Lucene search

K

HtmlUnit Project Security Vulnerabilities

cve
cve

CVE-2022-28366

Certain Neko-related HTML parsers allow a denial of service via crafted Processing Instruction (PI) input that causes excessive heap memory consumption. In particular, this issue exists in HtmlUnit-Neko through 2.26, and is fixed in 2.27. This issue also exists in CyberNeko HTML through 1.9.22...

7.5CVSS

7.1AI Score

0.002EPSS

2022-04-21 11:15 PM
126
2
cve
cve

CVE-2020-5529

HtmlUnit prior to 2.37.0 contains code execution vulnerabilities. HtmlUnit initializes Rhino engine improperly, hence a malicious JavScript code can execute arbitrary Java code on the application. Moreover, when embedded in Android application, Android-specific initialization of Rhino engine is...

8.1CVSS

8.1AI Score

0.004EPSS

2020-02-11 12:15 PM
88