Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-42328


When the webdriver for the Browser object downloads data from a HTTP server, the data pointer is set to NULL and is allocated only in curl_write_cb when receiving data. If the server's response is an empty document, then wd->data in the code below will remain NULL and an attempt to read from it will result in a crash.


Published

2024-11-27T12:15:20.757

Last Modified

2025-10-08T16:42:23.020

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 3.3 (LOW)

Weaknesses
  • Type: Secondary
    CWE-476
    CWE-690

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application zabbix zabbix < 7.0.4 Yes

References