[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2019-19204":6},{"stargazers_count":4,"fetched_at":5},7,"2026-06-05T14:55:33.319Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":23,"aliases":38,"duplicate_of":9,"upstream":39,"downstream":40,"duplicates":69,"related":70,"reserved_at":9,"published_at":74,"modified_at":75,"state":76,"summary":77,"references_raw":85,"kevs":128,"epss":129,"epss_history":132,"metrics":389,"affected":399},"CVE-2019-19204","An issue was discovered in Oniguruma 6.x before 6.9.4_rc2. In the function fetch_interval_quantifier (formerly known as fetch_range_quantifier) in regparse.c, PFETCH is called without checking PEND. This leads to a heap-based buffer over-read.",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":9,"capec":18},"CWE-125","Out-of-bounds Read","The product reads data past the end, or before the beginning, of the intended buffer.","weakness","Draft","Base",[19],{"id":20,"name":21,"techniques":22},"CAPEC-540","Overread Buffers",[],[24,33],{"_key":25,"name":26,"source":27,"url":28,"maturity":29,"reliability_score":30,"verified":31,"type":9,"platforms":32,"requires_auth":9,"exploitdb":9,"metasploit":9},"GITHUB_KKOS_ONIGURUMA","Oniguruma","github","https://github.com/kkos/oniguruma/issues/57","poc",0.3,false,[],{"_key":34,"name":35,"source":27,"url":36,"maturity":29,"reliability_score":30,"verified":31,"type":9,"platforms":37,"requires_auth":9,"exploitdb":9,"metasploit":9},"GITHUB_MANHNDD_CVE-2019-19204","Cve 2019 19204","https://github.com/ManhNDd/CVE-2019-19204",[],[],[],[41,43,45,47,49,51,53,55,57,59,61,63,65,67],{"_key":42},"SUSE-SU-2022:3327-1",{"_key":44},"OPENSUSE-SU-2024:11111-1",{"_key":46},"RHSA-2020:5275",{"_key":48},"DLA-2020-1",{"_key":50},"DLA-2431-1",{"_key":52},"MGASA-2020-0029",{"_key":54},"UBUNTU-CVE-2019-19204",{"_key":56},"USN-4460-1",{"_key":58},"RHSA-2024:0409",{"_key":60},"RHSA-2024:0572",{"_key":62},"RHSA-2024:0889",{"_key":64},"DEBIAN-CVE-2019-19204",{"_key":66},"RHSA-2020:3662",{"_key":68},"USN-5662-1",[],[71,72,73],{"_key":42},{"_key":44},{"_key":52},"2019-11-21T20:06:47.000Z","2024-08-05T02:09:39.457Z","Modified",{"cisa_kev":31,"cisa_ransomware":31,"cisa_vendor":9,"epss_severity":78,"epss_score":79,"severity":80,"severity_score":81,"severity_version":82,"severity_source":83,"severity_vector":84,"severity_status":76},"low",0.08946,"high",7.5,"v3.1","nvd","CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",[86,93,100,103,109,115,119,123],{"url":87,"sources":88,"tags":90},"https://github.com/kkos/oniguruma/releases/tag/v6.9.4_rc2",[89,83],"cve.org",[91,92],"X Refsource MISC","Release Notes",{"url":94,"sources":95,"tags":96},"https://github.com/kkos/oniguruma/issues/162",[89,83],[91,97,98,99],"Exploit","Patch","Third Party Advisory",{"url":36,"sources":101,"tags":102},[89,83],[91,97,99],{"url":104,"sources":105,"tags":106},"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NO267PLHGYZSWX3XTRPKYBKD4J3YOU5V/",[89,83],[107,108],"Vendor Advisory","X Refsource FEDORA",{"url":110,"sources":111,"tags":112},"https://lists.debian.org/debian-lts-announce/2019/12/msg00002.html",[89,83],[113,114,99],"Mailing List","X Refsource MLIST",{"url":116,"sources":117,"tags":118},"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V3MBNW6Z4DOXSCNWGBLQ7OA3OGUJ44WL/",[89,83],[107,108],{"url":120,"sources":121,"tags":122},"https://github.com/tarantula-team/CVE-2019-19204",[89,83],[91,99],{"url":124,"sources":125,"tags":126},"https://usn.ubuntu.com/4460-1/",[89,83],[107,127],"X Refsource