CVEs from 2019

4,015 normalized CVEs published or assigned in this year.

Total
4,015
critical
critical 232
high
high 332
medium
medium 301
low
low 72
% Critical
5.8%
% with KEV
2.9%
% with exploit
3.0%

Top vendors

Top products

  • u-boot 20
  • nsauditor 1
  • crypto 1
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Published Description Impact
CVE-2019-13735 critical 9.5 Out of bounds write in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. archdebian
CVE-2019-13739 critical 9.5 Insufficient policy enforcement in Omnibox in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name. archdebian
CVE-2019-13727 critical 9.5 Insufficient policy enforcement in WebSockets in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to bypass same origin policy via a crafted HTML page. archdebian
CVE-2019-0220 critical 9.5 multiple issues in apache debianarchsuse
CVE-2019-5756 critical 9.5 multiple issues in chromium archdebian
CVE-2019-13738 critical 9.5 Insufficient policy enforcement in navigation in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to bypass site isolation via a crafted HTML page. archdebian
CVE-2019-13732 critical 9.5 Use-after-free in WebAudio in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. archdebian
CVE-2019-13749 critical 9.5 Incorrect security UI in Omnibox in Google Chrome on iOS prior to 79.0.3945.79 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. archdebian
CVE-2019-13755 critical 9.5 Insufficient policy enforcement in extensions in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to disable extensions via a crafted HTML page. archdebian
CVE-2019-13756 critical 9.5 Incorrect security UI in printing in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via a crafted HTML page. archdebian
CVE-2019-13754 critical 9.5 Insufficient policy enforcement in extensions in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. archdebian
CVE-2019-13726 critical 9.5 Buffer overflow in password manager in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to execute arbitrary code via a crafted HTML page. archdebian
CVE-2019-13737 critical 9.5 Insufficient policy enforcement in autocomplete in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML pag… archdebian
CVE-2019-13730 critical 9.5 Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. archdebian
CVE-2019-13753 critical 9.5 Out of bounds read in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. archdebian
CVE-2019-13743 critical 9.5 Incorrect security UI in external protocol handling in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to spoof security UI via a crafted HTML page. archdebian
CVE-2019-13746 critical 9.5 Insufficient policy enforcement in Omnibox in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. archdebian
CVE-2019-13747 critical 9.5 Uninitialized data in rendering in Google Chrome on Android prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. archdebian
CVE-2019-13752 critical 9.5 Out of bounds read in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. archdebian
CVE-2019-5762 critical 9.5 multiple issues in chromium archdebian
CVE-2019-13748 critical 9.5 Insufficient policy enforcement in developer tools in Google Chrome prior to 79.0.3945.79 allowed a local attacker to obtain potentially sensitive information from process memory via a crafted HTML p… archdebian
CVE-2019-5821 critical 9.5 multiple issues in chromium archdebian
CVE-2019-13728 critical 9.5 Out of bounds write in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. archdebian
CVE-2019-13741 critical 9.5 Insufficient validation of untrusted input in Blink in Google Chrome prior to 79.0.3945.79 allowed a local attacker to bypass same origin policy via crafted clipboard content. archdebian
CVE-2019-17012 critical 9.5 Mozilla developers reported memory safety bugs present in Firefox 70 and Firefox ESR 68.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these… archsusedebian
CVE-2019-11699 critical 9.5 A malicious page can briefly cause the wrong name to be highlighted as the domain name in the addressbar during page navigations. This could result in user confusion of which site is currently loaded… archdebian
CVE-2019-11721 critical 9.5 The unicode latin 'kra' character can be used to spoof a standard 'k' character in the addressbar. This allows for domain spoofing attacks as do not display as punycode text, allowing for user confus… archdebian
CVE-2019-11716 critical 9.5 Until explicitly accessed by script, window.globalThis is not enumerable and, as a result, is not visible to code such as Object.getOwnPropertyNames(window). Sites that deploy a sandboxing that depen… archdebian
CVE-2019-11718 critical 9.5 Activity Stream can display content from sent from the Snippet Service website. This content is written to innerHTML on the Activity Stream page without sanitization, allowing for a potential access … archdebian
CVE-2019-11720 critical 9.5 Some unicode characters are incorrectly treated as whitespace during the parsing of web content instead of triggering parsing errors. This allows malicious code to then be processed, evading cross-si… archdebian
CVE-2019-11725 critical 9.5 When a user navigates to site marked as unsafe by the Safebrowsing API, warning messages are displayed and navigation is interrupted but resources from the same site loaded through websockets are not… archdebian
CVE-2019-5808 critical 9.5 multiple issues in chromium archdebian
