CVEs from 2019

3,157 normalized CVEs published or assigned in this year.

Total
3,157
critical
critical 227
high
high 474
medium
medium 476
low
low 94
% Critical
7.2%
% with KEV
3.7%
% with exploit
8.0%

Top products

  • u-boot 20
  • crimson 8
  • active_iq_unified_manager 7
  • weblogic_server 5
  • jdk 5
  • oncommand_workflow_automation 5
  • codeready_linux_builder_eus 4
  • oncommand_insight 4
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2019-13693 high 8.0 Use after free in IndexedDB in Google Chrome prior to 77.0.3865.120 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page.
CVE-2019-5865 high 8.0 Insufficient policy enforcement in navigations in Google Chrome prior to 76.0.3809.87 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML pa…
CVE-2019-6956 high 8.0 An issue was discovered in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. It is a buffer over-read in ps_mix_phase in libfaad/ps_dec.c.
CVE-2019-5792 high 8.0 Integer overflow in PDFium in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially perform out of bounds memory access via a crafted PDF file.
CVE-2019-14318 high 8.0 Crypto++ 8.3.0 and earlier contains a timing side channel in ECDSA signature generation. This allows a local or remote attacker, able to measure the duration of hundreds to thousands of signing opera…
CVE-2019-1350 high 8.0 A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-201…
CVE-2019-6473 high 8.0 An invalid hostname option can trigger an assertion failure in the Kea DHCPv4 server process (kea-dhcp4), causing the server process to exit. Versions affected: 1.4.0 to 1.5.0, 1.6.0-beta1, and 1.6.0…
CVE-2019-5435 high 8.0 An integer overflow in curl's URL API results in a buffer overflow in libcurl 7.62.0 to and including 7.64.1.
CVE-2019-5850 high 8.0 Use after free in offline mode in Google Chrome prior to 76.0.3809.87 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML pag…
CVE-2019-11461 high 8.0 An issue was discovered in GNOME Nautilus 3.30 prior to 3.30.6 and 3.32 prior to 3.32.1. A compromised thumbnailer may escape the bubblewrap sandbox used to confine thumbnailers by using the TIOCSTI …
CVE-2019-13711 high 8.0 Insufficient policy enforcement in JavaScript in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
CVE-2019-5862 high 8.0 Insufficient data validation in AppCache in Google Chrome prior to 76.0.3809.87 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.
CVE-2019-5803 high 8.0 Insufficient policy enforcement in Content Security Policy in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to bypass content security policy via a crafted HTML page.
CVE-2019-5802 high 8.0 Incorrect handling of download origins in Navigation in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
CVE-2019-13699 high 8.0 Use after free in media in Google Chrome prior to 78.0.3904.70 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
CVE-2019-1353 high 8.0 An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. When running Git in the Windows Subsystem for Linux (also known…
CVE-2019-0053 high 8.0 Insufficient validation of environment variables in the telnet client supplied in Junos OS can lead to stack-based buffer overflows, which can be exploited to bypass veriexec restrictions on Junos OS…
CVE-2019-19604 high 8.0 Arbitrary command execution is possible in Git before 2.20.2, 2.21.x before 2.21.1, 2.22.x before 2.22.2, 2.23.x before 2.23.1, and 2.24.x before 2.24.1 because a "git submodule update" operation can…
CVE-2019-5864 high 8.0 Insufficient data validation in CORS in Google Chrome prior to 76.0.3809.87 allowed an attacker who convinced a user to install a malicious extension to bypass content security policy via a crafted C…
CVE-2019-5852 high 8.0 Inappropriate implementation in JavaScript in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
CVE-2019-18183 high 8.0 arbitrary command execution in pacman
CVE-2019-18182 high 8.0 arbitrary command execution in pacman
CVE-2019-13708 high 8.0 Inappropriate implementation in navigation in Google Chrome on iOS prior to 78.0.3904.70 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
CVE-2019-6472 high 8.0 A packet containing a malformed DUID can cause the Kea DHCPv6 server process (kea-dhcp6) to exit due to an assertion failure. Versions affected: 1.4.0 to 1.5.0, 1.6.0-beta1, and 1.6.0-beta2.
CVE-2019-6133 high 8.0 In PolicyKit (aka polkit) 0.115, the "start time" protection mechanism can be bypassed because fork() is not atomic, and therefore authorization decisions are improperly cached. This is related to la…
CVE-2019-13710 high 8.0 Insufficient validation of untrusted input in downloads in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to bypass download restrictions via a crafted HTML page.
CVE-2019-15717 high 8.0 Irssi 1.2.x before 1.2.2 has a use-after-free if the IRC server sends a double CAP.
CVE-2019-13709 high 8.0 Insufficient policy enforcement in downloads in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to bypass download restrictions via a crafted HTML page.
