#logic-bug clear

CVE-2022-40304: libxml2 dict corruption via entity reference cycle (content[0]=0 on dict-owned pointer)

CVE-2022-40304 libxml2 dict corruption via entity reference cycles

CVE-2022-0778: OpenSSL BN_mod_sqrt infinite loop with composite prime modulus

CVE-2022-0778 — OpenSSL BN_mod_sqrt infinite loop on non-prime modulus via crafted EC certificate

CVE-2023-46218: curl cookie domain PSL check absent in Curl_cookie_getlist() — asymmetric validation logic bug

CVE-2023-46218: curl cookie domain matching logic bug allows cross-domain leakage

CVE-2023-27535: curl FTP connection reuse skips FTP_ACCOUNT / ALTERNATIVE_TO_USER / USE_SSL comparisons

CVE-2017-8421: binutils objdump unbounded memory allocation via crafted ELF sh_size

CVE-2022-40304: libxml2 dict corruption via entity reference cycle (ent->content[0]=0 on dict-owned memory)

CVE-2022-40304: libxml2 dict corruption from entity reference cycles

CVE-2022-40304: Dict Corruption via Entity Reference Cycles in libxml2

CVE-2022-0778: OpenSSL BN_mod_sqrt infinite loop via non-prime modulus in Tonelli-Shanks

CVE-2023-46218 — curl cookie mixed-case PSL bypass in Curl_cookie_add

CVE-2023-46218: curl cookie PSL check missing in Curl_cookie_getlist() — asymmetric validation logic-bug

CVE-2023-27535: curl FTP connection reuse misses ACCT/ALT-USER credentials

CVE-2017-8421: binutils objdump unbounded memory allocation via crafted ELF e_phnum / sh_size

CVE-2017-8421: binutils objdump unbounded allocation from forged ELF section metadata

CVE-2017-8421: Unbounded Memory Allocation in ELF Relocation Section Parsing