CVEs from 2019

3,175 normalized CVEs published or assigned in this year.

Total
3,175
critical
critical 231
high
high 484
medium
medium 483
low
low 94
% Critical
7.3%
% with KEV
3.7%
% with exploit
7.9%

Top products

  • u-boot 20
  • crimson 8
  • active_iq_unified_manager 7
  • weblogic_server 5
  • jdk 5
  • oncommand_workflow_automation 5
  • codeready_linux_builder_eus 4
  • oncommand_insight 4
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2019-5864 high 8.0 Insufficient data validation in CORS in Google Chrome prior to 76.0.3809.87 allowed an attacker who convinced a user to install a malicious extension to bypass content security policy via a crafted C…
CVE-2019-8907 high 8.0 do_core_note in readelf.c in libmagic.a in file 5.35 allows remote attackers to cause a denial of service (stack corruption and application crash) or possibly have unspecified other impact.
CVE-2019-11734 high 8.0 Mozilla developers and community members reported memory safety bugs present in Firefox 68. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of…
CVE-2019-7524 high 8.0 In Dovecot before 2.2.36.3 and 2.3.x before 2.3.5.1, a local attacker can cause a buffer overflow in the indexer-worker process, which can be used to elevate to root. This occurs because of missing c…
CVE-2019-11741 high 8.0 A compromised sandboxed content process can perform a Universal Cross-site Scripting (UXSS) attack on content from any site it can cause to be loaded in the same process. Because addons.mozilla.org a…
CVE-2019-5856 high 8.0 Insufficient policy enforcement in storage in Google Chrome prior to 76.0.3809.87 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.
CVE-2019-13715 high 8.0 Insufficient validation of untrusted input in Omnibox in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
CVE-2019-0053 high 8.0 Insufficient validation of environment variables in the telnet client supplied in Junos OS can lead to stack-based buffer overflows, which can be exploited to bypass veriexec restrictions on Junos OS…
CVE-2019-13697 high 8.0 Insufficient policy enforcement in performance APIs in Google Chrome prior to 77.0.3865.120 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
CVE-2019-5792 high 8.0 Integer overflow in PDFium in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially perform out of bounds memory access via a crafted PDF file.
CVE-2019-13700 high 8.0 Out of bounds memory access in the gamepad API in Google Chrome prior to 78.0.3904.70 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a c…
CVE-2019-5851 high 8.0 Use after free in WebAudio in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2019-18222 high 8.0 The ECDSA signature implementation in ecdsa.c in Arm Mbed Crypto 2.1 and Mbed TLS through 2.19.1 does not reduce the blinded scalar before computing the inverse, which allows a local attacker to reco…
CVE-2019-13719 high 8.0 Incorrect security UI in full screen mode in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to hide security UI via a crafted HTML page.
CVE-2019-6472 high 8.0 A packet containing a malformed DUID can cause the Kea DHCPv6 server process (kea-dhcp6) to exit due to an assertion failure. Versions affected: 1.4.0 to 1.5.0, 1.6.0-beta1, and 1.6.0-beta2.
CVE-2019-13701 high 8.0 Incorrect implementation in navigation in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
CVE-2019-5859 high 8.0 Insufficient filtering in URI schemes in Google Chrome on Windows prior to 76.0.3809.87 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
CVE-2019-13695 high 8.0 Use after free in audio in Google Chrome on Android prior to 77.0.3865.120 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2019-8343 high 8.0 In Netwide Assembler (NASM) 2.14.02, there is a use-after-free in paste_tokens in asm/preproc.c.
CVE-2019-13710 high 8.0 Insufficient validation of untrusted input in downloads in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to bypass download restrictions via a crafted HTML page.
CVE-2019-13711 high 8.0 Insufficient policy enforcement in JavaScript in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
CVE-2019-5855 high 8.0 Integer overflow in PDFium in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
CVE-2019-13699 high 8.0 Use after free in media in Google Chrome prior to 78.0.3904.70 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
CVE-2019-13705 high 8.0 Insufficient policy enforcement in extensions in Google Chrome prior to 78.0.3904.70 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted …
CVE-2019-13707 high 8.0 Insufficient validation of untrusted input in intents in Google Chrome on Android prior to 78.0.3904.70 allowed a local attacker to leak files via a crafted application.
CVE-2019-5848 high 8.0 Incorrect font handling in autofill in Google Chrome prior to 75.0.3770.142 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
CVE-2019-13716 high 8.0 Insufficient policy enforcement in service workers in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
CVE-2019-25016 high 8.0 In OpenDoas from 6.6 to 6.8 the users PATH variable was incorrectly inherited by authenticated executions if the authenticating rule allowed the user to execute any command. Rules that only allowed t…
CVE-2019-13717 high 8.0 Incorrect security UI in full screen mode in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to hide security UI via a crafted HTML page.
