In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was too narrow and an invalid character/length combination could be passed to xsltNumberFormatDecimal, leading to a read of uninitialized stack data.
Metrics
Affected Vendors & Products
References
History
Thu, 28 May 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: mitre
Published: 2019-07-01T01:27:39.000Z
Updated: 2026-05-28T18:36:48.291Z
Reserved: 2019-06-30T00:00:00.000Z
Link: CVE-2019-13118
Updated: 2024-08-04T23:41:10.546Z
Status : Modified
Published: 2019-07-01T02:15:09.800
Modified: 2026-05-28T19:16:29.950
Link: CVE-2019-13118