CVEs from 2019

3,175 normalized CVEs published or assigned in this year.

Total
3,175
critical
critical 231
high
high 484
medium
medium 483
low
low 94
% Critical
7.3%
% with KEV
3.7%
% with exploit
7.9%

Top products

  • u-boot 20
  • crimson 8
  • active_iq_unified_manager 7
  • weblogic_server 5
  • jdk 5
  • oncommand_workflow_automation 5
  • codeready_linux_builder_eus 4
  • oncommand_insight 4
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2019-13697 high 8.0 Insufficient policy enforcement in performance APIs in Google Chrome prior to 77.0.3865.120 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
CVE-2019-13707 high 8.0 Insufficient validation of untrusted input in intents in Google Chrome on Android prior to 78.0.3904.70 allowed a local attacker to leak files via a crafted application.
CVE-2019-13710 high 8.0 Insufficient validation of untrusted input in downloads in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to bypass download restrictions via a crafted HTML page.
CVE-2019-5853 high 8.0 Inappropriate implementation in JavaScript in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2019-0190 high 8.0 A bug exists in the way mod_ssl handled client renegotiations. A remote attacker could send a carefully crafted request that would cause mod_ssl to enter a loop leading to a denial of service. This b…
CVE-2019-13711 high 8.0 Insufficient policy enforcement in JavaScript in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
CVE-2019-5803 high 8.0 Insufficient policy enforcement in Content Security Policy in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to bypass content security policy via a crafted HTML page.
CVE-2019-13718 high 8.0 Insufficient data validation in Omnibox in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
CVE-2019-5867 high 8.0 Out of bounds read in JavaScript in Google Chrome prior to 76.0.3809.100 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2019-8343 high 8.0 In Netwide Assembler (NASM) 2.14.02, there is a use-after-free in paste_tokens in asm/preproc.c.
CVE-2019-5858 high 8.0 Incorrect security UI in MacOS services integration in Google Chrome on OS X prior to 76.0.3809.87 allowed a local attacker to execute arbitrary code via a crafted HTML page.
CVE-2019-0053 high 8.0 Insufficient validation of environment variables in the telnet client supplied in Junos OS can lead to stack-based buffer overflows, which can be exploited to bypass veriexec restrictions on Junos OS…
CVE-2019-5793 high 8.0 Insufficient policy enforcement in extensions in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to initiate the extensions installation user interface via a crafted HTML page.
CVE-2019-8381 high 8.0 An issue was discovered in Tcpreplay 4.3.1. An invalid memory access occurs in do_checksum in checksum.c. It can be triggered by sending a crafted pcap file to the tcpreplay-edit binary. It allows an…
CVE-2019-12881 high 8.0 i915_gem_userptr_get_pages in drivers/gpu/drm/i915/i915_gem_userptr.c in the Linux kernel 4.15.0 on Ubuntu 18.04.2 allows local users to cause a denial of service (NULL pointer dereference and BUG) o…
CVE-2019-13709 high 8.0 Insufficient policy enforcement in downloads in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to bypass download restrictions via a crafted HTML page.
CVE-2019-1351 high 8.0 A tampering vulnerability exists when Git for Visual Studio improperly handles virtual drive paths, aka 'Git for Visual Studio Tampering Vulnerability'.
CVE-2019-5865 high 8.0 Insufficient policy enforcement in navigations in Google Chrome prior to 76.0.3809.87 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML pa…
CVE-2019-6472 high 8.0 A packet containing a malformed DUID can cause the Kea DHCPv6 server process (kea-dhcp6) to exit due to an assertion failure. Versions affected: 1.4.0 to 1.5.0, 1.6.0-beta1, and 1.6.0-beta2.
CVE-2019-5864 high 8.0 Insufficient data validation in CORS in Google Chrome prior to 76.0.3809.87 allowed an attacker who convinced a user to install a malicious extension to bypass content security policy via a crafted C…
CVE-2019-11737 high 8.0 If a wildcard ('*') is specified for the host in Content Security Policy (CSP) directives, any port or path restriction of the directive will be ignored, leading to CSP directives not being properly …
CVE-2019-5800 high 8.0 Insufficient policy enforcement in Blink in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to bypass content security policy via a crafted HTML page.
CVE-2019-11461 high 8.0 An issue was discovered in GNOME Nautilus 3.30 prior to 3.30.6 and 3.32 prior to 3.32.1. A compromised thumbnailer may escape the bubblewrap sandbox used to confine thumbnailers by using the TIOCSTI …
CVE-2019-5862 high 8.0 Insufficient data validation in AppCache in Google Chrome prior to 76.0.3809.87 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.
