Search CVE reports


Toggle filters

1 – 8 of 8 results


CVE-2023-34623

Low priority
Needs evaluation

An issue was discovered jtidy thru r938 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies.

1 affected package

jtidy

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
jtidy Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2021-33391

Medium priority

Some fixes available 6 of 8

An issue in HTACG HTML Tidy v5.7.28 allows attacker to execute arbitrary code via the -g option of the CleanNode() function in gdoc.c.

1 affected package

tidy-html5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
tidy-html5 Fixed Fixed Fixed Vulnerable Ignored
Show less packages

CVE-2017-17497

Low priority
Ignored

In Tidy 5.7.0, the prvTidyTidyMetaCharset function in clean.c allows attackers to cause a denial of service (Segmentation Fault), because the currentNode variable in the "children of the head" processing feature is modified in the...

2 affected packages

tidy, tidy-html5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
tidy Not in release Not in release Not affected
tidy-html5 Not affected Not affected Not in release
Show less packages

CVE-2014-2277

Low priority
Ignored

The make_temporary_filename function in perltidy 20120701-1 and earlier allows local users to obtain sensitive information or write to arbitrary files via a symlink attack, related to use of the tmpnam function.

1 affected package

perltidy

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
perltidy Not affected Not affected
Show less packages

CVE-2017-13692

Medium priority
Not affected

In Tidy 5.5.31, the IsURLCodePoint function in attrs.c allows attackers to cause a denial of service (Segmentation Fault), as demonstrated by an invalid ISALNUM argument.

2 affected packages

tidy, tidy-html5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
tidy Not affected
tidy-html5 Not in release
Show less packages

CVE-2016-10374

Low priority
Vulnerable

perltidy through 20160302, as used by perlcritic, check-all-the-things, and other software, relies on the current working directory for certain output files and does not have a symlink-attack protection mechanism, which...

1 affected package

perltidy

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
perltidy Not affected Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2015-5523

Low priority

Some fixes available 3 of 4

The ParseValue function in lexer.c in tidy before 4.9.31 allows remote attackers to cause a denial of service (crash) via vectors involving multiple whitespace characters before an empty href, which triggers a large memory allocation.

1 affected package

tidy

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
tidy
Show less packages

CVE-2015-5522

Medium priority

Some fixes available 3 of 4

Heap-based buffer overflow in the ParseValue function in lexer.c in tidy before 4.9.31 allows remote attackers to cause a denial of service (crash) via vectors involving a command character in an href.

1 affected package

tidy

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
tidy
Show less packages