CVE-2019-6246: Svgpp
Critical severity, CVSS 9.8. EPSS: 1.8% chance of exploitation in the next 30 days.
An issue was discovered in SVG++ (aka svgpp) 1.2.3. After calling the gil::get_color function in Generic Image Library in Boost, the return code is used as an address, leading to an Access Violation because of an out-of-bounds read.
Affected products
- Svgpp Svgpp: version 1.2.3 only
Published 2019-01-13. Last modified 2026-06-17.