Vulnerabilities > Htacg > Tidy > 4.9.30

DATE CVE VULNERABILITY TITLE RISK
2015-08-11 CVE-2015-5523 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
The ParseValue function in lexer.c in tidy before 4.9.31 allows remote attackers to cause a denial of service (crash) via vectors involving multiple whitespace characters before an empty href, which triggers a large memory allocation.
4.3
2015-08-11 CVE-2015-5522 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
Heap-based buffer overflow in the ParseValue function in lexer.c in tidy before 4.9.31 allows remote attackers to cause a denial of service (crash) via vectors involving a command character in an href.
6.8