UBUNTU",[],{"date":130,"score":79,"percentile":131},"2026-06-04",0.92741,[133,136,139,142,145,147,149,151,154,157,160,163,166,169,172,176,179,182,185,188,191,194,197,200,203,206,209,212,215,218,221,224,227,230,233,236,239,242,245,248,251,254,256,259,262,265,268,270,273,276,278,281,284,287,290,292,295,298,301,304,307,310,313,316,318,321,324,327,330,333,335,337,340,342,345,348,351,354,357,360,363,366,369,372,375,377,379,381,383,386],{"date":134,"score":79,"percentile":135},"2025-11-04",0.9222,{"date":137,"score":79,"percentile":138},"2025-11-05",0.92221,{"date":140,"score":79,"percentile":141},"2025-11-06",0.92223,{"date":143,"score":79,"percentile":144},"2025-11-07",0.92225,{"date":146,"score":79,"percentile":141},"2025-11-08",{"date":148,"score":79,"percentile":135},"2025-11-09",{"date":150,"score":79,"percentile":138},"2025-11-10",{"date":152,"score":79,"percentile":153},"2025-11-11",0.92227,{"date":155,"score":79,"percentile":156},"2025-11-12",0.92232,{"date":158,"score":79,"percentile":159},"2025-11-13",0.92235,{"date":161,"score":79,"percentile":162},"2025-11-14",0.92237,{"date":164,"score":79,"percentile":165},"2025-11-15",0.92234,{"date":167,"score":79,"percentile":168},"2025-11-16",0.92241,{"date":170,"score":79,"percentile":171},"2025-11-17",0.92239,{"date":173,"score":174,"percentile":175},"2025-11-18",0.24983,0.9582,{"date":177,"score":174,"percentile":178},"2025-11-19",0.95822,{"date":180,"score":174,"percentile":181},"2025-11-20",0.95823,{"date":183,"score":79,"percentile":184},"2025-11-21",0.9225,{"date":186,"score":79,"percentile":187},"2025-11-22",0.92249,{"date":189,"score":79,"percentile":190},"2025-11-23",0.92255,{"date":192,"score":79,"percentile":193},"2025-11-24",0.92256,{"date":195,"score":79,"percentile":196},"2025-11-25",0.92258,{"date":198,"score":79,"percentile":199},"2025-11-26",0.92257,{"date":201,"score":79,"percentile":202},"2025-11-27",0.92254,{"date":204,"score":79,"percentile":205},"2025-11-28",0.92246,{"date":207,"score":79,"percentile":208},"2025-11-29",0.92264,{"date":210,"score":79,"percentile":211},"2025-11-30",0.92261,{"date":213,"score":79,"percentile":214},"2025-12-01",0.92306,{"date":216,"score":79,"percentile":217},"2025-12-02",0.9231,{"date":219,"score":79,"percentile":220},"2025-12-03",0.92313,{"date":222,"score":79,"percentile":223},"2025-12-04",0.92269,{"date":225,"score":79,"percentile":226},"2025-12-05",0.92273,{"date":228,"score":79,"percentile":229},"2025-12-06",0.92278,{"date":231,"score":79,"percentile":232},"2025-12-07",0.92277,{"date":234,"score":79,"percentile":235},"2025-12-08",0.92279,{"date":237,"score":79,"percentile":238},"2025-12-09",0.92281,{"date":240,"score":79,"percentile":241},"2025-12-10",0.92292,{"date":243,"score":79,"percentile":244},"2025-12-11",0.92294,{"date":246,"score":79,"percentile":247},"2025-12-12",0.92298,{"date":249,"score":79,"percentile":250},"2025-12-13",0.9229,{"date":252,"score":79,"percentile":253},"2025-12-14",0.92287,{"date":255,"score":79,"percentile":250},"2025-12-15",{"date":257,"score":79,"percentile":258},"2025-12-16",0.92296,{"date":260,"score":79,"percentile":261},"2025-12-17",0.92301,{"date":263,"score":79,"percentile":264},"2025-12-18",0.92305,{"date":266,"score":79,"percentile":267},"2025-12-19",0.92308,{"date":269,"score":79,"percentile":267},"2025-12-20",{"date":271,"score":79,"percentile":272},"2025-12-21",0.92309,{"date":274,"score":79,"percentile":275},"2025-12-22",0.92307,{"date":277,"score":79,"percentile":217},"2025-12-23",{"date":279,"score":79,"percentile":280},"2025-12-24",0.92314,{"date":282,"score":79,"percentile":283},"2025-12-25",0.92319,{"date":285,"score":79,"percentile":286},"2025-12-26",0.92318,{"date":288,"score":79,"percentile":289},"2025-12-27",0.92348,{"date":291,"score