CVE-2019-17001 critical 9.5 A Content-Security-Policy that blocks in-line scripts could be bypassed using an object tag to execute JavaScript in the protected document (cross-site scripting). This is a separate bypass from CVE-… archdebian
CVE-2019-13764 critical 9.5 Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. archdebian
CVE-2019-5760 critical 9.5 multiple issues in chromium archdebian
CVE-2019-13744 critical 9.5 Insufficient policy enforcement in cookies in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to leak cross-origin data via a crafted HTML page. archdebian
CVE-2019-9816 critical 9.5 A possible vulnerability exists where type confusion can occur when manipulating JavaScript objects in object groups, allowing for the bypassing of security checks within these groups. *Note: this vu… archsusedebian
CVE-2019-12874 critical 9.5 arbitrary code execution in vlc archdebian
CVE-2019-19926 critical 9.5 multiple issues in chromium archdebiansuse
CVE-2019-7221 critical 9.5 The KVM implementation in the Linux kernel through 4.20.5 has a Use-after-Free. archsusedebian
CVE-2019-11715 critical 9.5 Due to an error while parsing page content, it is possible for properly sanitized user input to be misinterpreted and lead to XSS hazards on web sites in certain circumstances. This vulnerability aff… archdebian
CVE-2019-11724 critical 9.5 Application permissions give additional remote troubleshooting permission to the site input.mozilla.org, which has been retired and now redirects to another site. This additional permission is unnece… archsusedebian
CVE-2019-5813 critical 9.5 multiple issues in chromium archdebian
CVE-2019-3857 critical 9.5 An integer overflow flaw which could lead to an out of bounds write was discovered in libssh2 before 1.8.1 in the way SSH_MSG_CHANNEL_REQUEST packets with an exit signal are parsed. A remote attacker… archsusedebian
CVE-2019-3858 critical 9.5 An out of bounds read flaw was discovered in libssh2 before 1.8.1 when a specially crafted SFTP packet is received from the server. A remote attacker who compromises a SSH server may be able to cause… archsusedebian
CVE-2019-3862 critical 9.5 An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SSH_MSG_CHANNEL_REQUEST packets with an exit status message and no payload are parsed. A remote attacker who compromises a… archsusedebian
CVE-2019-3863 critical 9.5 A flaw was found in libssh2 before 1.8.1 creating a vulnerability on the SSH client side. A server could send a multiple keyboard interactive response messages whose total length are greater than uns… archsusedebian
CVE-2019-5819 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5818 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5820 critical 9.5 multiple issues in chromium archdebian
CVE-2019-15846 critical 9.5 Exim before 4.92.2 allows remote attackers to execute arbitrary code as root via a trailing backslash. archdebian
CVE-2019-5830 critical 9.5 multiple issues in chromium archdebian
CVE-2019-13917 critical 9.5 Exim 4.85 through 4.92 (fixed in 4.92.1) allows remote code execution as root in some unusual configurations that use the ${sort } expansion for items that can be controlled by an attacker (e.g., $lo… archdebian
CVE-2019-9791 critical 9.5 The type inference system allows the compilation of functions that can cause type confusions between arbitrary objects when compiled through the IonMonkey just-in-time (JIT) compiler and when the con… archsusedebian
CVE-2019-11719 critical 9.5 When importing a curve25519 private key in PKCS#8format with leading 0x00 bytes, it is possible to trigger an out-of-bounds read in the Network Security Services (NSS) library. This could lead to inf… archsusedebian
CVE-2019-5758 critical 9.5 multiple issues in chromium archdebian
CVE-2019-3861 critical 9.5 An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SSH packets with a padding length value greater than the packet length are parsed. A remote attacker who compromises a SSH… archsusedebian
CVE-2019-9811 critical 9.5 As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack and then opening a browser feature that used the compromised translation. This v… archsusedebian
CVE-2019-11728 critical 9.5 The HTTP Alternative Services header, Alt-Svc, can be used by a malicious site to scan all TCP ports of any host that the accessible to a user when web content is loaded. This vulnerability affects F… archdebian
CVE-2019-0215 critical 9.5 multiple issues in apache debianarch
CVE-2019-9799 critical 9.5 Insufficient bounds checking of data during inter-process communication might allow a compromised content process to be able to read memory from the parent process under certain conditions. This vuln… archdebian
CVE-2019-13734 critical 9.5 Out of bounds write in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. archdebian
CVE-2019-13745 critical 9.5 Insufficient policy enforcement in audio in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to leak cross-origin data via a crafted HTML page. archdebian
CVE-2019-5759 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5754 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5763 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5761 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5766 critical 9.5 multiple issues in chromium archdebian
