Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The decode_entities function in util.c in HTML-Parser before 3.63 allows context-dependent attackers to cause a denial of service (infinite loop) via an incomplete SGML numeric character reference, which triggers generation of an invalid UTF-8 character.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
HTML-Parser无效HTML实体解析拒绝服务漏洞
Vulnerability Description
HTML Parser是用于解析线性或嵌套式HTML的Java库。 HTML-Parser存在无效HTML实体解析拒绝服务漏洞。由于utils.c的decode_entities()函数中存在一个错误,攻击者通过构造一个特殊的字符串以使HTML Parser在解析HTML实体中无效的UTF-8字符时触发死循环,导致拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A