CVE-2015-5522

Heap-based buffer overflow in the ParseValue function in lexer.c in tidy before 4.9.31 allows remote attackers to cause a denial of service (crash) via vectors involving a command character in an href.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 89%
VendorProductVersion
htacgtidy
𝑥
≤ 4.9.30
canonicalubuntu_linux
12.04
canonicalubuntu_linux
14.04
canonicalubuntu_linux
15.04
debiandebian_linux
7.0
debiandebian_linux
8.0
appleiphone_os
𝑥
≤ 8.2
applemac_os_x
𝑥
≤ 10.6.8
applewatchos
𝑥
≤ 1.0.1
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
tidy
vivid
Fixed 20091223cvs-1.4ubuntu0.1
released
utopic
ignored
trusty
Fixed 20091223cvs-1.2ubuntu1.1
released
precise
Fixed 20091223cvs-1ubuntu2.1
released