CVE-2010-2947

Severity CVSS v4.0:
Pending analysis
Type:
CWE-119 Buffer Errors
Publication date:
24/08/2010
Last modified:
11/04/2025

Description

Heap-based buffer overflow in the HX_split function in string.c in libHX before 3.6 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a string that is inconsistent with the expected number of fields.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:jan_engelhardt:libhx:*:*:*:*:*:*:*:* 3.5 (including)
cpe:2.3:a:jan_engelhardt:libhx:1.10.0:*:*:*:*:*:*:*
cpe:2.3:a:jan_engelhardt:libhx:1.10.1:*:*:*:*:*:*:*
cpe:2.3:a:jan_engelhardt:libhx:1.10.2:*:*:*:*:*:*:*
cpe:2.3:a:jan_engelhardt:libhx:1.15:*:*:*:*:*:*:*
cpe:2.3:a:jan_engelhardt:libhx:1.17:*:*:*:*:*:*:*
cpe:2.3:a:jan_engelhardt:libhx:1.18:*:*:*:*:*:*:*
cpe:2.3:a:jan_engelhardt:libhx:1.22:*:*:*:*:*:*:*
cpe:2.3:a:jan_engelhardt:libhx:1.23:*:*:*:*:*:*:*
cpe:2.3:a:jan_engelhardt:libhx:1.25:*:*:*:*:*:*:*
cpe:2.3:a:jan_engelhardt:libhx:1.26:*:*:*:*:*:*:*
cpe:2.3:a:jan_engelhardt:libhx:1.27:*:*:*:*:*:*:*
cpe:2.3:a:jan_engelhardt:libhx:1.28:*:*:*:*:*:*:*
cpe:2.3:a:jan_engelhardt:libhx:2.0:*:*:*:*:*:*:*
cpe:2.3:a:jan_engelhardt:libhx:2.1:*:*:*:*:*:*:*