CVE-2019-7524 high 8.0 In Dovecot before 2.2.36.3 and 2.3.x before 2.3.5.1, a local attacker can cause a buffer overflow in the indexer-worker process, which can be used to elevate to root. This occurs because of missing c…
CVE-2019-13695 high 8.0 Use after free in audio in Google Chrome on Android prior to 77.0.3865.120 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2019-11741 high 8.0 A compromised sandboxed content process can perform a Universal Cross-site Scripting (UXSS) attack on content from any site it can cause to be loaded in the same process. Because addons.mozilla.org a…
CVE-2019-19450 high 8.0 3y ago RHSA-2023:5790: python-reportlab security update (Important)
CVE-2019-17626 high 8.0 4y ago RHSA-2020:0201: python-reportlab security update (Important)
CVE-2019-10195 high 8.0 4y ago RHBA-2019:4268: idm:DL1 bug fix update (Important)
CVE-2019-18466 high 8.0 4y ago RHSA-2019:4269: container-tools:rhel8 security and bug fix update (Important)
CVE-2019-9514 high 8.0 4y ago RHSA-2019:4273: container-tools:1.0 security update (Important)
CVE-2019-9512 high 8.0 4y ago RHSA-2019:4273: container-tools:1.0 security update (Important)
CVE-2019-10352 high 8.0 4y ago Improper Limitation of a Pathname to a Restricted Directory in Jenkins
CVE-2019-10353 high 8.0 4y ago Cross-Site Request Forgery in Jenkins
CVE-2019-10354 high 8.0 4y ago Missing Authorization in Jenkins
CVE-2019-0981 high 8.0 4y ago RHSA-2019:1259: dotnet security, bug fix, and enhancement update (Important)
CVE-2019-0980 high 8.0 4y ago RHSA-2019:1259: dotnet security, bug fix, and enhancement update (Important)
CVE-2019-2435 high 8.0 4y ago Improper Access Control in MySQL Connector Python
CVE-2019-5885 high 8.0 4y ago Matrix Synapse before 0.34.0.1, when the macaroon_secret_key authentication parameter is not set, uses a predictable value to derive a secret key and other secrets which could allow remote attackers …
CVE-2019-16884 high 8.0 4y ago RHSA-2019:4269: container-tools:rhel8 security and bug fix update (Important)
CVE-2019-10214 high 8.0 4y ago RHSA-2019:3494: container-tools:1.0 security and bug fix update (Important)
CVE-2019-14867 high 8.0 5y ago RHBA-2019:4268: idm:DL1 bug fix update (Important)
CVE-2019-0820 high 8.0 5y ago RHSA-2019:1259: dotnet security, bug fix, and enhancement update (Important)
CVE-2019-19523 high 8.0 5y ago In the Linux kernel before 5.3.7, there is a use-after-free bug that can be caused by a malicious USB device in the drivers/usb/misc/adutux.c driver, aka CID-44efc269db79.
CVE-2019-19528 high 8.0 5y ago In the Linux kernel before 5.3.7, there is a use-after-free bug that can be caused by a malicious USB device in the drivers/usb/misc/iowarrior.c driver, aka CID-edc4746f253d.
CVE-2019-18811 high 8.0 5y ago A memory leak in the sof_set_get_large_ctrl_data() function in sound/soc/sof/ipc.c in the Linux kernel through 5.3.9 allows attackers to cause a denial of service (memory consumption) by triggering s…
CVE-2019-2938 high 8.0 6y ago RHSA-2020:5500: mariadb:10.3 security, bug fix, and enhancement update (Important)
CVE-2019-2974 high 8.0 6y ago RHSA-2020:5500: mariadb:10.3 security, bug fix, and enhancement update (Important)
CVE-2019-2960 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2019-3004 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2019-3009 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2019-3011 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2019-2963 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2019-2911 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2019-2966 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2019-3018 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2019-2914 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2019-2957 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2019-2946 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2019-2997 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2019-2967 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2019-2982 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2019-2998 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2019-2991 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2019-2993 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2019-2968 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2019-10130 high 8.0 6y ago RHSA-2020:5619: postgresql:9.6 security update (Important)
CVE-2019-10208 high 8.0 6y ago RHSA-2020:5619: postgresql:9.6 security update (Important)
CVE-2019-17639 high 8.0 6y ago RHSA-2020:3386: java-1.8.0-ibm security update (Important)
CVE-2019-19807 high 8.0 6y ago In the Linux kernel before 5.3.11, sound/core/timer.c has a use-after-free caused by erroneous code refactoring, aka CID-e7af6307a8a5. This is related to snd_timer_open and snd_timer_close_locked. Th…
CVE-2019-3016 high 8.0 6y ago In a Linux KVM guest that has PV TLB enabled, a process in the guest kernel may be able to read memory locations from another process in the same guest. This problem is limit to the host running linu…
CVE-2019-20382 high 8.0 6y ago QEMU 4.1.0 has a memory leak in zrle_compress_data in ui/vnc-enc-zrle.c during a VNC disconnect operation because libz is misused, resulting in a situation where memory allocated in deflateInit2 is n…
CVE-2019-10086 high 8.0 6y ago RHSA-2025:9318: javapackages-tools:201801 security update (Important)
CVE-2019-0199 high 8.0 6y ago The HTTP/2 implementation in Apache Tomcat 9.0.0.M1 to 9.0.14 and 8.5.0 to 8.5.37 accepted streams with excessive numbers of SETTINGS frames and also permitted clients to keep streams open without re…
CVE-2019-12525 high 8.0 6y ago RHSA-2020:2041: squid:4 security update (Important)
CVE-2019-12519 high 8.0 6y ago RHSA-2020:2041: squid:4 security update (Important)
CVE-2019-5108 high 8.0 6y ago An exploitable denial-of-service vulnerability exists in the Linux kernel prior to mainline 5.3. An attacker could exploit this vulnerability by triggering AP to send IAPP location updates for statio…
CVE-2019-16746 high 8.0 6y ago An issue was discovered in net/wireless/nl80211.c in the Linux kernel through 5.2.17. It does not check the length of variable elements in a beacon head, leading to a buffer overflow.