CVE-2019-8377 high 8.0 An issue was discovered in Tcpreplay 4.3.1. A NULL pointer dereference occurred in the function get_ipv6_l4proto() located at get.c. This can be triggered by sending a crafted pcap file to the tcprep…
CVE-2019-5857 high 8.0 Inappropriate implementation in JavaScript in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page.
CVE-2019-5853 high 8.0 Inappropriate implementation in JavaScript in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2019-13703 high 8.0 Insufficient policy enforcement in the Omnibox in Google Chrome on Android prior to 78.0.3904.70 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
CVE-2019-5847 high 8.0 Inappropriate implementation in JavaScript in Google Chrome prior to 75.0.3770.142 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2019-5858 high 8.0 Incorrect security UI in MacOS services integration in Google Chrome on OS X prior to 76.0.3809.87 allowed a local attacker to execute arbitrary code via a crafted HTML page.
CVE-2019-13693 high 8.0 Use after free in IndexedDB in Google Chrome prior to 77.0.3865.120 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page.
CVE-2019-8381 high 8.0 An issue was discovered in Tcpreplay 4.3.1. An invalid memory access occurs in do_checksum in checksum.c. It can be triggered by sending a crafted pcap file to the tcpreplay-edit binary. It allows an…
CVE-2019-13708 high 8.0 Inappropriate implementation in navigation in Google Chrome on iOS prior to 78.0.3904.70 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
CVE-2019-2201 high 8.0 In generate_jsimd_ycc_rgb_convert_neon of jsimd_arm64_neon.S, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution in an unprivileged proces…
CVE-2019-19450 high 8.0 3y ago RHSA-2023:5790: python-reportlab security update (Important)
CVE-2019-17626 high 8.0 4y ago RHSA-2020:0201: python-reportlab security update (Important)
CVE-2019-10195 high 8.0 4y ago RHBA-2019:4268: idm:DL1 bug fix update (Important)
CVE-2019-18466 high 8.0 4y ago RHSA-2019:4269: container-tools:rhel8 security and bug fix update (Important)
CVE-2019-9512 high 8.0 4y ago RHSA-2019:4273: container-tools:1.0 security update (Important)
CVE-2019-9514 high 8.0 4y ago RHSA-2019:4273: container-tools:1.0 security update (Important)
CVE-2019-10353 high 8.0 4y ago Cross-Site Request Forgery in Jenkins
CVE-2019-10354 high 8.0 4y ago Missing Authorization in Jenkins
CVE-2019-10352 high 8.0 4y ago Improper Limitation of a Pathname to a Restricted Directory in Jenkins
CVE-2019-0981 high 8.0 4y ago RHSA-2019:1259: dotnet security, bug fix, and enhancement update (Important)
CVE-2019-0980 high 8.0 4y ago RHSA-2019:1259: dotnet security, bug fix, and enhancement update (Important)
CVE-2019-2435 high 8.0 4y ago Improper Access Control in MySQL Connector Python
CVE-2019-5885 high 8.0 4y ago Matrix Synapse before 0.34.0.1, when the macaroon_secret_key authentication parameter is not set, uses a predictable value to derive a secret key and other secrets which could allow remote attackers …
CVE-2019-16884 high 8.0 4y ago RHSA-2019:4269: container-tools:rhel8 security and bug fix update (Important)
CVE-2019-10214 high 8.0 4y ago RHSA-2019:3494: container-tools:1.0 security and bug fix update (Important)
CVE-2019-14867 high 8.0 5y ago RHBA-2019:4268: idm:DL1 bug fix update (Important)
CVE-2019-0820 high 8.0 5y ago RHSA-2019:1259: dotnet security, bug fix, and enhancement update (Important)
CVE-2019-19528 high 8.0 5y ago In the Linux kernel before 5.3.7, there is a use-after-free bug that can be caused by a malicious USB device in the drivers/usb/misc/iowarrior.c driver, aka CID-edc4746f253d.
CVE-2019-19523 high 8.0 5y ago In the Linux kernel before 5.3.7, there is a use-after-free bug that can be caused by a malicious USB device in the drivers/usb/misc/adutux.c driver, aka CID-44efc269db79.
