаяCVSS 1,9Эксплойта нетEPSS 0 %htacg · tidy22 июн. 2025 г.