CVE-2021-26220
The ezxml_toxml function in ezxml 0.8.6 and earlier is vulnerable to OOB write when opening XML file after exhausting the memory pool.
- Affected products
- Astra Linux, Debian, Suse, Ezxml
- Ezxml Project Ezxml
- ≤ 0.8.6
- CVSS 3.1
- 8.1 HIGH
- EPSS
- 1.2% (65th percentile)
- Weakness
- CWE-787
- NVD status
- Modified
- Published
- 2021-02-08
CVE-2021-26220 at NVD
No indexed exploits for CVE-2021-26220 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2021-26220 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.