CVE-2019-16234 high 8.0 6y ago drivers/net/wireless/intel/iwlwifi/pcie/trans.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer dereference.
CVE-2019-17053 high 8.0 6y ago ieee802154_create in net/ieee802154/socket.c in the AF_IEEE802154 network module in the Linux kernel through 5.3.2 does not enforce CAP_NET_RAW, which means that unprivileged users can create a raw s…
CVE-2019-19074 high 8.0 6y ago A memory leak in the ath9k_wmi_cmd() function in drivers/net/wireless/ath/ath9k/wmi.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption), aka CID-72…
CVE-2019-8980 high 8.0 6y ago A memory leak in the kernel_read_file function in fs/exec.c in the Linux kernel through 4.20.11 allows attackers to cause a denial of service (memory consumption) by triggering vfs_read failures.
CVE-2019-19073 high 8.0 6y ago Memory leaks in drivers/net/wireless/ath/ath9k/htc_hst.c in the Linux kernel through 5.3.11 allow attackers to cause a denial of service (memory consumption) by triggering wait_for_completion_timeout…
CVE-2019-19065 high 8.0 6y ago A memory leak in the sdma_init() function in drivers/infiniband/hw/hfi1/sdma.c in the Linux kernel before 5.3.9 allows attackers to cause a denial of service (memory consumption) by triggering rhasht…
CVE-2019-19534 high 8.0 6y ago In the Linux kernel before 5.3.11, there is an info-leak bug that can be caused by a malicious USB device in the drivers/net/can/usb/peak_usb/pcan_usb_core.c driver, aka CID-f7a1337f0d29.
CVE-2019-12819 high 8.0 6y ago An issue was discovered in the Linux kernel before 5.0. The function __mdiobus_register() in drivers/net/phy/mdio_bus.c calls put_device(), which will trigger a fixed_mdio_bus_init use-after-free. Th…
CVE-2019-15221 high 8.0 6y ago An issue was discovered in the Linux kernel before 5.1.17. There is a NULL pointer dereference caused by a malicious USB device in the sound/usb/line6/pcm.c driver.
CVE-2019-18805 high 8.0 6y ago An issue was discovered in net/ipv4/sysctl_net_ipv4.c in the Linux kernel before 5.0.11. There is a net/ipv4/tcp_input.c signed integer overflow in tcp_ack_update_rtt() when userspace writes a very l…
CVE-2019-19532 high 8.0 6y ago In the Linux kernel before 5.3.9, there are multiple out-of-bounds write bugs that can be caused by a malicious USB device in the Linux kernel HID drivers, aka CID-d9d4b1e46d95. This affects drivers/…
CVE-2019-17055 high 8.0 6y ago base_sock_create in drivers/isdn/mISDN/socket.c in the AF_ISDN network module in the Linux kernel through 5.3.2 does not enforce CAP_NET_RAW, which means that unprivileged users can create a raw sock…
CVE-2019-15099 high 8.0 6y ago drivers/net/wireless/ath/ath10k/usb.c in the Linux kernel through 5.2.8 has a NULL pointer dereference via an incomplete address in an endpoint descriptor.
CVE-2019-19077 high 8.0 6y ago A memory leak in the bnxt_re_create_srq() function in drivers/infiniband/hw/bnxt_re/ib_verbs.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by…
CVE-2019-18282 high 8.0 6y ago The flow_dissector feature in the Linux kernel 4.3 through 5.x before 5.3.10 has a device tracking vulnerability, aka CID-55667441c84f. This occurs because the auto flowlabel of a UDP IPv6 packet rel…
CVE-2019-15090 high 8.0 6y ago An issue was discovered in drivers/scsi/qedi/qedi_dbg.c in the Linux kernel before 5.1.12. In the qedi_dbg_* family of functions, there is an out-of-bounds read.
CVE-2019-19047 high 8.0 6y ago A memory leak in the mlx5_fw_fatal_reporter_dump() function in drivers/net/ethernet/mellanox/mlx5/core/health.c in the Linux kernel before 5.3.11 allows attackers to cause a denial of service (memory…