CVEs from 2019

3,175 normalized CVEs published or assigned in this year.

Total
3,175
critical
critical 231
high
high 484
medium
medium 483
low
low 94
% Critical
7.3%
% with KEV
3.7%
% with exploit
7.9%

Top products

  • u-boot 20
  • crimson 8
  • active_iq_unified_manager 7
  • weblogic_server 5
  • jdk 5
  • oncommand_workflow_automation 5
  • codeready_linux_builder_eus 4
  • oncommand_insight 4
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2019-11487 high 8.0 7y ago The Linux kernel before 5.1-rc5 allows page->_refcount reference count overflow, with resultant use-after-free issues, if about 140 GiB of RAM exists. This is related to fs/fuse/dev.c, fs/pipe.c, fs/…
CVE-2019-9503 high 8.0 7y ago The Broadcom brcmfmac WiFi driver prior to commit a4176ec356c73a46c07c181c6d04039fafa34a9f is vulnerable to a frame validation bypass. If the brcmfmac driver receives a firmware event frame from a re…
CVE-2019-12817 high 8.0 7y ago arch/powerpc/mm/mmu_context_book3s64.c in the Linux kernel before 5.1.15 for powerpc has a bug where unrelated processes may be able to read/write to one another's virtual memory under certain condit…
CVE-2019-3846 high 8.0 7y ago A flaw that allowed an attacker to corrupt memory and possibly escalate privileges was found in the mwifiex kernel module while connecting to a malicious wireless network.
CVE-2019-9500 high 8.0 7y ago The Broadcom brcmfmac WiFi driver prior to commit 1b5e2423164b3670e8bc9174e4762d297990deff is vulnerable to a heap buffer overflow. If the Wake-up on Wireless LAN functionality is configured, a malic…
CVE-2019-11740 high 8.0 7y ago Mozilla developers and community members reported memory safety bugs present in Firefox 68, Firefox ESR 68, and Firefox 60.8. Some of these bugs showed evidence of memory corruption and we presume th…
CVE-2019-11742 high 8.0 7y ago A same-origin policy violation occurs allowing the theft of cross-origin images through a combination of SVG filters and a <canvas> element due to an error in how same-origin policy is applied …
CVE-2019-11752 high 8.0 7y ago It is possible to delete an IndexedDB key value and subsequently try to extract it during conversion. This results in a use-after-free and a potentially exploitable crash. This vulnerability affects …
CVE-2019-11749 high 8.0 7y ago A vulnerability exists in WebRTC where malicious web content can use probing techniques on the getUserMedia API using constraints to reveal device properties of cameras on the system without triggeri…
CVE-2019-11750 high 8.0 7y ago A type confusion vulnerability exists in Spidermonkey, which results in a non-exploitable crash. This vulnerability affects Firefox < 69 and Firefox ESR < 68.1.
CVE-2019-11743 high 8.0 7y ago Navigation events were not fully adhering to the W3C's "Navigation-Timing Level 2" draft specification in some instances for the unload event, which restricts access to detailed timing attributes to …
CVE-2019-11735 high 8.0 7y ago Mozilla developers and community members reported memory safety bugs present in Firefox 68 and Firefox ESR 68. Some of these bugs showed evidence of memory corruption and we presume that with enough …
CVE-2019-9812 high 8.0 7y ago Given a compromised sandboxed content process due to a separate vulnerability, it is possible to escape that sandbox by loading accounts.firefox.com in that process and forcing a log-in to a maliciou…
CVE-2019-11744 high 8.0 7y ago Some HTML elements, such as &lt;title&gt; and &lt;textarea&gt;, can contain literal angle brackets without treating them as markup. It is possible to pass a literal closing tag to .innerHTML on these…
CVE-2019-11748 high 8.0 7y ago WebRTC in Firefox will honor persisted permissions given to sites for access to microphone and camera resources even when in a third-party context. In light of recent high profile vulnerabilities in …
