cbcvebase.

Debian Htmldoc vulnerabilities

24 known vulnerabilities affecting debian/htmldoc.

Total CVEs
24
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL3MEDIUM1LOW20

Vulnerabilities

Page 1 of 2
CVE-2021-43579P3LOWCVSS 7.8PoCfixed in htmldoc 1.9.13-1 (bookworm)2021
CVE-2021-43579 [HIGH] CVE-2021-43579: htmldoc - A stack-based buffer overflow in image_load_bmp() in HTMLDOC <= 1.9.13 results i... A stack-based buffer overflow in image_load_bmp() in HTMLDOC <= 1.9.13 results in remote code execution if the victim converts an HTML document linking to a crafted BMP file. Scope: local bookworm: resolved (fixed in 1.9.13-1) bullseye: resolved (fixed in 1.9.11-4+deb11u1) forky: resolved (fixed in 1.9.13-1) sid: resolved (fixed in 1.9.13-1) trixie: resolved (fixed
debian
CVE-2021-23158P3LOWCVSS 9.8fixed in htmldoc 1.9.11-4 (bookworm)2021
CVE-2021-23158 [CRITICAL] CVE-2021-23158: htmldoc - A flaw was found in htmldoc in v1.9.12. Double-free in function pspdf_export(),i... A flaw was found in htmldoc in v1.9.12. Double-free in function pspdf_export(),in ps-pdf.cxx may result in a write-what-where condition, allowing an attacker to execute arbitrary code and denial of service. Scope: local bookworm: resolved (fixed in 1.9.11-4) bullseye: resolved (fixed in 1.9.11-4) forky: resolved (fixed in 1.9.11-4) sid: resolved (fixed in 1.9.11
debian
CVE-2021-23165P3CRITICALCVSS 9.8fixed in htmldoc 1.9.11-4 (bookworm)2021
CVE-2021-23165 [CRITICAL] CVE-2021-23165: htmldoc - A flaw was found in htmldoc before v1.9.12. Heap buffer overflow in pspdf_prepar... A flaw was found in htmldoc before v1.9.12. Heap buffer overflow in pspdf_prepare_outpages(), in ps-pdf.cxx may lead to execute arbitrary code and denial of service. Scope: local bookworm: resolved (fixed in 1.9.11-4) bullseye: resolved (fixed in 1.9.11-4) forky: resolved (fixed in 1.9.11-4) sid: resolved (fixed in 1.9.11-4) trixie: resolved (fixed in 1.9.11-4)
debian
CVE-2024-46478P3CRITICALCVSS 9.8fixed in htmldoc 1.9.18-3 (forky)2024
CVE-2024-46478 [CRITICAL] CVE-2024-46478: htmldoc - HTMLDOC v1.9.18 contains a buffer overflow in parse_pre function,ps-pdf.cxx:5681... HTMLDOC v1.9.18 contains a buffer overflow in parse_pre function,ps-pdf.cxx:5681. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 1.9.18-3) sid: resolved (fixed in 1.9.18-3) trixie: resolved (fixed in 1.9.18-3)
debian
CVE-2021-20308P3LOWCVSS 7.5fixed in htmldoc 1.9.11-3 (bookworm)2021
CVE-2021-20308 [HIGH] CVE-2021-20308: htmldoc - Integer overflow in the htmldoc 1.9.11 and before may allow attackers to execute... Integer overflow in the htmldoc 1.9.11 and before may allow attackers to execute arbitrary code and cause a denial of service that is similar to CVE-2017-9181. Scope: local bookworm: resolved (fixed in 1.9.11-3) bullseye: resolved (fixed in 1.9.11-3) forky: resolved (fixed in 1.9.11-3) sid: resolved (fixed in 1.9.11-3) trixie: resolved (fixed in 1.9.11-3)
debian
CVE-2024-45508P3CRITICALCVSS 9.8fixed in htmldoc 1.9.18-2 (forky)2024
CVE-2024-45508 [CRITICAL] CVE-2024-45508: htmldoc - HTMLDOC before 1.9.19 has an out-of-bounds write in parse_paragraph in ps-pdf.cx... HTMLDOC before 1.9.19 has an out-of-bounds write in parse_paragraph in ps-pdf.cxx because of an attempt to strip leading whitespace from a whitespace-only node. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 1.9.18-2) sid: resolved (fixed in 1.9.18-2) trixie: resolved (fixed in 1.9.18-2)
debian
CVE-2009-3050P3LOWCVSS 10.0fixed in htmldoc 1.8.27-4.1 (bookworm)2009
