Vulnerabilities > Cesnet > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-01-22 CVE-2019-20395 Uncontrolled Recursion vulnerability in Cesnet Libyang
A stack consumption issue is present in libyang before v1.0-r1 due to the self-referential union type containing leafrefs.
network
low complexity
cesnet CWE-674
6.5
2020-01-22 CVE-2019-20392 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Cesnet Libyang
An invalid memory access flaw is present in libyang before v1.0-r1 in the function resolve_feature_value() when an if-feature statement is used inside a list key node, and the feature used is not defined.
network
low complexity
cesnet CWE-119
6.5
2020-01-22 CVE-2019-20391 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Cesnet Libyang
An invalid memory access flaw is present in libyang before v1.0-r3 in the function resolve_feature_value() when an if-feature statement is used inside a bit.
network
low complexity
cesnet CWE-119
6.5