CVE-2021-20308 is an integer overflow vulnerability in htmldoc versions 1.9.11 and earlier, affecting Debian Linux and the htmldoc project. This critical vulnerability (CVSS 9.8) allows unauthenticated remote attackers to execute arbitrary code and cause a denial of service, similar to CVE-2017-9181, with low attack complexity. While the EPSS score is low and it's not on the KEV catalog, indicating a low likelihood of widespread exploitation, its high FAUCET Risk Score of 78/100 warrants attention. There is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), and it has received no community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.9.11CPE matchmatch criteria | cpe:2.3:a:htmldoc_project:htmldoc:*:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.