2 results (0.008 seconds)

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 1

An issue was discovered htmlcleaner thru = 2.28 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies. • https://github.com/amplafi/htmlcleaner/issues/13 https://lists.debian.org/debian-lts-announce/2023/08/msg00007.html https://www.debian.org/security/2023/dsa-5471 • CWE-787: Out-of-bounds Write •

CVSS: 4.9EPSS: 0%CPEs: 20EXPL: 2

Multiple race conditions in HtmlCleaner before 2.6, as used in Open-Xchange AppSuite 7.2.2 before rev13 and other products, allow remote authenticated users to read the private e-mail of other persons in opportunistic circumstances by leveraging lack of thread safety and performing a rapid series of (1) mail-sending or (2) draft-saving operations. Múltiples vulnerabilidades de condición de carrera en HtmlCleaner anterior a v2.6, como es utilizado en Open-Xchange AppSuite v7.2.2 anterior a rev13 y otros productos, permiten a los usuarios remotos autenticados leer el correo electrónico privado de otras personas en situaciones oportunistas, mediante el aprovechamiento de la falta de seguridad de los subprocesos y la realización de una serie rápida de (1) envío de emails o (2) operaciones de guardado de borradores. • http://archives.neohapsis.com/archives/bugtraq/2013-08/0115.html http://sourceforge.net/p/htmlcleaner/bugs/86 • CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') •