Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2015-5523
Description:The ParseValue function in lexer.c in tidy before 4.9.31 allows remote attackers to cause a denial of service (crash) via vectors involving multiple whitespace characters before an empty href, which triggers a large memory allocation.
Test IDs: 1.3.6.1.4.1.25623.1.1.1.2.2015.273  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2015-5523
http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html
http://lists.apple.com/archives/security-announce/2015/Sep/msg00005.html
http://lists.apple.com/archives/security-announce/2015/Sep/msg00008.html
BugTraq ID: 75037
http://www.securityfocus.com/bid/75037
Debian Security Information: DSA-3309 (Google Search)
http://www.debian.org/security/2015/dsa-3309
http://www.openwall.com/lists/oss-security/2015/06/04/2
http://www.openwall.com/lists/oss-security/2015/07/13/7
http://www.openwall.com/lists/oss-security/2015/07/15/3
http://www.securitytracker.com/id/1033703
http://www.ubuntu.com/usn/USN-2695-1




© 1998-2025 E-Soft Inc. All rights reserved.