CVE-2019-5815: Debian Linux

High severity, CVSS 7.5. EPSS: 1.8% chance of exploitation in the next 30 days.

Type confusion in xsltNumberFormatGetMultipleLevel prior to libxslt 1.1.33 could allow attackers to potentially exploit heap corruption via crafted XML data.

Affected products

  • Debian Debian Linux: version 10.0 only
  • Xmlsoft Libxslt: before 1.1.33 (fixed in 1.1.33)

Published 2019-12-11. Last modified 2026-06-17.