CVE-2019-13118 - CVE House
Back to Database
Status published Unknown CVE-2019-13118

In numbers.c in libxslt 1.1.33, a type holding grouping characters...

Vulnerability Description

In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was too narrow and an invalid character/length combination could be passed to xsltNumberFormatDecimal, leading to a read of uninitialized stack data.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-13118

Credits & Attribution

No credits recorded in the NVD database.

References

Affected Vendor

Affected Software

libxslt, leap, active iq unified manager, cloud backup, clustered data ontap, e-series performance analyzer, e-series santricity management plug-ins, e-series santricity os controller, e-series santricity storage manager, e-series santricity web services, oncommand insight, oncommand workflow automation, ontap select deploy administration utility, plug-in for symantec netbackup, santricity unified manager, steelstore cloud integrated storage, jdk, fedora, ubuntu linux, icloud, itunes, iphone os, mac os x, macos, tvos
Vulnerable Versions:
1.1.33, 15.1, 11.0, 1.8.0, 31, 12.04, 14.04, 16.04, 18.04, 19.04, 19.10, 0, 10.0, 10.12.6, 10.13.6, 10.4.6

Timeline

Official Publish: July 1st, 2019
Last Modified: May 28th, 2026
Added to House: July 20th, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.