← Vulnerability feed

Vulnerability record · CVE-2019-11637 · published 1 May 2019

CVE-2019-11637: Gnu recutils out-of-bounds read vulnerability

Gnu · Recutils

An issue was discovered in GNU recutils 1.8. There is a NULL pointer dereference in the function rec_rset_get_props at rec-rset.c in librec.a, leading to a crash.

6.5 CVSS 3.0 Medium EPSS 1.4% · top 28.4% CWE-125 · Out-of-bounds readCWE-476 · NULL pointer dereference
6.5CVSS 3.0 base score, v2 4.3
1.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An issue was discovered in GNU recutils 1.8. There is a NULL pointer dereference in the function rec_rset_get_props at rec-rset.c in librec.a, leading to a crash.

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-11637 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2019-11639Gnu recutils out-of-bounds write vulnerabilityAn issue was discovered in GNU recutils 1.8. There is a stack-based buffer overflow in the function rec_type_check_enum at rec-types.c in librec.a.EPSS 1.9%8.8CVE-2019-11640Gnu recutils out-of-bounds write vulnerabilityAn issue was discovered in GNU recutils 1.8. There is a heap-based buffer overflow in the function rec_fex_parse_str_simple at rec-fex.c in librec.a.EPSS 1.9%7.5CVE-2025-65409Gnu recutils divide by zero vulnerabilityA divide-by-zero in the encryption/decryption routines of GNU Recutils v1.9 allows attackers to cause a Denial of Service (DoS) via inputting an empt…EPSS 0.36%6.5CVE-2019-11638Gnu recutils out-of-bounds read vulnerabilityAn issue was discovered in GNU recutils 1.8. There is a NULL pointer dereference in the function rec_field_name_equal_p at rec-field-name.c in librec…EPSS 1.4%6.5CVE-2019-6455Gnu recutils double free vulnerabilityAn issue was discovered in GNU Recutils 1.8. There is a double-free problem in the function rec_mset_elem_destroy() in the file rec-mset.c.EPSS 1.3%6.5CVE-2019-6456Gnu recutils null pointer dereference vulnerabilityAn issue was discovered in GNU Recutils 1.8. There is a NULL pointer dereference in the function rec_fex_size() in the file rec-fex.c of librec.a.EPSS 1.3%6.5CVE-2019-6457Gnu recutils memory leak vulnerabilityAn issue was discovered in GNU Recutils 1.8. There is a memory leak in rec_aggregate_reg_new in rec-aggregate.c in librec.a.EPSS 1.3%6.5CVE-2019-6458Gnu recutils memory leak vulnerabilityAn issue was discovered in GNU Recutils 1.8. There is a memory leak in rec_buf_new in rec-buf.c when called from rec_parse_rset in rec-parser.c in li…EPSS 1.3%

Source: NIST National Vulnerability Database (record CVE-2019-11637), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.