0.005 Low
EPSS
Percentile
76.1%
Oniguruma through 6.9.3, as used in PHP 7.3.x and other products, has a heap-based buffer over-read in str_lower_case_match in regexec.c.
bugzilla.redhat.com/show_bug.cgi?id=1777537
nvd.nist.gov/vuln/detail/CVE-2019-19246
www.cve.org/CVERecord?id=CVE-2019-19246