CVE-2019-9793 critical 9.5 A mechanism was discovered that removes some bounds checking for string, array, or typed array accesses if Spectre mitigations have been disabled. This vulnerability could allow an attacker to create… archsusedebian
CVE-2019-5767 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5770 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5757 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5765 critical 9.5 multiple issues in chromium archdebian
CVE-2019-11760 critical 9.5 A fixed-size stack buffer could overflow in nrappkit when doing WebRTC signaling. This resulted in a potentially exploitable crash in some instances. This vulnerability affects Firefox < 70, Thunderb… archdebian
CVE-2019-3829 critical 9.5 A vulnerability was found in gnutls versions from 3.5.8 before 3.6.7. A memory corruption (double free) vulnerability in the certificate verification API. Any client or server application that verifi… archsusedebian
CVE-2019-17010 critical 9.5 Under certain conditions, when checking the Resist Fingerprinting preference during device orientation checks, a race condition could have caused a use-after-free and a potentially exploitable crash.… archsusedebian
CVE-2019-5768 critical 9.5 multiple issues in chromium archdebian
CVE-2019-17022 critical 9.5 When pasting a &lt;style&gt; tag from the clipboard into a rich text editor, the CSS sanitizer does not escape &lt; and &gt; characters. Because the resulting string is pasted directly into the text … archdebian
CVE-2019-11697 critical 9.5 If the ALT and "a" keys are pressed when users receive an extension installation prompt, the extension will be installed without the install prompt delay that keeps the prompt visible in order for us… archsusedebian
CVE-2019-11723 critical 9.5 A vulnerability exists during the installation of add-ons where the initial fetch ignored the origin attributes of the browsing context. This could leak cookies in private browsing mode or across dif… archdebian
CVE-2019-11761 critical 9.5 By using a form with a data URI it was possible to gain access to the privileged JSONView object that had been cloned into content. Impact from exposing this object appears to be minimal, however it … archdebian
CVE-2019-9806 critical 9.5 A vulnerability exists during authorization prompting for FTP transaction where successive modal prompts are displayed and cannot be immediately dismissed. This allows for a denial of service (DOS) a… archdebian
CVE-2019-5811 critical 9.5 multiple issues in chromium archdebian
CVE-2019-9808 critical 9.5 If WebRTC permission is requested from documents with data: or blob: URLs, the permission notifications do not properly display the originating domain. The notification states "Unknown origin" as the… archdebian
CVE-2019-11765 critical 9.5 A compromised content process could send a message to the parent process that would cause the 'Click to Play' permission prompt to be shown. However, due to lack of validation from the parent process… archdebian
CVE-2019-5773 critical 9.5 multiple issues in chromium archdebian
CVE-2019-13767 critical 9.5 Use after free in media picker in Google Chrome prior to 79.0.3945.88 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. archdebian
CVE-2019-17016 critical 9.5 When pasting a &lt;style&gt; tag from the clipboard into a rich text editor, the CSS sanitizer incorrectly rewrites a @namespace rule. This could allow for injection into certain types of websites re… archdebian
CVE-2019-17014 critical 9.5 If an image had not loaded correctly (such as when it is not actually an image), it could be dragged and dropped cross-domain, resulting in a cross-origin information leak. This vulnerability affects… archdebian
CVE-2019-17020 critical 9.5 If an XML file is served with a Content Security Policy and the XML file includes an XSL stylesheet, the Content Security Policy will not be applied to the contents of the XSL stylesheet. If the XSL … archdebian
CVE-2019-17025 critical 9.5 Mozilla developers reported memory safety bugs present in Firefox 71. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been expl… archdebian
CVE-2019-9802 critical 9.5 If a Sandbox content process is compromised, it can initiate an FTP download which will then use a child process to render the downloaded data. The downloaded data can then be passed to the Chrome pr… archdebian
CVE-2019-5764 critical 9.5 multiple issues in chromium archdebian
CVE-2019-9803 critical 9.5 The Upgrade-Insecure-Requests (UIR) specification states that if UIR is enabled through Content Security Policy (CSP), navigation to a same-origin URL must be upgraded to HTTPS. Firefox will incorrec… archdebian
CVE-2019-5774 critical 9.5 multiple issues in chromium archdebian
CVE-2019-9807 critical 9.5 When arbitrary text is sent over an FTP connection and a page reload is initiated, it is possible to create a modal alert message with this text as the content. This could potentially be used for soc… archdebian
CVE-2019-5775 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5777 critical 9.5 multiple issues in chromium archdebian
CVE-2019-9809 critical 9.5 If the source for resources on a page is through an FTP connection, it is possible to trigger a series of modal alert messages for these resources through invalid credentials or locations. These mess… archdebian
CVE-2019-17024 critical 9.5 Mozilla developers reported memory safety bugs present in Firefox 71 and Firefox ESR 68.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these… archdebian