CVE-2009-3050 [CRITICAL] CVE-2009-3050: htmldoc - Buffer overflow in the set_page_size function in util.cxx in HTMLDOC 1.8.27 and ... Buffer overflow in the set_page_size function in util.cxx in HTMLDOC 1.8.27 and earlier allows context-dependent attackers to execute arbitrary code via a long MEDIA SIZE comment. NOTE: it was later reported that there were additional vectors in htmllib.cxx and ps-pdf.cxx using an AFM font file with a long glyph name, but these vectors do not cross privilege bound
debian
CVE-2021-34121P3LOWCVSS 7.8fixed in htmldoc 1.9.13-1 (bookworm)2021
CVE-2021-34121 [HIGH] CVE-2021-34121: htmldoc - An Out of Bounds flaw was discovered in htmodoc 1.9.12 in function parse_tree() ... An Out of Bounds flaw was discovered in htmodoc 1.9.12 in function parse_tree() in toc.cxx, this possibly leads to memory layout information leaking in the data. This might be used in a chain of vulnerability in order to reach code execution. Scope: local bookworm: resolved (fixed in 1.9.13-1) bullseye: open forky: resolved (fixed in 1.9.13-1) sid: resolved (fixed i
debian
CVE-2022-34033P3LOWCVSS 7.5fixed in htmldoc 1.9.12-1 (bookworm)2022
CVE-2022-34033 [HIGH] CVE-2022-34033: htmldoc - HTMLDoc v1.9.15 was discovered to contain a heap overflow via (write_header) /ht... HTMLDoc v1.9.15 was discovered to contain a heap overflow via (write_header) /htmldoc/htmldoc/html.cxx:273. Scope: local bookworm: resolved (fixed in 1.9.12-1) bullseye: open forky: resolved (fixed in 1.9.12-1) sid: resolved (fixed in 1.9.12-1) trixie: resolved (fixed in 1.9.12-1)
debian
CVE-2022-34035P3LOWCVSS 7.5fixed in htmldoc 1.9.12-1 (bookworm)2022
CVE-2022-34035 [HIGH] CVE-2022-34035: htmldoc - HTMLDoc v1.9.12 and below was discovered to contain a heap overflow via e_node h... HTMLDoc v1.9.12 and below was discovered to contain a heap overflow via e_node htmldoc/htmldoc/html.cxx:588. Scope: local bookworm: resolved (fixed in 1.9.12-1) bullseye: open forky: resolved (fixed in 1.9.12-1) sid: resolved (fixed in 1.9.12-1) trixie: resolved (fixed in 1.9.12-1)
debian
CVE-2021-23206P3LOWCVSS 7.8fixed in htmldoc 1.9.11-4 (bookworm)2021
CVE-2021-23206 [HIGH] CVE-2021-23206: htmldoc - A flaw was found in htmldoc in v1.9.12 and prior. A stack buffer overflow in par... A flaw was found in htmldoc in v1.9.12 and prior. A stack buffer overflow in parse_table() in ps-pdf.cxx may lead to execute arbitrary code and denial of service. Scope: local bookworm: resolved (fixed in 1.9.11-4) bullseye: resolved (fixed in 1.9.11-4) forky: resolved (fixed in 1.9.11-4) sid: resolved (fixed in 1.9.11-4) trixie: resolved (fixed in 1.9.11-4)
debian
CVE-2021-23180P3LOWCVSS 7.8fixed in htmldoc 1.9.11-4 (bookworm)2021
CVE-2021-23180 [HIGH] CVE-2021-23180: htmldoc - A flaw was found in htmldoc in v1.9.12 and before. Null pointer dereference in f... A flaw was found in htmldoc in v1.9.12 and before. Null pointer dereference in file_extension(),in file.c may lead to execute arbitrary code and denial of service. Scope: local bookworm: resolved (fixed in 1.9.11-4) bullseye: resolved (fixed in 1.9.11-4) forky: resolved (fixed in 1.9.11-4) sid: resolved (fixed in 1.9.11-4) trixie: resolved (fixed in 1.9.11-4)
debian
CVE-2021-26259P4LOWCVSS 7.8fixed in htmldoc 1.9.11-4 (bookworm)2021
CVE-2021-26259 [HIGH] CVE-2021-26259: htmldoc - A flaw was found in htmldoc in v1.9.12. Heap buffer overflow in render_table_row... A flaw was found in htmldoc in v1.9.12. Heap buffer overflow in render_table_row(),in ps-pdf.cxx may lead to arbitrary code execution and denial of service. Scope: local bookworm: resolved (fixed in 1.9.11-4) bullseye: resolved (fixed in 1.9.11-4) forky: resolved (fixed in 1.9.11-4) sid: resolved (fixed in 1.9.11-4) trixie: resolved (fixed in 1.9.11-4)
debian
CVE-2022-28085P4LOWCVSS 7.8fixed in htmldoc 1.9.15-2 (bookworm)2022
