Msweet develops a focused portfolio of lightweight parsing and document-handling libraries, including Mini-XML for data serialization, CodeDoc for documentation generation, and PDFIO for PDF manipulation, that see broad use in embedded and server applications. The vulnerability surface concentrates on memory-safety weaknesses characteristic of C-based codebases—use-after-free conditions, buffer overflows, out-of-bounds writes, and infinite-loop flaws—that arise from input parsing across these libraries. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Msweet over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-20593MEDIUM In Mini-XML (aka mxml) v2.12, there is stack-based buffer overflow in the scan_file function in mxmldoc.c. | Dec 30, 2018 | 5.5 | 20 | NO | NO |
CVE-2018-20592MEDIUM In Mini-XML (aka mxml) v2.12, there is a use-after-free in the mxmlAdd function of the mxml-node.c file. Remote attackers could leverage this vulnerability to cause a denial-of-ser | Dec 30, 2018 | 5.5 | 20 | NO | NO |
CVE-2018-20005MEDIUM An issue has been found in Mini-XML (aka mxml) 2.12. It is a use-after-free in mxmlWalkNext in mxml-search.c, as demonstrated by mxmldoc. | Dec 10, 2018 | 5.5 | 20 | NO | NO |
CVE-2023-38850MEDIUM Buffer Overflow vulnerability in Michaelrsweet codedoc v.3.7 allows an attacker to cause a denial of service via the codedoc.c:1742 comppnent. | Aug 15, 2023 | 5.5 | 18 | NO | NO |
CVE-2024-42358MEDIUM PDFio is a simple C library for reading and writing PDF files. There is a denial of service (DOS) vulnerability in the TTF parser. Maliciously crafted TTF files can cause the progr | Aug 6, 2024 | 5.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Msweet.
Media articles that mention a CVE ID that affects a product developed by Msweet — matched by CVE ID, not by vendor name.