Vulnerability Database

289,599

Total vulnerabilities in the database

CVE-2019-13118

In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was too narrow and an invalid character/length combination could be passed to xsltNumberFormatDecimal, leading to a read of uninitialized stack data.

CVSS v3:

  • Severity: Medium
  • Score: 5.3
  • AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CVSS v2:

  • Severity: Medium
  • Score: 5
  • AV:N/AC:L/Au:N/C:P/I:N/A:N

CWEs:

Software From Fixed in
xmlsoft / libxslt 1.1.33 1.1.33.x
opensuse / leap 15.1 15.1.x
netapp / e-series_santricity_os_controller 11.0 11.50.2.x
oracle / jdk 1.8.0-update231 1.8.0-update231.x
fedoraproject / fedora 31 31.x
canonical / ubuntu_linux 18.04 18.04.x
canonical / ubuntu_linux 19.04 19.04.x
canonical / ubuntu_linux 14.04 14.04.x
canonical / ubuntu_linux 19.10 19.10.x
canonical / ubuntu_linux 16.04 16.04.x
canonical / ubuntu_linux 12.04 12.04.x
apple / tvos - 12.4
apple / iphone_os - 12.4
apple / icloud - 7.13
apple / itunes - 12.9.6
apple / icloud 10.0 10.6
apple / mac_os_x 10.13.6-security_update_2019-003 10.13.6-security_update_2019-003.x
apple / mac_os_x 10.13.6-security_update_2019-002 10.13.6-security_update_2019-002.x
apple / mac_os_x 10.13.6-security_update_2019-001 10.13.6-security_update_2019-001.x
apple / mac_os_x 10.12.6-security_update_2019-003 10.12.6-security_update_2019-003.x
apple / mac_os_x 10.12.6-security_update_2019-002 10.12.6-security_update_2019-002.x
apple / mac_os_x 10.12.6-security_update_2019-001 10.12.6-security_update_2019-001.x
apple / macos 10.4.6 10.14.6
nokogiri - 1.10.5