CVE-2019-11738 high 8.0 7y ago If a Content Security Policy (CSP) directive is defined that uses a hash-based source that takes the empty string as input, execution of any javascript: URIs will be allowed. This could allow for mal…
CVE-2019-11747 high 8.0 7y ago The "Forget about this site" feature in the History pane is intended to remove all saved user data that indicates a user has visited a site. This includes removing any HTTP Strict Transport Security …
CVE-2019-11746 high 8.0 7y ago A use-after-free vulnerability can occur while manipulating video elements if the body is freed while still in use. This results in a potentially exploitable crash. This vulnerability affects Firefox…
CVE-2019-12527 high 8.0 7y ago RHSA-2019:2593: squid:4 security update (Important)
CVE-2019-11775 high 8.0 7y ago RHSA-2019:2590: java-1.8.0-ibm security update (Important)
CVE-2019-11772 high 8.0 7y ago RHSA-2019:2590: java-1.8.0-ibm security update (Important)
CVE-2019-14812 high 8.0 7y ago RHSA-2019:2591: ghostscript security update (Important)
CVE-2019-14817 high 8.0 7y ago RHSA-2019:2591: ghostscript security update (Important)
CVE-2019-14811 high 8.0 7y ago RHSA-2019:2591: ghostscript security update (Important)
CVE-2019-14813 high 8.0 7y ago RHSA-2019:2591: ghostscript security update (Important)
CVE-2019-1010238 high 8.0 7y ago RHSA-2019:2582: pango security update (Important)
CVE-2019-0203 high 8.0 7y ago RHSA-2019:2512: subversion:1.10 security update (Important)
CVE-2019-2691 high 8.0 7y ago RHSA-2019:2511: mysql:8.0 security update (Important)
CVE-2019-2778 high 8.0 7y ago RHSA-2019:2511: mysql:8.0 security update (Important)
CVE-2019-2796 high 8.0 7y ago RHSA-2019:2511: mysql:8.0 security update (Important)
CVE-2019-2803 high 8.0 7y ago RHSA-2019:2511: mysql:8.0 security update (Important)
CVE-2019-2815 high 8.0 7y ago RHSA-2019:2511: mysql:8.0 security update (Important)
CVE-2019-2819 high 8.0 7y ago RHSA-2019:2511: mysql:8.0 security update (Important)
CVE-2019-2830 high 8.0 7y ago RHSA-2019:2511: mysql:8.0 security update (Important)
CVE-2019-2834 high 8.0 7y ago RHSA-2019:2511: mysql:8.0 security update (Important)
CVE-2019-2969 high 8.0 7y ago RHSA-2019:2511: mysql:8.0 security update (Important)
CVE-2019-2607 high 8.0 7y ago RHSA-2019:2511: mysql:8.0 security update (Important)
CVE-2019-2617 high 8.0 7y ago RHSA-2019:2511: mysql:8.0 security update (Important)
CVE-2019-2626 high 8.0 7y ago RHSA-2019:2511: mysql:8.0 security update (Important)
CVE-2019-2631 high 8.0 7y ago RHSA-2019:2511: mysql:8.0 security update (Important)
CVE-2019-2634 high 8.0 7y ago RHSA-2019:2511: mysql:8.0 security update (Important)
CVE-2019-2681 high 8.0 7y ago RHSA-2019:2511: mysql:8.0 security update (Important)
CVE-2019-2685 high 8.0 7y ago RHSA-2019:2511: mysql:8.0 security update (Important)
CVE-2019-2686 high 8.0 7y ago RHSA-2019:2511: mysql:8.0 security update (Important)
CVE-2019-2694 high 8.0 7y ago RHSA-2019:2511: mysql:8.0 security update (Important)
CVE-2019-2755 high 8.0 7y ago RHSA-2019:2511: mysql:8.0 security update (Important)
CVE-2019-2812 high 8.0 7y ago RHSA-2019:2511: mysql:8.0 security update (Important)
CVE-2019-2624 high 8.0 7y ago RHSA-2019:2511: mysql:8.0 security update (Important)
CVE-2019-2774 high 8.0 7y ago RHSA-2019:2511: mysql:8.0 security update (Important)
CVE-2019-2780 high 8.0 7y ago RHSA-2019:2511: mysql:8.0 security update (Important)
CVE-2019-2795 high 8.0 7y ago RHSA-2019:2511: mysql:8.0 security update (Important)
CVE-2019-2797 high 8.0 7y ago RHSA-2019:2511: mysql:8.0 security update (Important)
CVE-2019-2808 high 8.0 7y ago RHSA-2019:2511: mysql:8.0 security update (Important)
CVE-2019-2810 high 8.0 7y ago RHSA-2019:2511: mysql:8.0 security update (Important)
