
CVE-2021-20308 – Gentoo Linux Security Advisory 202405-07
https://notcve.org/view.php?id=CVE-2021-20308
05 Apr 2021 — Integer overflow in the htmldoc 1.9.11 and before may allow attackers to execute arbitrary code and cause a denial of service that is similar to CVE-2017-9181. El desbordamiento de enteros en htmldoc versiones 1.9.11 y anteriores, puede permitir a atacantes ejecutar código arbitrario y causar una denegación de servicio similar a CVE-2017-9181 It was discovered that HTMLDOC incorrectly handled certain inputs, which could lead to an integer overflow. An attacker could potentially use this issue to cause a den... • https://bugzilla.redhat.com/show_bug.cgi?id=1946289 • CWE-190: Integer Overflow or Wraparound •

CVE-2019-19630 – Ubuntu Security Notice USN-4696-1
https://notcve.org/view.php?id=CVE-2019-19630
08 Dec 2019 — HTMLDOC 1.9.7 allows a stack-based buffer overflow in the hd_strlcpy() function in string.c (when called from render_contents in ps-pdf.cxx) via a crafted HTML document. HTMLDOC versión 1.9.7, permite un desbordamiento del búfer en la región stack de la memoria en la función hd_strlcpy() en el archivo string.c (cuando se llamo desde render_contents en el archivo ps-pdf.cxx) por medio de un documento HTML diseñado. It was discovered that HTMLDOC incorrectly handled certain HTML files. An attacker could possi... • https://github.com/michaelrsweet/htmldoc/issues/370 • CWE-787: Out-of-bounds Write •

CVE-2009-3050
https://notcve.org/view.php?id=CVE-2009-3050
02 Sep 2009 — Buffer overflow in the set_page_size function in util.cxx in HTMLDOC 1.8.27 and earlier allows context-dependent attackers to execute arbitrary code via a long MEDIA SIZE comment. NOTE: it was later reported that there were additional vectors in htmllib.cxx and ps-pdf.cxx using an AFM font file with a long glyph name, but these vectors do not cross privilege boundaries. Desbordamiento de búfer en la función set_page_size en util.cxx en HTMLDOC 1.8.27 y versiones anteriores permite a atacantes dependientes d... • http://bugs.gentoo.org/show_bug.cgi?id=278186 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •