QSearchQSearch

CVE-2019-11068

9.8 CRITICAL

libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upo...

Published: 2019-04-10 · Last updated: 2026-05-28

Severity and scoring

CVSS
9.8 CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

VendorProduct
canonicalactive_iq_unified_manager, cloud_backup, debian_linux
debianactive_iq_unified_manager, cloud_backup, debian_linux
fedoraprojectactive_iq_unified_manager, cloud_backup, debian_linux
netappactive_iq_unified_manager, cloud_backup, debian_linux
opensuseactive_iq_unified_manager, cloud_backup, debian_linux
oracleactive_iq_unified_manager, cloud_backup, debian_linux
xmlsoftactive_iq_unified_manager, cloud_backup, debian_linux

Description

libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code. xsltCheckRead can return -1 for a crafted URL that is not actually invalid and is subsequently loaded.

Source: NVD

References

Related CVEs

Same vendor

  • CVE-2026-35273 Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management) (9.8 CRITICAL)
  • CVE-2026-49975 Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP ... (7.5 HIGH)
  • CVE-2026-46843 Vulnerability in Oracle REST Data Services (component: Core) (5.3 MEDIUM)
  • CVE-2026-46842 Vulnerability in Oracle REST Data Services (component: Core) (5.3 MEDIUM)
  • CVE-2026-46841 Vulnerability in Oracle REST Data Services (component: General) (5.3 MEDIUM)