Search CVE reports


Toggle filters

1 – 6 of 6 results


CVE-2025-6498

Medium priority
Vulnerable

A vulnerability classified as problematic has been found in HTACG tidy-html5 5.8.0. Affected is the function defaultAlloc of the file src/alloc.c. The manipulation leads to memory leak. It is possible to launch the attack on the...

1 affected package

tidy-html5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tidy-html5 Vulnerable Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2025-6497

Medium priority
Vulnerable

A vulnerability was found in HTACG tidy-html5 5.8.0. It has been rated as problematic. This issue affects the function prvTidyParseNamespace of the file src/parser.c. The manipulation leads to reachable assertion....

1 affected package

tidy-html5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tidy-html5 Vulnerable Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2025-6496

Medium priority
Vulnerable

A vulnerability was found in HTACG tidy-html5 5.8.0. It has been declared as problematic. This vulnerability affects the function InsertNodeAsParent of the file src/parser.c. The manipulation leads to null pointer dereference....

1 affected package

tidy-html5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tidy-html5 Vulnerable Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2021-33391

Medium priority

Some fixes available 7 of 9

An issue in HTACG HTML Tidy v5.7.28 allows attacker to execute arbitrary code via the -g option of the CleanNode() function in gdoc.c.

1 affected package

tidy-html5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tidy-html5 Fixed Fixed Fixed Vulnerable
Show less packages

CVE-2017-17497

Low priority
Ignored

In Tidy 5.7.0, the prvTidyTidyMetaCharset function in clean.c allows attackers to cause a denial of service (Segmentation Fault), because the currentNode variable in the "children of the head" processing feature is modified in the...

2 affected packages

tidy, tidy-html5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tidy Not in release Not in release
tidy-html5 Not affected Not affected
Show less packages

CVE-2017-13692

Medium priority
Not affected

In Tidy 5.5.31, the IsURLCodePoint function in attrs.c allows attackers to cause a denial of service (Segmentation Fault), as demonstrated by an invalid ISALNUM argument.

2 affected packages

tidy, tidy-html5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tidy
tidy-html5
Show less packages