漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Type Confusion in Lexbor Fragment Parser
Vulnerability Description
Lexbor is a web browser engine library. Prior to 2.7.0, a type‑confusion vulnerability exists in Lexbor’s HTML fragment parser. When ns = UNDEF, a comment is created using the “unknown element” constructor. The comment’s data are written into the element’s fields via an unsafe cast, corrupting the qualified_name field. That corrupted value is later used as a pointer and dereferenced near the zero page. This vulnerability is fixed in 2.7.0.
CVSS Information
N/A
Vulnerability Type
使用不兼容类型访问资源(类型混淆)
Vulnerability Title
Lexbor 安全漏洞
Vulnerability Description
Lexbor是Lexbor开源的一个用于处理HTML和CSS的C语言工具库。 Lexbor 2.7.0之前版本存在安全漏洞,该漏洞源于HTML片段解析器存在类型混淆,可能导致指针取消引用。
CVSS Information
N/A
Vulnerability Type
N/A