CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
PARTIAL
AV:N/AC:M/Au:N/C:N/I:N/A:P
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
EPSS
Percentile
54.2%
An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_internal_dtd() performs incorrect memory handling while parsing crafted XML files, which leads to an out-of-bounds write of a one byte constant.
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
Debian | 12 | all | mapcache | <= 1.14.0-1 | mapcache_1.14.0-1_all.deb |
Debian | 11 | all | mapcache | <= 1.10.0-2 | mapcache_1.10.0-2_all.deb |
Debian | 999 | all | mapcache | <= 1.14.1-1 | mapcache_1.14.1-1_all.deb |
Debian | 13 | all | mapcache | <= 1.14.1-1 | mapcache_1.14.1-1_all.deb |
Debian | 12 | all | netcdf | < 1:4.9.0-1 | netcdf_1:4.9.0-1_all.deb |
Debian | 11 | all | netcdf | <= 1:4.7.4-1 | netcdf_1:4.7.4-1_all.deb |
Debian | 999 | all | netcdf | < 1:4.9.0-1 | netcdf_1:4.9.0-1_all.deb |
Debian | 13 | all | netcdf | < 1:4.9.0-1 | netcdf_1:4.9.0-1_all.deb |
Debian | 12 | all | netcdf-parallel | < 1:4.9.0-1 | netcdf-parallel_1:4.9.0-1_all.deb |
Debian | 11 | all | netcdf-parallel | <= 1:4.7.4-1 | netcdf-parallel_1:4.7.4-1_all.deb |
CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
PARTIAL
AV:N/AC:M/Au:N/C:N/I:N/A:P
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
EPSS
Percentile
54.2%