Yabasic is a small, open-source BASIC interpreter with a narrow but dedicated user base, and its limited disclosure history centers on memory-safety issues in the interpreter's core. The recurring weakness pattern reflects the challenge of safe bounds-checking in a language runtime; current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Yabasic over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-19720HIGH Yabasic 2.86.1 has a heap-based buffer overflow in the yylex() function in flex.c via a crafted BASIC source file. | Dec 11, 2019 | 8.8 | 28 | NO | NO |
CVE-2019-19796HIGH Yabasic 2.86.2 has a heap-based buffer overflow in myformat in function.c via a crafted BASIC source file. | Dec 13, 2019 | 7.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Yabasic.
Media articles that mention a CVE ID that affects a product developed by Yabasic — matched by CVE ID, not by vendor name.