CVE-2019-5868 high 8.0 Use after free in PDFium in Google Chrome prior to 76.0.3809.100 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
CVE-2019-6474 high 8.0 A missing check on incoming client requests can be exploited to cause a situation where the Kea server's lease storage contains leases which are rejected as invalid when the server tries to load leas…
CVE-2019-18182 high 8.0 arbitrary command execution in pacman
CVE-2019-1353 high 8.0 An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. When running Git in the Windows Subsystem for Linux (also known…
CVE-2019-13694 high 8.0 Use after free in WebRTC in Google Chrome prior to 77.0.3865.120 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2019-19604 high 8.0 Arbitrary command execution is possible in Git before 2.20.2, 2.21.x before 2.21.1, 2.22.x before 2.22.2, 2.23.x before 2.23.1, and 2.24.x before 2.24.1 because a "git submodule update" operation can…
CVE-2019-8376 high 8.0 An issue was discovered in Tcpreplay 4.3.1. A NULL pointer dereference occurred in the function get_layer4_v6() located at get.c. This can be triggered by sending a crafted pcap file to the tcpreplay…
CVE-2019-1350 high 8.0 A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-201…
CVE-2019-13696 high 8.0 Use after free in JavaScript in Google Chrome prior to 77.0.3865.120 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2019-9686 high 8.0 arbitrary code execution in pacman
CVE-2019-11734 high 8.0 Mozilla developers and community members reported memory safety bugs present in Firefox 68. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of…
CVE-2019-18183 high 8.0 arbitrary command execution in pacman
CVE-2019-5861 high 8.0 Insufficient data validation in Blink in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to bypass anti-clickjacking policy via a crafted HTML page.
CVE-2019-11683 high 8.0 udp_gro_receive_segment in net/ipv4/udp_offload.c in the Linux kernel 5.x before 5.0.13 allows remote attackers to cause a denial of service (slab-out-of-bounds memory corruption) or possibly have un…
CVE-2019-14318 high 8.0 Crypto++ 8.3.0 and earlier contains a timing side channel in ECDSA signature generation. This allows a local or remote attacker, able to measure the duration of hundreds to thousands of signing opera…
CVE-2019-19450 high 8.0 3y ago RHSA-2023:5790: python-reportlab security update (Important)
CVE-2019-17626 high 8.0 4y ago RHSA-2020:0201: python-reportlab security update (Important)
CVE-2019-10195 high 8.0 4y ago RHBA-2019:4268: idm:DL1 bug fix update (Important)
CVE-2019-18466 high 8.0 4y ago RHSA-2019:4269: container-tools:rhel8 security and bug fix update (Important)
CVE-2019-9514 high 8.0 4y ago RHSA-2019:4273: container-tools:1.0 security update (Important)
CVE-2019-9512 high 8.0 4y ago RHSA-2019:4273: container-tools:1.0 security update (Important)
CVE-2019-10354 high 8.0 4y ago Missing Authorization in Jenkins
CVE-2019-10353 high 8.0 4y ago Cross-Site Request Forgery in Jenkins
CVE-2019-10352 high 8.0 4y ago Improper Limitation of a Pathname to a Restricted Directory in Jenkins
CVE-2019-0981 high 8.0 4y ago RHSA-2019:1259: dotnet security, bug fix, and enhancement update (Important)
CVE-2019-0980 high 8.0 4y ago RHSA-2019:1259: dotnet security, bug fix, and enhancement update (Important)
CVE-2019-2435 high 8.0 4y ago Improper Access Control in MySQL Connector Python
CVE-2019-5885 high 8.0 4y ago Matrix Synapse before 0.34.0.1, when the macaroon_secret_key authentication parameter is not set, uses a predictable value to derive a secret key and other secrets which could allow remote attackers …
CVE-2019-16884 high 8.0 4y ago RHSA-2019:4269: container-tools:rhel8 security and bug fix update (Important)
CVE-2019-10214 high 8.0 4y ago RHSA-2019:3494: container-tools:1.0 security and bug fix update (Important)
CVE-2019-14867 high 8.0 5y ago RHBA-2019:4268: idm:DL1 bug fix update (Important)
CVE-2019-0820 high 8.0 5y ago RHSA-2019:1259: dotnet security, bug fix, and enhancement update (Important)
CVE-2019-18811 high 8.0 5y ago A memory leak in the sof_set_get_large_ctrl_data() function in sound/soc/sof/ipc.c in the Linux kernel through 5.3.9 allows attackers to cause a denial of service (memory consumption) by triggering s…
CVE-2019-19528 high 8.0 5y ago In the Linux kernel before 5.3.7, there is a use-after-free bug that can be caused by a malicious USB device in the drivers/usb/misc/iowarrior.c driver, aka CID-edc4746f253d.
CVE-2019-19523 high 8.0 5y ago In the Linux kernel before 5.3.7, there is a use-after-free bug that can be caused by a malicious USB device in the drivers/usb/misc/adutux.c driver, aka CID-44efc269db79.
