← Back

Mini Xml

mini-xml

Vendor: Mini Xml Project • 5 CVEs

CVEs (5)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mini Xml Project
1Mini Xml
Nov 21, 2024
May 26, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A stack buffer overflow exists in Mini-XML v3.2. When inputting an unformed XML string to the mxmlLoadString API, it will cause a stack-buffer-overflow in mxml_string_getc:2611. NOTE: it is unclear whether this input is...Show more
A stack buffer overflow exists in Mini-XML v3.2. When inputting an unformed XML string to the mxmlLoadString API, it will cause a stack-buffer-overflow in mxml_string_getc:2611. NOTE: it is unclear whether this input is allowed by the API specificationShow less
1Mini Xml Project
1Mini Xml
Nov 21, 2024
May 26, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A memory leak issue was discovered in Mini-XML v3.2 that could cause a denial of service. NOTE: testing reports are inconsistent, with some testers seeing the issue in both the 3.2 release and in the October 2021 develop...Show more
A memory leak issue was discovered in Mini-XML v3.2 that could cause a denial of service. NOTE: testing reports are inconsistent, with some testers seeing the issue in both the 3.2 release and in the October 2021 development code, but others not seeing the issue in the 3.2 releaseShow less
3Debian
FedoraprojectMini Xml Project
3Debian Linux
FedoraMini Xml
Nov 21, 2024
Dec 10, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An issue has been found in Mini-XML (aka mxml) 2.12. It is a stack-based buffer overflow in mxml_write_node in mxml-file.c via vectors involving a double-precision floating point number and the '<order type="real">' subs...Show more
An issue has been found in Mini-XML (aka mxml) 2.12. It is a stack-based buffer overflow in mxml_write_node in mxml-file.c via vectors involving a double-precision floating point number and the '<order type="real">' substring, as demonstrated by testmxml.Show less
2Debian
Mini Xml Project
2Debian Linux
Mini Xml
May 13, 2026
Feb 3, 2017
N/A· v4
5.5 MEDIUM· v3
7.1 HIGH· v2
The mxml_write_node function in mxml-file.c in mxml 2.9, 2.7, and possibly earlier allows remote attackers to cause a denial of service (stack consumption) via crafted xml file.
2Debian
Mini Xml Project
2Debian Linux
Mini Xml
May 13, 2026
Feb 3, 2017
N/A· v4
5.5 MEDIUM· v3
7.1 HIGH· v2
The mxmlDelete function in mxml-node.c in mxml 2.9, 2.7, and possibly earlier allows remote attackers to cause a denial of service (stack consumption) via crafted xml file.