":79,"percentile":280},"2025-12-28",{"date":293,"score":79,"percentile":294},"2025-12-29",0.92311,{"date":296,"score":79,"percentile":297},"2025-12-30",0.92315,{"date":299,"score":79,"percentile":300},"2025-12-31",0.92323,{"date":302,"score":79,"percentile":303},"2026-01-01",0.92377,{"date":305,"score":79,"percentile":306},"2026-01-02",0.92373,{"date":308,"score":79,"percentile":309},"2026-01-03",0.92371,{"date":311,"score":79,"percentile":312},"2026-01-04",0.92327,{"date":314,"score":79,"percentile":315},"2026-01-05",0.92325,{"date":317,"score":79,"percentile":312},"2026-01-06",{"date":319,"score":79,"percentile":320},"2026-01-07",0.92328,{"date":322,"score":79,"percentile":323},"2026-01-08",0.92331,{"date":325,"score":79,"percentile":326},"2026-01-09",0.92334,{"date":328,"score":79,"percentile":329},"2026-01-10",0.92335,{"date":331,"score":79,"percentile":332},"2026-01-11",0.9233,{"date":334,"score":79,"percentile":332},"2026-01-12",{"date":336,"score":79,"percentile":332},"2026-01-13",{"date":338,"score":79,"percentile":339},"2026-01-14",0.92341,{"date":341,"score":79,"percentile":339},"2026-01-15",{"date":343,"score":79,"percentile":344},"2026-01-16",0.92343,{"date":346,"score":79,"percentile":347},"2026-01-17",0.92344,{"date":349,"score":79,"percentile":350},"2026-01-18",0.92337,{"date":352,"score":79,"percentile":353},"2026-01-19",0.92339,{"date":355,"score":79,"percentile":356},"2026-01-20",0.92342,{"date":358,"score":79,"percentile":359},"2026-01-21",0.92346,{"date":361,"score":79,"percentile":362},"2026-01-22",0.9235,{"date":364,"score":79,"percentile":365},"2026-01-23",0.92358,{"date":367,"score":79,"percentile":368},"2026-01-24",0.92363,{"date":370,"score":79,"percentile":371},"2026-01-25",0.92365,{"date":373,"score":79,"percentile":374},"2026-01-26",0.92368,{"date":376,"score":79,"percentile":309},"2026-01-27",{"date":378,"score":79,"percentile":306},"2026-01-28",{"date":380,"score":79,"percentile":306},"2026-01-29",{"date":382,"score":79,"percentile":309},"2026-01-30",{"date":384,"score":79,"percentile":385},"2026-01-31",0.92372,{"date":387,"score":79,"percentile":388},"2026-02-01",0.92412,[390],{"source":83,"cvss_v2_0":391,"cvss_v3_0":9,"cvss_v3_1":396,"cvss_v4_0":9},{"baseScore":392,"baseSeverity":9,"vectorString":393,"impactScore":394,"exploitabilityScore":395},5,"AV:N/AC:L/Au:N/C:N/I:N/A:P",2.9,10,{"baseScore":81,"baseSeverity":397,"vectorString":84,"impactScore":398,"exploitabilityScore":395},"HIGH",6,[400,409,417],{"ecosystem":9,"name":401,"vendor":402,"product":403,"cpe_part":404,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":405},"debian linux","debian","debian_linux","o",[406],{"version":407,"is_range":31,"range_type":408,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"8.0","cpe",{"ecosystem":9,"name":410,"vendor":411,"product":410,"cpe_part":404,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":412},"fedora","fedoraproject",[413,415],{"version":414,"is_range":31,"range_type":408,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"30",{"version":416,"is_range":31,"range_type":408,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"31",{"ecosystem":9,"name":418,"vendor":419,"product":418,"cpe_part":420,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":421},"oniguruma","oniguruma_project","a",[422,429],{"version":423,"is_range":424,"range_type":408,"version_start":425,"version_start_type":426,"version_end":427,"version_end_type":428,"fixed_in":9},"gte6.0.0_lt6.9.4",true,"6.0.0","including","6.9.4","excluding",{"version":430,"is_range":31,"range_type":408,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"6.9.4:rc1"]