CVEs from 2019

3,175 normalized CVEs published or assigned in this year.

Total
3,175
critical
critical 231
high
high 484
medium
medium 483
low
low 94
% Critical
7.3%
% with KEV
3.7%
% with exploit
7.9%

Top products

  • u-boot 20
  • crimson 8
  • active_iq_unified_manager 7
  • weblogic_server 5
  • jdk 5
  • oncommand_workflow_automation 5
  • codeready_linux_builder_eus 4
  • oncommand_insight 4
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2019-11734 high 8.0 Mozilla developers and community members reported memory safety bugs present in Firefox 68. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of…
CVE-2019-5799 high 8.0 Incorrect inheritance of a new document's policy in Content Security Policy in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to bypass content security policy via a crafted HTML page.
CVE-2019-13704 high 8.0 Insufficient policy enforcement in navigation in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to bypass content security policy via a crafted HTML page.
CVE-2019-13715 high 8.0 Insufficient validation of untrusted input in Omnibox in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
CVE-2019-8907 high 8.0 do_core_note in readelf.c in libmagic.a in file 5.35 allows remote attackers to cause a denial of service (stack corruption and application crash) or possibly have unspecified other impact.
CVE-2019-13693 high 8.0 Use after free in IndexedDB in Google Chrome prior to 77.0.3865.120 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page.
CVE-2019-5852 high 8.0 Inappropriate implementation in JavaScript in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
CVE-2019-13711 high 8.0 Insufficient policy enforcement in JavaScript in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
CVE-2019-13717 high 8.0 Incorrect security UI in full screen mode in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to hide security UI via a crafted HTML page.
CVE-2019-13705 high 8.0 Insufficient policy enforcement in extensions in Google Chrome prior to 78.0.3904.70 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted …
CVE-2019-13699 high 8.0 Use after free in media in Google Chrome prior to 78.0.3904.70 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
CVE-2019-8377 high 8.0 An issue was discovered in Tcpreplay 4.3.1. A NULL pointer dereference occurred in the function get_ipv6_l4proto() located at get.c. This can be triggered by sending a crafted pcap file to the tcprep…
CVE-2019-2201 high 8.0 In generate_jsimd_ycc_rgb_convert_neon of jsimd_arm64_neon.S, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution in an unprivileged proces…
CVE-2019-12881 high 8.0 i915_gem_userptr_get_pages in drivers/gpu/drm/i915/i915_gem_userptr.c in the Linux kernel 4.15.0 on Ubuntu 18.04.2 allows local users to cause a denial of service (NULL pointer dereference and BUG) o…
CVE-2019-5854 high 8.0 Integer overflow in PDFium in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
CVE-2019-8343 high 8.0 In Netwide Assembler (NASM) 2.14.02, there is a use-after-free in paste_tokens in asm/preproc.c.
CVE-2019-5855 high 8.0 Integer overflow in PDFium in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
CVE-2019-5864 high 8.0 Insufficient data validation in CORS in Google Chrome prior to 76.0.3809.87 allowed an attacker who convinced a user to install a malicious extension to bypass content security policy via a crafted C…
CVE-2019-0190 high 8.0 A bug exists in the way mod_ssl handled client renegotiations. A remote attacker could send a carefully crafted request that would cause mod_ssl to enter a loop leading to a denial of service. This b…
CVE-2019-5792 high 8.0 Integer overflow in PDFium in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially perform out of bounds memory access via a crafted PDF file.
CVE-2019-5842 high 8.0 Use after free in Blink in Google Chrome prior to 75.0.3770.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2019-19604 high 8.0 Arbitrary command execution is possible in Git before 2.20.2, 2.21.x before 2.21.1, 2.22.x before 2.22.2, 2.23.x before 2.23.1, and 2.24.x before 2.24.1 because a "git submodule update" operation can…
CVE-2019-18183 high 8.0 arbitrary command execution in pacman
CVE-2019-5865 high 8.0 Insufficient policy enforcement in navigations in Google Chrome prior to 76.0.3809.87 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML pa…
CVE-2019-11741 high 8.0 A compromised sandboxed content process can perform a Universal Cross-site Scripting (UXSS) attack on content from any site it can cause to be loaded in the same process. Because addons.mozilla.org a…
CVE-2019-5802 high 8.0 Incorrect handling of download origins in Navigation in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
CVE-2019-1353 high 8.0 An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. When running Git in the Windows Subsystem for Linux (also known…
CVE-2019-6133 high 8.0 In PolicyKit (aka polkit) 0.115, the "start time" protection mechanism can be bypassed because fork() is not atomic, and therefore authorization decisions are improperly cached. This is related to la…
CVE-2019-5851 high 8.0 Use after free in WebAudio in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2019-7524 high 8.0 In Dovecot before 2.2.36.3 and 2.3.x before 2.3.5.1, a local attacker can cause a buffer overflow in the indexer-worker process, which can be used to elevate to root. This occurs because of missing c…
CVE-2019-14318 high 8.0 Crypto++ 8.3.0 and earlier contains a timing side channel in ECDSA signature generation. This allows a local or remote attacker, able to measure the duration of hundreds to thousands of signing opera…
CVE-2019-13700 high 8.0 Out of bounds memory access in the gamepad API in Google Chrome prior to 78.0.3904.70 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a c…
CVE-2019-5858 high 8.0 Incorrect security UI in MacOS services integration in Google Chrome on OS X prior to 76.0.3809.87 allowed a local attacker to execute arbitrary code via a crafted HTML page.
