Heap-based buffer overflow in the HX_split function in string.c in libHX before 3.6 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a string that is inconsistent with the expected number of fields.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.116
EPSS Ranking 93.3%