Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2019-20395

A stack consumption issue is present in libyang before v1.0-r1 due to the self-referential union type containing leafrefs. Applications that use libyang to parse untrusted input yang files may crash.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 37.2%
CVSS Severity
CVSS v3 Score 6.5
CVSS v2 Score 4.3
Products affected by CVE-2019-20395
  • Cesnet » Libyang » Version: 0.11
    cpe:2.3:a:cesnet:libyang:0.11
  • Cesnet » Libyang » Version: 0.12
    cpe:2.3:a:cesnet:libyang:0.12
  • Cesnet » Libyang » Version: 0.13
    cpe:2.3:a:cesnet:libyang:0.13
  • Cesnet » Libyang » Version: 0.14
    cpe:2.3:a:cesnet:libyang:0.14
  • Cesnet » Libyang » Version: 0.15
    cpe:2.3:a:cesnet:libyang:0.15
  • Cesnet » Libyang » Version: 0.16
    cpe:2.3:a:cesnet:libyang:0.16


Contact Us

Shodan ® - All rights reserved