CVE-2022-28085 [HIGH] CVE-2022-28085: htmldoc - A flaw was found in htmldoc commit 31f7804. A heap buffer overflow in the functi... A flaw was found in htmldoc commit 31f7804. A heap buffer overflow in the function pdf_write_names in ps-pdf.cxx may lead to arbitrary code execution and Denial of Service (DoS). Scope: local bookworm: resolved (fixed in 1.9.15-2) bullseye: resolved (fixed in 1.9.11-4+deb11u3) forky: resolved (fixed in 1.9.15-2) sid: resolved (fixed in 1.9.15-2) trixie: resolved (fi
debian
CVE-2021-34119P4LOWCVSS 7.8fixed in htmldoc 1.9.12-1 (bookworm)2021
CVE-2021-34119 [HIGH] CVE-2021-34119: htmldoc - A flaw was discovered in htmodoc 1.9.12 in function parse_paragraph in ps-pdf.cx... A flaw was discovered in htmodoc 1.9.12 in function parse_paragraph in ps-pdf.cxx ,this flaw possibly allows possible code execution and a denial of service via a crafted file. Scope: local bookworm: resolved (fixed in 1.9.12-1) bullseye: open forky: resolved (fixed in 1.9.12-1) sid: resolved (fixed in 1.9.12-1) trixie: resolved (fixed in 1.9.12-1)
debian
CVE-2019-19630P4LOWCVSS 7.8fixed in htmldoc 1.9.7-1 (bookworm)2019
CVE-2019-19630 [HIGH] CVE-2019-19630: htmldoc - HTMLDOC 1.9.7 allows a stack-based buffer overflow in the hd_strlcpy() function ... HTMLDOC 1.9.7 allows a stack-based buffer overflow in the hd_strlcpy() function in string.c (when called from render_contents in ps-pdf.cxx) via a crafted HTML document. Scope: local bookworm: resolved (fixed in 1.9.7-1) bullseye: resolved (fixed in 1.9.7-1) forky: resolved (fixed in 1.9.7-1) sid: resolved (fixed in 1.9.7-1) trixie: resolved (fixed in 1.9.7-1)
debian
CVE-2021-26252P4LOWCVSS 7.8fixed in htmldoc 1.9.11-4 (bookworm)2021
CVE-2021-26252 [HIGH] CVE-2021-26252: htmldoc - A flaw was found in htmldoc in v1.9.12. Heap buffer overflow in pspdf_prepare_pa... A flaw was found in htmldoc in v1.9.12. Heap buffer overflow in pspdf_prepare_page(),in ps-pdf.cxx may lead to execute arbitrary code and denial of service. Scope: local bookworm: resolved (fixed in 1.9.11-4) bullseye: resolved (fixed in 1.9.11-4) forky: resolved (fixed in 1.9.11-4) sid: resolved (fixed in 1.9.11-4) trixie: resolved (fixed in 1.9.11-4)
debian
CVE-2021-23191P4LOWCVSS 7.8fixed in htmldoc 1.9.11-4 (bookworm)2021
CVE-2021-23191 [HIGH] CVE-2021-23191: htmldoc - A security issue was found in htmldoc v1.9.12 and before. A NULL pointer derefer... A security issue was found in htmldoc v1.9.12 and before. A NULL pointer dereference in the function image_load_jpeg() in image.cxx may result in denial of service. Scope: local bookworm: resolved (fixed in 1.9.11-4) bullseye: resolved (fixed in 1.9.11-4) forky: resolved (fixed in 1.9.11-4) sid: resolved (fixed in 1.9.11-4) trixie: resolved (fixed in 1.9.11-4)
debian
CVE-2021-26948P4LOWCVSS 7.8fixed in htmldoc 1.9.11-4 (bookworm)2021
CVE-2021-26948 [HIGH] CVE-2021-26948: htmldoc - Null pointer dereference in the htmldoc v1.9.11 and before may allow attackers t... Null pointer dereference in the htmldoc v1.9.11 and before may allow attackers to execute arbitrary code and cause a denial of service via a crafted html file. Scope: local bookworm: resolved (fixed in 1.9.11-4) bullseye: resolved (fixed in 1.9.11-4) forky: resolved (fixed in 1.9.11-4) sid: resolved (fixed in 1.9.11-4) trixie: resolved (fixed in 1.9.11-4)
debian
CVE-2022-0137P4LOWCVSS 7.5fixed in htmldoc 1.9.15-1 (bookworm)2022
CVE-2022-0137 [HIGH] CVE-2022-0137: htmldoc - A heap buffer overflow in image_set_mask function of HTMLDOC before 1.9.15 allow... A heap buffer overflow in image_set_mask function of HTMLDOC before 1.9.15 allows an attacker to write outside the buffer boundaries. Scope: local bookworm: resolved (fixed in 1.9.15-1) bullseye: open forky: resolved (fixed in 1.9.15-1) sid: resolved (fixed in 1.9.15-1) trixie: resolved (fixed in 1.9.15-1)
debian