Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Jgm

#17898of 53,624
15Total CVSS
Vulnerabilities · 2
High
2
PT-2022-11601
7.5
2022-12-18
Unknown · Xml-Conduit · CVE-2021-4249
**Name of the Vulnerable Software and Affected Versions** xml-conduit versions prior to 1.9.1.0 **Description** A vulnerability was found in the DOCTYPE Entity Expansion Handler component of xml-conduit, affecting an unknown function of the file xml-conduit/src/Text/XML/Stream/Parse.hs. The manipulation leads to an infinite loop and can be launched remotely. **Recommendations** For versions prior to 1.9.1.0, upgrade to version 1.9.1.0 to address this issue. As a temporary workaround, consider restricting the use of the DOCTYPE Entity Expansion Handler component until the upgrade is applied.
PT-2021-22272
7.5
2021-08-16
Gitit · Gitit · CVE-2021-38711
**Name of the Vulnerable Software and Affected Versions** gitit versions prior to 0.15.0.0 **Description** The Export feature in gitit can be exploited to leak information from files. **Recommendations** For versions prior to 0.15.0.0, update to version 0.15.0.0 or later to resolve the issue.