CVE-2024-35333: HTML2XHTML Project HTML2XHTML

High severity, CVSS 8.4. EPSS: 0.4% chance of exploitation in the next 30 days.

A stack-buffer-overflow vulnerability exists in the read_charset_decl function of html2xhtml 1.3. This vulnerability occurs due to improper bounds checking when copying data into a fixed-size stack buffer. An attacker can exploit this vulnerability by providing a specially crafted input to the vulnerable function, causing a buffer overflow and potentially leading to arbitrary code execution, denial of service, or data corruption.

Affected products

Published 2024-05-29. Last modified 2026-06-17.