htmldoc_project CVE Vulnerabilities & Metrics

Focus on htmldoc_project vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About htmldoc_project Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with htmldoc_project. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total htmldoc_project CVEs: 22
Earliest CVE date: 08 Dec 2019, 02:15 UTC
Latest CVE date: 01 Sep 2024, 22:15 UTC

Latest CVE reference: CVE-2024-45508

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 1

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -50.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -50.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical htmldoc_project CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 4.7

Max CVSS: 10.0

Critical CVEs (≥9): 1

CVSS Range vs. Count

Range Count
0.0-3.9 6
4.0-6.9 13
7.0-8.9 2
9.0-10.0 1

CVSS Distribution Chart

Top 5 Highest CVSS htmldoc_project CVEs

These are the five CVEs with the highest CVSS scores for htmldoc_project, sorted by severity first and recency.

All CVEs for htmldoc_project

CVE-2024-45508 htmldoc_project vulnerability CVSS: 0 01 Sep 2024, 22:15 UTC

HTMLDOC before 1.9.19 has an out-of-bounds write in parse_paragraph in ps-pdf.cxx because of an attempt to strip leading whitespace from a whitespace-only node.

CVE-2021-34121 htmldoc_project vulnerability CVSS: 0 18 Jul 2023, 14:15 UTC

An Out of Bounds flaw was discovered in htmodoc 1.9.12 in function parse_tree() in toc.cxx, this possibly leads to memory layout information leaking in the data. This might be used in a chain of vulnerability in order to reach code execution.

CVE-2021-34119 htmldoc_project vulnerability CVSS: 0 18 Jul 2023, 14:15 UTC

A flaw was discovered in htmodoc 1.9.12 in function parse_paragraph in ps-pdf.cxx ,this flaw possibly allows possible code execution and a denial of service via a crafted file.

CVE-2022-0137 htmldoc_project vulnerability CVSS: 0 14 Nov 2022, 18:15 UTC

A heap buffer overflow in image_set_mask function of HTMLDOC before 1.9.15 allows an attacker to write outside the buffer boundaries.

CVE-2022-34035 htmldoc_project vulnerability CVSS: 0 18 Jul 2022, 21:15 UTC

HTMLDoc v1.9.12 and below was discovered to contain a heap overflow via e_node htmldoc/htmldoc/html.cxx:588.

CVE-2022-34033 htmldoc_project vulnerability CVSS: 0 18 Jul 2022, 21:15 UTC

HTMLDoc v1.9.15 was discovered to contain a heap overflow via (write_header) /htmldoc/htmldoc/html.cxx:273.

CVE-2022-27114 htmldoc_project vulnerability CVSS: 4.3 09 May 2022, 17:15 UTC

There is a vulnerability in htmldoc 1.9.16. In image_load_jpeg function image.cxx when it calls malloc,'img->width' and 'img->height' they are large enough to cause an integer overflow. So, the malloc function may return a heap blosmaller than the expected size, and it will cause a buffer overflow/Address boundary error in the jpeg_read_scanlines function.

CVE-2022-28085 htmldoc_project vulnerability CVSS: 6.8 27 Apr 2022, 03:15 UTC

A flaw was found in htmldoc commit 31f7804. A heap buffer overflow in the function pdf_write_names in ps-pdf.cxx may lead to arbitrary code execution and Denial of Service (DoS).

CVE-2022-24191 htmldoc_project vulnerability CVSS: 4.3 04 Apr 2022, 11:15 UTC

In HTMLDOC 1.9.14, an infinite loop in the gif_read_lzw function can lead to a pointer arbitrarily pointing to heap memory and resulting in a buffer overflow.

CVE-2021-23165 htmldoc_project vulnerability CVSS: 10.0 16 Mar 2022, 15:15 UTC

A flaw was found in htmldoc before v1.9.12. Heap buffer overflow in pspdf_prepare_outpages(), in ps-pdf.cxx may lead to execute arbitrary code and denial of service.

CVE-2021-23158 htmldoc_project vulnerability CVSS: 7.5 16 Mar 2022, 15:15 UTC

A flaw was found in htmldoc in v1.9.12. Double-free in function pspdf_export(),in ps-pdf.cxx may result in a write-what-where condition, allowing an attacker to execute arbitrary code and denial of service.

CVE-2021-26948 htmldoc_project vulnerability CVSS: 6.8 03 Mar 2022, 23:15 UTC

Null pointer dereference in the htmldoc v1.9.11 and before may allow attackers to execute arbitrary code and cause a denial of service via a crafted html file.

CVE-2021-26259 htmldoc_project vulnerability CVSS: 6.8 03 Mar 2022, 23:15 UTC

A flaw was found in htmldoc in v1.9.12. Heap buffer overflow in render_table_row(),in ps-pdf.cxx may lead to arbitrary code execution and denial of service.

CVE-2021-23206 htmldoc_project vulnerability CVSS: 6.8 02 Mar 2022, 23:15 UTC

A flaw was found in htmldoc in v1.9.12 and prior. A stack buffer overflow in parse_table() in ps-pdf.cxx may lead to execute arbitrary code and denial of service.

CVE-2021-23191 htmldoc_project vulnerability CVSS: 6.8 02 Mar 2022, 23:15 UTC

A security issue was found in htmldoc v1.9.12 and before. A NULL pointer dereference in the function image_load_jpeg() in image.cxx may result in denial of service.

CVE-2021-23180 htmldoc_project vulnerability CVSS: 6.8 02 Mar 2022, 23:15 UTC

A flaw was found in htmldoc in v1.9.12 and before. Null pointer dereference in file_extension(),in file.c may lead to execute arbitrary code and denial of service.

CVE-2021-26252 htmldoc_project vulnerability CVSS: 6.8 24 Feb 2022, 19:15 UTC

A flaw was found in htmldoc in v1.9.12. Heap buffer overflow in pspdf_prepare_page(),in ps-pdf.cxx may lead to execute arbitrary code and denial of service.

CVE-2022-0534 htmldoc_project vulnerability CVSS: 4.3 09 Feb 2022, 23:15 UTC

A vulnerability was found in htmldoc version 1.9.15 where the stack out-of-bounds read takes place in gif_get_code() and occurs when opening a malicious GIF file, which can result in a crash (segmentation fault).

CVE-2021-43579 htmldoc_project vulnerability CVSS: 6.8 10 Jan 2022, 14:10 UTC

A stack-based buffer overflow in image_load_bmp() in HTMLDOC <= 1.9.13 results in remote code execution if the victim converts an HTML document linking to a crafted BMP file.

CVE-2021-40985 htmldoc_project vulnerability CVSS: 4.3 03 Nov 2021, 17:15 UTC

A stack-based buffer under-read in htmldoc before 1.9.12, allows attackers to cause a denial of service via a crafted BMP image to image_load_bmp.

CVE-2021-20308 htmldoc_project vulnerability CVSS: 7.5 05 Apr 2021, 22:15 UTC

Integer overflow in the htmldoc 1.9.11 and before may allow attackers to execute arbitrary code and cause a denial of service that is similar to CVE-2017-9181.

CVE-2019-19630 htmldoc_project vulnerability CVSS: 6.8 08 Dec 2019, 02:15 UTC

HTMLDOC 1.9.7 allows a stack-based buffer overflow in the hd_strlcpy() function in string.c (when called from render_contents in ps-pdf.cxx) via a crafted HTML document.