Mini Xml Project maintains a lightweight XML parsing library that, despite a narrow product footprint, achieves prominence through deep embedding in server and application software where XML processing is foundational. The observed vulnerability surface centers on the core parsing product itself, with the durable signal rooted in the inherent complexity of XML parsing and document handling. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mini Xml Project over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-20004HIGH An issue has been found in Mini-XML (aka mxml) 2.12. It is a stack-based buffer overflow in mxml_write_node in mxml-file.c via vectors involving a double-precision floating point n | Dec 10, 2018 | 8.8 | 27 | NO | NO |
CVE-2021-42860HIGH A stack buffer overflow exists in Mini-XML v3.2. When inputting an unformed XML string to the mxmlLoadString API, it will cause a stack-buffer-overflow in mxml_string_getc:2611. NO | May 26, 2022 | 7.5 | 24 | NO | NO |
CVE-2021-42859HIGH A memory leak issue was discovered in Mini-XML v3.2 that could cause a denial of service. NOTE: testing reports are inconsistent, with some testers seeing the issue in both the 3.2 | May 26, 2022 | 7.5 | 24 | NO | NO |
CVE-2016-4571MEDIUM The mxml_write_node function in mxml-file.c in mxml 2.9, 2.7, and possibly earlier allows remote attackers to cause a denial of service (stack consumption) via crafted xml file. | Feb 3, 2017 | 5.5 | 21 | NO | NO |
CVE-2016-4570MEDIUM The mxmlDelete function in mxml-node.c in mxml 2.9, 2.7, and possibly earlier allows remote attackers to cause a denial of service (stack consumption) via crafted xml file. | Feb 3, 2017 | 5.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mini Xml Project.
Media articles that mention a CVE ID that affects a product developed by Mini Xml Project — matched by CVE ID, not by vendor name.