CVE-2019-5815 is a type confusion vulnerability in libxslt versions prior to 1.1.33, specifically within the xsltNumberFormatGetMultipleLevel function, affecting products like Debian Linux and xmlsoft libxslt. This flaw could allow an unauthenticated attacker to trigger heap corruption by providing specially crafted XML data. Rated as HIGH severity (CVSS 7.5), it carries a significant impact of high availability loss, although confidentiality and integrity are not directly affected. While there are no known public exploits or Metasploit/Nuclei modules, and it's not listed on the KEV catalog, the vulnerability has garnered some community discussion and media coverage, indicating a degree of awareness despite its inactive exploitation status.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.1.33CPE matchmatch criteria | cpe:2.3:a:xmlsoft:libxslt:*:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* | ||
< 74.0.3729.108CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.