CVE-2019-1010258 describes a buffer overflow vulnerability in the nanosvg library, specifically affecting versions after commit c1f6e209c16b18b46aa9f45d7e619acf42c29726. This flaw, located in the nsvg__parseColorRGB function, can lead to memory corruption and a denial-of-service condition, with potential for more severe impacts. Rated as Medium severity (CVSS 6.5), exploitation typically requires user interaction, such as opening a specially crafted SVG file, though network-based attacks are possible if the library processes untrusted network input. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:nanosvg_project:nanosvg:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.