CVE-2019-18182 high 8.0 arbitrary command execution in pacman
CVE-2019-3871 high 8.0 A vulnerability was found in PowerDNS Authoritative Server before 4.0.7 and before 4.1.7. An insufficient validation of data coming from the user when building a HTTP request from a DNS query in the …
CVE-2019-15717 high 8.0 Irssi 1.2.x before 1.2.2 has a use-after-free if the IRC server sends a double CAP.
CVE-2019-1351 high 8.0 A tampering vulnerability exists when Git for Visual Studio improperly handles virtual drive paths, aka 'Git for Visual Studio Tampering Vulnerability'.
CVE-2019-5800 high 8.0 Insufficient policy enforcement in Blink in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to bypass content security policy via a crafted HTML page.
CVE-2019-19882 high 8.0 shadow 4.8, in certain circumstances affecting at least Gentoo, Arch Linux, and Void Linux, allows local users to obtain root access because setuid programs are misconfigured. Specifically, this affe…
CVE-2019-19450 high 8.0 3y ago RHSA-2023:5790: python-reportlab security update (Important)
CVE-2019-17626 high 8.0 4y ago RHSA-2020:0201: python-reportlab security update (Important)
CVE-2019-10195 high 8.0 4y ago RHBA-2019:4268: idm:DL1 bug fix update (Important)
CVE-2019-18466 high 8.0 4y ago RHSA-2019:4269: container-tools:rhel8 security and bug fix update (Important)
CVE-2019-9512 high 8.0 4y ago RHSA-2019:4273: container-tools:1.0 security update (Important)
CVE-2019-9514 high 8.0 4y ago RHSA-2019:4273: container-tools:1.0 security update (Important)
CVE-2019-10354 high 8.0 4y ago Missing Authorization in Jenkins
CVE-2019-10353 high 8.0 4y ago Cross-Site Request Forgery in Jenkins
CVE-2019-10352 high 8.0 4y ago Improper Limitation of a Pathname to a Restricted Directory in Jenkins
CVE-2019-0981 high 8.0 4y ago RHSA-2019:1259: dotnet security, bug fix, and enhancement update (Important)
CVE-2019-0980 high 8.0 4y ago RHSA-2019:1259: dotnet security, bug fix, and enhancement update (Important)
CVE-2019-2435 high 8.0 4y ago Improper Access Control in MySQL Connector Python
CVE-2019-5885 high 8.0 4y ago Matrix Synapse before 0.34.0.1, when the macaroon_secret_key authentication parameter is not set, uses a predictable value to derive a secret key and other secrets which could allow remote attackers …
CVE-2019-16884 high 8.0 4y ago RHSA-2019:4269: container-tools:rhel8 security and bug fix update (Important)
CVE-2019-10214 high 8.0 4y ago RHSA-2019:3494: container-tools:1.0 security and bug fix update (Important)
CVE-2019-14867 high 8.0 5y ago RHBA-2019:4268: idm:DL1 bug fix update (Important)
CVE-2019-0820 high 8.0 5y ago RHSA-2019:1259: dotnet security, bug fix, and enhancement update (Important)
CVE-2019-19523 high 8.0 5y ago In the Linux kernel before 5.3.7, there is a use-after-free bug that can be caused by a malicious USB device in the drivers/usb/misc/adutux.c driver, aka CID-44efc269db79.
CVE-2019-19528 high 8.0 5y ago In the Linux kernel before 5.3.7, there is a use-after-free bug that can be caused by a malicious USB device in the drivers/usb/misc/iowarrior.c driver, aka CID-edc4746f253d.