CVE-2019-2826 high 8.0 7y ago RHSA-2019:2511: mysql:8.0 security update (Important)
CVE-2019-2434 high 8.0 7y ago RHSA-2019:2511: mysql:8.0 security update (Important)
CVE-2019-2455 high 8.0 7y ago RHSA-2019:2511: mysql:8.0 security update (Important)
CVE-2019-2481 high 8.0 7y ago RHSA-2019:2511: mysql:8.0 security update (Important)
CVE-2019-2482 high 8.0 7y ago RHSA-2019:2511: mysql:8.0 security update (Important)
CVE-2019-2486 high 8.0 7y ago RHSA-2019:2511: mysql:8.0 security update (Important)
CVE-2019-2494 high 8.0 7y ago RHSA-2019:2511: mysql:8.0 security update (Important)
CVE-2019-2507 high 8.0 7y ago RHSA-2019:2511: mysql:8.0 security update (Important)
CVE-2019-2495 high 8.0 7y ago RHSA-2019:2511: mysql:8.0 security update (Important)
CVE-2019-2502 high 8.0 7y ago RHSA-2019:2511: mysql:8.0 security update (Important)
CVE-2019-2503 high 8.0 7y ago RHSA-2019:2511: mysql:8.0 security update (Important)
CVE-2019-2539 high 8.0 7y ago RHSA-2019:2511: mysql:8.0 security update (Important)
CVE-2019-2580 high 8.0 7y ago RHSA-2019:2511: mysql:8.0 security update (Important)
CVE-2019-2606 high 8.0 7y ago RHSA-2019:2511: mysql:8.0 security update (Important)
CVE-2019-2581 high 8.0 7y ago RHSA-2019:2511: mysql:8.0 security update (Important)
CVE-2019-2585 high 8.0 7y ago RHSA-2019:2511: mysql:8.0 security update (Important)
CVE-2019-2587 high 8.0 7y ago RHSA-2019:2511: mysql:8.0 security update (Important)
CVE-2019-2623 high 8.0 7y ago RHSA-2019:2511: mysql:8.0 security update (Important)
CVE-2019-2589 high 8.0 7y ago RHSA-2019:2511: mysql:8.0 security update (Important)
CVE-2019-2592 high 8.0 7y ago RHSA-2019:2511: mysql:8.0 security update (Important)
CVE-2019-2593 high 8.0 7y ago RHSA-2019:2511: mysql:8.0 security update (Important)
CVE-2019-2596 high 8.0 7y ago RHSA-2019:2511: mysql:8.0 security update (Important)
CVE-2019-2687 high 8.0 7y ago RHSA-2019:2511: mysql:8.0 security update (Important)
CVE-2019-2738 high 8.0 7y ago RHSA-2019:2511: mysql:8.0 security update (Important)
CVE-2019-2752 high 8.0 7y ago RHSA-2019:2511: mysql:8.0 security update (Important)
CVE-2019-2420 high 8.0 7y ago RHSA-2019:2511: mysql:8.0 security update (Important)
CVE-2019-2688 high 8.0 7y ago RHSA-2019:2511: mysql:8.0 security update (Important)
CVE-2019-3003 high 8.0 7y ago RHSA-2019:2511: mysql:8.0 security update (Important)
CVE-2019-2950 high 8.0 7y ago RHSA-2019:2511: mysql:8.0 security update (Important)
CVE-2019-2948 high 8.0 7y ago RHSA-2019:2511: mysql:8.0 security update (Important)
CVE-2019-2814 high 8.0 7y ago RHSA-2019:2511: mysql:8.0 security update (Important)
CVE-2019-2811 high 8.0 7y ago RHSA-2019:2511: mysql:8.0 security update (Important)
CVE-2019-2802 high 8.0 7y ago RHSA-2019:2511: mysql:8.0 security update (Important)
CVE-2019-2801 high 8.0 7y ago RHSA-2019:2511: mysql:8.0 security update (Important)
CVE-2019-2800 high 8.0 7y ago RHSA-2019:2511: mysql:8.0 security update (Important)
CVE-2019-2695 high 8.0 7y ago RHSA-2019:2511: mysql:8.0 security update (Important)
CVE-2019-2798 high 8.0 7y ago RHSA-2019:2511: mysql:8.0 security update (Important)
CVE-2019-2789 high 8.0 7y ago RHSA-2019:2511: mysql:8.0 security update (Important)
CVE-2019-2785 high 8.0 7y ago RHSA-2019:2511: mysql:8.0 security update (Important)
CVE-2019-2784 high 8.0 7y ago RHSA-2019:2511: mysql:8.0 security update (Important)
CVE-2019-2757 high 8.0 7y ago RHSA-2019:2511: mysql:8.0 security update (Important)
CVE-2019-2644 high 8.0 7y ago RHSA-2019:2511: mysql:8.0 security update (Important)
CVE-2019-2879 high 8.0 7y ago RHSA-2019:2511: mysql:8.0 security update (Important)
CVE-2019-2636 high 8.0 7y ago RHSA-2019:2511: mysql:8.0 security update (Important)
CVE-2019-2635 high 8.0 7y ago RHSA-2019:2511: mysql:8.0 security update (Important)
CVE-2019-2630 high 8.0 7y ago RHSA-2019:2511: mysql:8.0 security update (Important)