CVE-2021-44960 is a null pointer dereference vulnerability affecting SVGPP SVG++ library version 1.3.0. Specifically, the XMLDocument::getRoot function within renderDocument improperly handles the XMLDocument object, leading to a null pointer being returned prematurely. This results in a denial of service (DoS) due to a subsequent null pointer reference. Rated with a CVSS score of 6.5 (Medium), this vulnerability can be triggered remotely with low attack complexity, requiring user interaction. While it does not impact confidentiality or integrity, a successful exploit can lead to high availability impact. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, indicating low public awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.3.0CPE matchmatch criteria | cpe:2.3:a:svgpp:svgpp:1.3.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.