CVE-2019-18811 high 8.0 5y ago A memory leak in the sof_set_get_large_ctrl_data() function in sound/soc/sof/ipc.c in the Linux kernel through 5.3.9 allows attackers to cause a denial of service (memory consumption) by triggering s…
CVE-2019-2938 high 8.0 6y ago RHSA-2020:5500: mariadb:10.3 security, bug fix, and enhancement update (Important)
CVE-2019-2974 high 8.0 6y ago RHSA-2020:5500: mariadb:10.3 security, bug fix, and enhancement update (Important)
CVE-2019-3009 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2019-2946 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2019-2914 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2019-2998 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2019-3011 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2019-2911 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2019-2957 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2019-3004 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2019-2982 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2019-2960 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2019-2993 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2019-2963 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2019-2997 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2019-3018 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2019-2991 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2019-2967 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2019-2966 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2019-2968 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2019-10208 high 8.0 6y ago RHSA-2020:5619: postgresql:9.6 security update (Important)
CVE-2019-10130 high 8.0 6y ago RHSA-2020:5619: postgresql:9.6 security update (Important)
CVE-2019-17639 high 8.0 6y ago RHSA-2020:3386: java-1.8.0-ibm security update (Important)
CVE-2019-19807 high 8.0 6y ago In the Linux kernel before 5.3.11, sound/core/timer.c has a use-after-free caused by erroneous code refactoring, aka CID-e7af6307a8a5. This is related to snd_timer_open and snd_timer_close_locked. Th…
CVE-2019-3016 high 8.0 6y ago In a Linux KVM guest that has PV TLB enabled, a process in the guest kernel may be able to read memory locations from another process in the same guest. This problem is limit to the host running linu…
CVE-2019-20382 high 8.0 6y ago QEMU 4.1.0 has a memory leak in zrle_compress_data in ui/vnc-enc-zrle.c during a VNC disconnect operation because libz is misused, resulting in a situation where memory allocated in deflateInit2 is n…
CVE-2019-10086 high 8.0 6y ago RHSA-2025:9318: javapackages-tools:201801 security update (Important)
CVE-2019-0199 high 8.0 6y ago The HTTP/2 implementation in Apache Tomcat 9.0.0.M1 to 9.0.14 and 8.5.0 to 8.5.37 accepted streams with excessive numbers of SETTINGS frames and also permitted clients to keep streams open without re…
CVE-2019-12525 high 8.0 6y ago RHSA-2020:2041: squid:4 security update (Important)
CVE-2019-12519 high 8.0 6y ago RHSA-2020:2041: squid:4 security update (Important)
CVE-2019-10639 high 8.0 6y ago The Linux kernel 4.x (starting from 4.1) and 5.x before 5.0.8 allows Information Exposure (partial kernel address disclosure), leading to a KASLR bypass. Specifically, it is possible to extract the K…
CVE-2019-8980 high 8.0 6y ago A memory leak in the kernel_read_file function in fs/exec.c in the Linux kernel through 4.20.11 allows attackers to cause a denial of service (memory consumption) by triggering vfs_read failures.
CVE-2019-15223 high 8.0 6y ago An issue was discovered in the Linux kernel before 5.1.8. There is a NULL pointer dereference caused by a malicious USB device in the sound/usb/line6/driver.c driver.
CVE-2019-19768 high 8.0 6y ago In the Linux kernel 5.4.0-rc2, there is a use-after-free (read) in the __blk_add_trace function in kernel/trace/blktrace.c (which is used to fill out a blk_io_trace structure and place it in a per-cp…
CVE-2019-5108 high 8.0 6y ago An exploitable denial-of-service vulnerability exists in the Linux kernel prior to mainline 5.3. An attacker could exploit this vulnerability by triggering AP to send IAPP location updates for statio…
CVE-2019-15090 high 8.0 6y ago An issue was discovered in drivers/scsi/qedi/qedi_dbg.c in the Linux kernel before 5.1.12. In the qedi_dbg_* family of functions, there is an out-of-bounds read.
CVE-2019-16746 high 8.0 6y ago An issue was discovered in net/wireless/nl80211.c in the Linux kernel through 5.2.17. It does not check the length of variable elements in a beacon head, leading to a buffer overflow.
CVE-2019-19534 high 8.0 6y ago In the Linux kernel before 5.3.11, there is an info-leak bug that can be caused by a malicious USB device in the drivers/net/can/usb/peak_usb/pcan_usb_core.c driver, aka CID-f7a1337f0d29.
CVE-2019-19058 high 8.0 6y ago A memory leak in the alloc_sgtable() function in drivers/net/wireless/intel/iwlwifi/fw/dbg.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by t…
CVE-2019-19057 high 8.0 6y ago Two memory leaks in the mwifiex_pcie_init_evt_ring() function in drivers/net/wireless/marvell/mwifiex/pcie.c in the Linux kernel through 5.3.11 allow attackers to cause a denial of service (memory co…
CVE-2019-19055 high 8.0 6y ago A memory leak in the nl80211_get_ftm_responder_stats() function in net/wireless/nl80211.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by trig…