Mini Xml
Vendor:
First CVE: Feb 3, 2017 · Active for 9 years
5
Total CVEs
More Total CVEs than 77% of tracked products
1.7
Avg CVEs / Year
Higher CVE frequency than 59% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 40% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Mini Xml over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 3, 2017
9 years ago
Most Recent CVE
May 26, 2022
1,520 days ago
CVE Severity & Scoring
Mini Xml5 CVEs
40%
60%
All CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local2 (40.0%)
Network3 (60.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None2 (40.0%)
Unknown0 (0.0%)
Required3 (60.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None5 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-20004HIGH An issue has been found in Mini-XML (aka mxml) 2.12. It is a stack-based buffer overflow in mxml_write_node in mxml-file.c via vectors involving a double-precision floating point n | Dec 10, 2018 | 8.8 | 27 | NO | NO |
CVE-2021-42860HIGH A stack buffer overflow exists in Mini-XML v3.2. When inputting an unformed XML string to the mxmlLoadString API, it will cause a stack-buffer-overflow in mxml_string_getc:2611. NO | May 26, 2022 | 7.5 | 24 | NO | NO |
CVE-2021-42859HIGH A memory leak issue was discovered in Mini-XML v3.2 that could cause a denial of service. NOTE: testing reports are inconsistent, with some testers seeing the issue in both the 3.2 | May 26, 2022 | 7.5 | 24 | NO | NO |
CVE-2016-4571MEDIUM The mxml_write_node function in mxml-file.c in mxml 2.9, 2.7, and possibly earlier allows remote attackers to cause a denial of service (stack consumption) via crafted xml file. | Feb 3, 2017 | 5.5 | 21 | NO | NO |
CVE-2016-4570MEDIUM The mxmlDelete function in mxml-node.c in mxml 2.9, 2.7, and possibly earlier allows remote attackers to cause a denial of service (stack consumption) via crafted xml file. | Feb 3, 2017 | 5.5 | 21 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (5 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (5 CVEs).
Media Mentions
Signals from CVEs in this product scope (5 CVEs).
Top CNAs Publishing CVEs For Mini Xml
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.2 | 2 | 7.5 | 1.0% | 0 | 0 |
| 2.9 | 2 | 5.5 | 1.6% | 0 | 0 |
| 2.12 | 1 | 8.8 | 2.0% | 0 | 0 |