CVE-2019-2938 high 8.0 6y ago RHSA-2020:5500: mariadb:10.3 security, bug fix, and enhancement update (Important)
CVE-2019-2974 high 8.0 6y ago RHSA-2020:5500: mariadb:10.3 security, bug fix, and enhancement update (Important)
CVE-2019-2960 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2019-3009 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2019-3011 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2019-3004 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2019-2998 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2019-2968 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2019-2993 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2019-2967 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2019-2997 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2019-2982 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2019-2991 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2019-2911 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2019-2963 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2019-2957 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2019-2966 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2019-2914 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2019-3018 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2019-2946 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2019-10208 high 8.0 6y ago RHSA-2020:5619: postgresql:9.6 security update (Important)
CVE-2019-10130 high 8.0 6y ago RHSA-2020:5619: postgresql:9.6 security update (Important)
CVE-2019-17639 high 8.0 6y ago RHSA-2020:3386: java-1.8.0-ibm security update (Important)
CVE-2019-3016 high 8.0 6y ago In a Linux KVM guest that has PV TLB enabled, a process in the guest kernel may be able to read memory locations from another process in the same guest. This problem is limit to the host running linu…
CVE-2019-19807 high 8.0 6y ago In the Linux kernel before 5.3.11, sound/core/timer.c has a use-after-free caused by erroneous code refactoring, aka CID-e7af6307a8a5. This is related to snd_timer_open and snd_timer_close_locked. Th…
CVE-2019-20382 high 8.0 6y ago QEMU 4.1.0 has a memory leak in zrle_compress_data in ui/vnc-enc-zrle.c during a VNC disconnect operation because libz is misused, resulting in a situation where memory allocated in deflateInit2 is n…
CVE-2019-10086 high 8.0 6y ago RHSA-2025:9318: javapackages-tools:201801 security update (Important)
CVE-2019-0199 high 8.0 6y ago The HTTP/2 implementation in Apache Tomcat 9.0.0.M1 to 9.0.14 and 8.5.0 to 8.5.37 accepted streams with excessive numbers of SETTINGS frames and also permitted clients to keep streams open without re…
CVE-2019-12519 high 8.0 6y ago RHSA-2020:2041: squid:4 security update (Important)
CVE-2019-12525 high 8.0 6y ago RHSA-2020:2041: squid:4 security update (Important)
CVE-2019-19073 high 8.0 6y ago Memory leaks in drivers/net/wireless/ath/ath9k/htc_hst.c in the Linux kernel through 5.3.11 allow attackers to cause a denial of service (memory consumption) by triggering wait_for_completion_timeout…
CVE-2019-19074 high 8.0 6y ago A memory leak in the ath9k_wmi_cmd() function in drivers/net/wireless/ath/ath9k/wmi.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption), aka CID-72…
CVE-2019-15099 high 8.0 6y ago drivers/net/wireless/ath/ath10k/usb.c in the Linux kernel through 5.2.8 has a NULL pointer dereference via an incomplete address in an endpoint descriptor.
CVE-2019-19065 high 8.0 6y ago A memory leak in the sdma_init() function in drivers/infiniband/hw/hfi1/sdma.c in the Linux kernel before 5.3.9 allows attackers to cause a denial of service (memory consumption) by triggering rhasht…
CVE-2019-16234 high 8.0 6y ago drivers/net/wireless/intel/iwlwifi/pcie/trans.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer dereference.
CVE-2019-12819 high 8.0 6y ago An issue was discovered in the Linux kernel before 5.0. The function __mdiobus_register() in drivers/net/phy/mdio_bus.c calls put_device(), which will trigger a fixed_mdio_bus_init use-after-free. Th…
CVE-2019-17053 high 8.0 6y ago ieee802154_create in net/ieee802154/socket.c in the AF_IEEE802154 network module in the Linux kernel through 5.3.2 does not enforce CAP_NET_RAW, which means that unprivileged users can create a raw s…
CVE-2019-19768 high 8.0 6y ago In the Linux kernel 5.4.0-rc2, there is a use-after-free (read) in the __blk_add_trace function in kernel/trace/blktrace.c (which is used to fill out a blk_io_trace structure and place it in a per-cp…
CVE-2019-15221 high 8.0 6y ago An issue was discovered in the Linux kernel before 5.1.17. There is a NULL pointer dereference caused by a malicious USB device in the sound/usb/line6/pcm.c driver.
CVE-2019-16746 high 8.0 6y ago An issue was discovered in net/wireless/nl80211.c in the Linux kernel through 5.2.17. It does not check the length of variable elements in a beacon head, leading to a buffer overflow.
CVE-2019-19077 high 8.0 6y ago A memory leak in the bnxt_re_create_srq() function in drivers/infiniband/hw/bnxt_re/ib_verbs.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by…