CVE-2019-18811 high 8.0 5y ago A memory leak in the sof_set_get_large_ctrl_data() function in sound/soc/sof/ipc.c in the Linux kernel through 5.3.9 allows attackers to cause a denial of service (memory consumption) by triggering s…
CVE-2019-2974 high 8.0 6y ago RHSA-2020:5500: mariadb:10.3 security, bug fix, and enhancement update (Important)
CVE-2019-2938 high 8.0 6y ago RHSA-2020:5500: mariadb:10.3 security, bug fix, and enhancement update (Important)
CVE-2019-2946 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2019-2914 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2019-2957 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2019-2911 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2019-2960 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2019-3018 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2019-2968 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2019-3009 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2019-2997 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2019-2963 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2019-3004 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2019-2967 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2019-2982 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2019-2998 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2019-2966 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2019-2991 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2019-2993 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2019-3011 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2019-10208 high 8.0 6y ago RHSA-2020:5619: postgresql:9.6 security update (Important)
CVE-2019-10130 high 8.0 6y ago RHSA-2020:5619: postgresql:9.6 security update (Important)
CVE-2019-17639 high 8.0 6y ago RHSA-2020:3386: java-1.8.0-ibm security update (Important)
CVE-2019-19807 high 8.0 6y ago In the Linux kernel before 5.3.11, sound/core/timer.c has a use-after-free caused by erroneous code refactoring, aka CID-e7af6307a8a5. This is related to snd_timer_open and snd_timer_close_locked. Th…
CVE-2019-3016 high 8.0 6y ago In a Linux KVM guest that has PV TLB enabled, a process in the guest kernel may be able to read memory locations from another process in the same guest. This problem is limit to the host running linu…
CVE-2019-20382 high 8.0 6y ago QEMU 4.1.0 has a memory leak in zrle_compress_data in ui/vnc-enc-zrle.c during a VNC disconnect operation because libz is misused, resulting in a situation where memory allocated in deflateInit2 is n…
CVE-2019-10086 high 8.0 6y ago RHSA-2025:9318: javapackages-tools:201801 security update (Important)
CVE-2019-0199 high 8.0 6y ago The HTTP/2 implementation in Apache Tomcat 9.0.0.M1 to 9.0.14 and 8.5.0 to 8.5.37 accepted streams with excessive numbers of SETTINGS frames and also permitted clients to keep streams open without re…
CVE-2019-12525 high 8.0 6y ago RHSA-2020:2041: squid:4 security update (Important)
CVE-2019-12519 high 8.0 6y ago RHSA-2020:2041: squid:4 security update (Important)
CVE-2019-17055 high 8.0 6y ago base_sock_create in drivers/isdn/mISDN/socket.c in the AF_ISDN network module in the Linux kernel through 5.3.2 does not enforce CAP_NET_RAW, which means that unprivileged users can create a raw sock…
CVE-2019-19057 high 8.0 6y ago Two memory leaks in the mwifiex_pcie_init_evt_ring() function in drivers/net/wireless/marvell/mwifiex/pcie.c in the Linux kernel through 5.3.11 allow attackers to cause a denial of service (memory co…
CVE-2019-19047 high 8.0 6y ago A memory leak in the mlx5_fw_fatal_reporter_dump() function in drivers/net/ethernet/mellanox/mlx5/core/health.c in the Linux kernel before 5.3.11 allows attackers to cause a denial of service (memory…
CVE-2019-19058 high 8.0 6y ago A memory leak in the alloc_sgtable() function in drivers/net/wireless/intel/iwlwifi/fw/dbg.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by t…
CVE-2019-19067 high 8.0 6y ago Four memory leaks in the acp_hw_init() function in drivers/gpu/drm/amd/amdgpu/amdgpu_acp.c in the Linux kernel before 5.3.8 allow attackers to cause a denial of service (memory consumption) by trigge…
CVE-2019-15099 high 8.0 6y ago drivers/net/wireless/ath/ath10k/usb.c in the Linux kernel through 5.2.8 has a NULL pointer dereference via an incomplete address in an endpoint descriptor.
CVE-2019-18282 high 8.0 6y ago The flow_dissector feature in the Linux kernel 4.3 through 5.x before 5.3.10 has a device tracking vulnerability, aka CID-55667441c84f. This occurs because the auto flowlabel of a UDP IPv6 packet rel…
CVE-2019-12819 high 8.0 6y ago An issue was discovered in the Linux kernel before 5.0. The function __mdiobus_register() in drivers/net/phy/mdio_bus.c calls put_device(), which will trigger a fixed_mdio_bus_init use-after-free. Th…
CVE-2019-19059 high 8.0 6y ago Multiple memory leaks in the iwl_pcie_ctxt_info_gen3_init() function in drivers/net/wireless/intel/iwlwifi/pcie/ctxt-info-gen3.c in the Linux kernel through 5.3.11 allow attackers to cause a denial o…
CVE-2019-18805 high 8.0 6y ago An issue was discovered in net/ipv4/sysctl_net_ipv4.c in the Linux kernel before 5.0.11. There is a net/ipv4/tcp_input.c signed integer overflow in tcp_ack_update_rtt() when userspace writes a very l…
CVE-2019-5108 high 8.0 6y ago An exploitable denial-of-service vulnerability exists in the Linux kernel prior to mainline 5.3. An attacker could exploit this vulnerability by triggering AP to send IAPP location updates for statio…