Skip to main content

Vendor archive

tozt CVEs

Beta · best-effort

2 CVEs tagged to vendor tozt0 Critical, 0 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2024-23525

Published Jan 18, 2024

The Spreadsheet::ParseXLSX package before 0.30 for Perl allows XXE attacks because it neglects to use the no_xxe option of XML::Twig.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-22368

Published Jan 9, 2024

The Spreadsheet::ParseXLSX package before 0.28 for Perl can encounter an out-of-memory condition during parsing of a crafted XLSX document. This occurs because the memoize impleme…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-2 of 2 CVEsPage 1 of 1