CVE-2019-13118

Modified
Published: 01 Jul 2019, 01:27
Last modified:28 May 2026, 18:36

Vulnerability Summary

Overall Risk (default)
low
21/100
CVSS Score
5.3 MEDIUM
v3.1 (nvd)
EPSS Score
1.01% LOW
1% probability -0.02%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

01 Jul 2019, 01:27
Published
Vulnerability first disclosed
28 May 2026, 18:36
Last Modified
Vulnerability information updated

Description

In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was too narrow and an invalid character/length combination could be passed to xsltNumberFormatDecimal, leading to a read of uninitialized stack data.

CVSS Metrics

  • v3.1MEDIUMScore: 5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
  • v2.0MEDIUMScore: 5AV:N/AC:L/Au:N/C:P/I:N/A:N

EPSS Trends

Current EPSS score: 1.01% Percentile: 77%

Techniques & Countermeasures

  • CWE-843Access of Resource Using Incompatible Type ('Type Confusion')

    The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.

Affected Systems

  • appleicloud

    < 7.13 | ≥ 10.0, < 10.6

  • appleiphone_os

    < 12.4

  • appleitunes

    < 12.9.6

  • applemac_os_x

    10.12.6:security_update_2019-001 | 10.12.6:security_update_2019-002 | 10.12.6:security_update_2019-003 | 10.13.6:security_update_2019-001 | 10.13.6:security_update_2019-002 | 10.13.6:security_update_2019-003

  • UnknownmacOS

    ≥ 10.4.6, < 10.14.6

  • appletvos

    < 12.4

  • canonicalubuntu_linux

    12.04 | 14.04 | 16.04 | 18.04 | 19.04 | 19.10

  • fedoraprojectfedora

    31

  • netappactive_iq_unified_manager

    na

  • netappcloud_backup

    na

  • netappclustered_data_ontap

    na

  • netappe-series_performance_analyzer

    na

  • netappe-series_santricity_management_plug-ins

    na

  • netappe-series_santricity_os_controller

    ≥ 11.0, ≤ 11.50.2

  • netappe-series_santricity_storage_manager

    na

  • netappe-series_santricity_web_services

    na

  • netapponcommand_insight

    na

  • netapponcommand_workflow_automation

    na

  • netappontap_select_deploy_administration_utility

    na

  • netappplug-in_for_symantec_netbackup

    na

  • netappsantricity_unified_manager

    na

  • netappsteelstore_cloud_integrated_storage

    na

  • opensuseleap

    15.1

  • oraclejdk

    1.8.0:update231

  • xmlsoftlibxslt

    1.1.33

References (41)