CVE-2021-31347 describes a memory handling vulnerability in ezXML 0.8.6, specifically within the ezxml_parse_str() function, which can lead to writing outside allocated memory when processing crafted XML files. This affects Debian Linux and the ezXML project. The vulnerability has a CVSS score of 6.5 (Medium), indicating it can be exploited remotely with low attack complexity, requiring user interaction, and potentially leading to high availability impact. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.8.6CPE matchmatch criteria | cpe:2.3:a:ezxml_project:ezxml:0.8.6:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.