CVE-2024-50614

TinyXML2 through 10.0.0 has a reachable assertion for UINT_MAX/16, that may lead to application exit, in tinyxml2.cpp XMLUtil::GetCharacterRef.
References
Link Resource
https://github.com/leethomason/tinyxml2/issues/996 Exploit Issue Tracking
Configurations

Configuration 1 (hide)

cpe:2.3:a:tinyxml2_project:tinyxml2:*:*:*:*:*:*:*:*

History

04 Sep 2025, 16:42

Type Values Removed Values Added
First Time Tinyxml2 Project tinyxml2
Tinyxml2 Project
References () https://github.com/leethomason/tinyxml2/issues/996 - () https://github.com/leethomason/tinyxml2/issues/996 - Exploit, Issue Tracking
CPE cpe:2.3:a:tinyxml2_project:tinyxml2:*:*:*:*:*:*:*:*

30 Oct 2024, 20:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CWE CWE-617

28 Oct 2024, 13:58

Type Values Removed Values Added
Summary
  • (es) TinyXML2 a 10.0.0 tiene una afirmación alcanzable para UINT_MAX/16, que puede provocar la salida de la aplicación, en tinyxml2.cpp XMLUtil::GetCharacterRef.

27 Oct 2024, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-27 22:15

Updated : 2025-09-04 16:42


NVD link : CVE-2024-50614

Mitre link : CVE-2024-50614

CVE.ORG link : CVE-2024-50614


JSON object : View

Products Affected

tinyxml2_project

  • tinyxml2
CWE
CWE-617

Reachable Assertion