CVE-2019-5815

HIGH

Xmlsoft Libxslt < 1.1.33 - Out-of-Bounds Write

Title source: rule
STIX 2.1

Description

Type confusion in xsltNumberFormatGetMultipleLevel prior to libxslt 1.1.33 could allow attackers to potentially exploit heap corruption via crafted XML data.

Scores

CVSS v3 7.5
EPSS 0.0011
EPSS Percentile 29.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-843 CWE-787
Status published
Products (3)
debian/debian_linux 10.0
rubygems/nokogiri 0 - 1.10.5RubyGems
xmlsoft/libxslt < 1.1.33
Published Dec 11, 2019
Tracked Since Feb 18, 2026