CVE-2019-5033: Aspose Aspose.cells
High severity, CVSS 8.8. EPSS: 3.1% chance of exploitation in the next 30 days.
An exploitable out-of-bounds read vulnerability exists in the Number record parser of Aspose Aspose.Cells 19.1.0 library. A specially crafted XLS file can cause an out-of-bounds read, resulting in remote code execution. An attacker needs to provide a malformed file to the victim to trigger the vulnerability.
Affected products
- Aspose Aspose.cells: version 19.1.0 only
Published 2019-08-21. Last modified 2026-06-17.