Search CVE reports


Toggle filters

11 – 19 of 19 results


CVE-2019-20397

Medium priority
Vulnerable

A double-free is present in libyang before v1.0-r1 in the function yyparse() when an organization field is not terminated. Applications that use libyang to parse untrusted input yang files may be vulnerable to this flaw, which...

1 affected package

libyang

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libyang Not affected Not in release Not affected Vulnerable Not in release
Show less packages

CVE-2019-20396

Medium priority
Vulnerable

A segmentation fault is present in yyparse in libyang before v1.0-r1 due to a malformed pattern statement value during lys_parse_path parsing.

1 affected package

libyang

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libyang Not affected Not in release Not affected Vulnerable Not in release
Show less packages

CVE-2019-20395

Medium priority
Vulnerable

A stack consumption issue is present in libyang before v1.0-r1 due to the self-referential union type containing leafrefs. Applications that use libyang to parse untrusted input yang files may crash.

2 affected packages

libyang, libyang2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libyang Not affected Not in release Not affected Vulnerable Not in release
libyang2 Not in release Not affected Not affected Not in release Not in release
Show less packages

CVE-2019-20394

Medium priority
Vulnerable

A double-free is present in libyang before v1.0-r3 in the function yyparse() when a type statement in used in a notification statement. Applications that use libyang to parse untrusted input yang files may be vulnerable to this...

1 affected package

libyang

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libyang Not affected Not in release Not affected Vulnerable Not in release
Show less packages

CVE-2019-20393

Medium priority
Vulnerable

A double-free is present in libyang before v1.0-r1 in the function yyparse() when an empty description is used. Applications that use libyang to parse untrusted input yang files may be vulnerable to this flaw, which would cause a...

1 affected package

libyang

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libyang Not affected Not in release Not affected Vulnerable Not in release
Show less packages

CVE-2019-20392

Medium priority
Vulnerable

An invalid memory access flaw is present in libyang before v1.0-r1 in the function resolve_feature_value() when an if-feature statement is used inside a list key node, and the feature used is not defined. Applications that use...

1 affected package

libyang

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libyang Not affected Not in release Not affected Vulnerable Not in release
Show less packages

CVE-2019-20391

Medium priority
Vulnerable

An invalid memory access flaw is present in libyang before v1.0-r3 in the function resolve_feature_value() when an if-feature statement is used inside a bit. Applications that use libyang to parse untrusted input yang files may crash.

1 affected package

libyang

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libyang Not affected Not in release Not affected Vulnerable Not in release
Show less packages

CVE-2019-19334

Medium priority
Ignored

In all versions of libyang before 1.0-r5, a stack-based buffer overflow was discovered in the way libyang parses YANG files with a leaf of type "identityref". An application that uses libyang to parse untrusted YANG files may be...

1 affected package

libyang

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libyang Not affected Not in release
Show less packages

CVE-2019-19333

Medium priority
Ignored

In all versions of libyang before 1.0-r5, a stack-based buffer overflow was discovered in the way libyang parses YANG files with a leaf of type "bits". An application that uses libyang to parse untrusted YANG files may...

1 affected package

libyang

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libyang Not affected Not in release
Show less packages