CVEs from 2019

4,015 normalized CVEs published or assigned in this year.

Total
4,015
critical
critical 232
high
high 332
medium
medium 301
low
low 72
% Critical
5.8%
% with KEV
2.9%
% with exploit
3.0%

Top vendors

Top products

  • u-boot 20
  • nsauditor 1
  • crypto 1
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Published Description Impact
CVE-2019-3822 high 8.0 libcurl versions from 7.36.0 to before 7.64.0 are vulnerable to a stack-based buffer overflow. The function creating an outgoing NTLM type-3 header (`lib/vauth/ntlm.c:Curl_auth_create_ntlm_type3_mess… archsusedebian
CVE-2019-9812 high 8.0 Given a compromised sandboxed content process due to a separate vulnerability, it is possible to escape that sandbox by loading accounts.firefox.com in that process and forcing a log-in to a maliciou… archsusedebian
CVE-2019-16866 high 8.0 Unbound before 1.9.4 accesses uninitialized memory, which allows remote attackers to trigger a crash via a crafted NOTIFY query. The source IP address of the query must match an access-control rule. archdebian
CVE-2019-5788 high 8.0 multiple issues in chromium archdebian
CVE-2019-3814 high 8.0 It was discovered that Dovecot before versions 2.2.36.1 and 2.3.4.1 incorrectly handled client certificates. A remote attacker in possession of a valid certificate with an empty username field could … archsusedebian
CVE-2019-5794 high 8.0 multiple issues in chromium archdebian
CVE-2019-5796 high 8.0 multiple issues in chromium archdebian
CVE-2019-13703 high 8.0 multiple issues in chromium archdebian
CVE-2019-13707 high 8.0 multiple issues in chromium archdebian
CVE-2019-15903 high 8.0 multiple issues in chromium archdebiansuserockylinux
CVE-2019-13719 high 8.0 multiple issues in chromium archdebian
CVE-2019-20503 high 8.0 multiple issues in chromium archdebiansuse
CVE-2019-5790 high 8.0 multiple issues in chromium archdebian
CVE-2019-9893 high 8.0 libseccomp before 2.4.0 did not correctly generate 64-bit syscall argument comparisons using the arithmetic operators (LT, GT, LE, GE), which might able to lead to bypassing seccomp filters and poten… archsusedebian
CVE-2019-11461 high 8.0 An issue was discovered in GNOME Nautilus 3.30 prior to 3.30.6 and 3.32 prior to 3.32.1. A compromised thumbnailer may escape the bubblewrap sandbox used to confine thumbnailers by using the TIOCSTI … archsusedebian
CVE-2019-1387 high 8.0 An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. Recursive clones are currently affected by a vulnerability that… archdebian
CVE-2019-11742 high 8.0 A same-origin policy violation occurs allowing the theft of cross-origin images through a combination of SVG filters and a <canvas> element due to an error in how same-origin policy is applied … archsusedebian
CVE-2019-1352 high 8.0 A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-201… archdebian
CVE-2019-5853 high 8.0 multiple issues in chromium archdebian
CVE-2019-8906 high 8.0 do_core_note in readelf.c in libmagic.a in file 5.35 has an out-of-bounds read because memcpy is misused. archsusedebian
CVE-2019-13713 high 8.0 multiple issues in chromium archdebian
CVE-2019-13716 high 8.0 multiple issues in chromium archdebian
CVE-2019-14811 high 8.0 A flaw was found in, ghostscript versions prior to 9.50, in the .pdf_hook_DSC_Creator procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restriction… archsusedebian
CVE-2019-11735 high 8.0 Mozilla developers and community members reported memory safety bugs present in Firefox 68 and Firefox ESR 68. Some of these bugs showed evidence of memory corruption and we presume that with enough … archsusedebian
CVE-2019-11748 high 8.0 WebRTC in Firefox will honor persisted permissions given to sites for access to microphone and camera resources even when in a third-party context. In light of recent high profile vulnerabilities in … archsusedebian
CVE-2019-5859 high 8.0 multiple issues in chromium archdebian
CVE-2019-5861 high 8.0 multiple issues in chromium archdebian
CVE-2019-5785 high 8.0 Incorrect convexity calculations in Skia in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. archsusedebian
CVE-2019-5857 high 8.0 multiple issues in chromium archdebian
CVE-2019-5858 high 8.0 multiple issues in chromium archdebian
CVE-2019-5862 high 8.0 multiple issues in chromium archdebian
CVE-2019-13697 high 8.0 multiple issues in chromium archdebian
CVE-2019-13704 high 8.0 multiple issues in chromium archdebian
CVE-2019-13710 high 8.0 multiple issues in chromium archdebian
CVE-2019-13715 high 8.0 multiple issues in chromium archdebian
CVE-2019-6472 high 8.0 A packet containing a malformed DUID can cause the Kea DHCPv6 server process (kea-dhcp6) to exit due to an assertion failure. Versions affected: 1.4.0 to 1.5.0, 1.6.0-beta1, and 1.6.0-beta2. archdebian
CVE-2019-9686 high 8.0 arbitrary code execution in pacman arch
CVE-2019-5797 high 8.0 multiple issues in chromium archdebian
CVE-2019-8907 high 8.0 do_core_note in readelf.c in libmagic.a in file 5.35 allows remote attackers to cause a denial of service (stack corruption and application crash) or possibly have unspecified other impact. archsusedebian
CVE-2019-5855 high 8.0 multiple issues in chromium archdebian
CVE-2019-18183 high 8.0 arbitrary command execution in pacman arch
CVE-2019-18182 high 8.0 arbitrary command execution in pacman arch
CVE-2019-11737 high 8.0 If a wildcard ('*') is specified for the host in Content Security Policy (CSP) directives, any port or path restriction of the directive will be ignored, leading to CSP directives not being properly … archdebian
CVE-2019-1351 high 8.0 A tampering vulnerability exists when Git for Visual Studio improperly handles virtual drive paths, aka 'Git for Visual Studio Tampering Vulnerability'. archdebian
CVE-2019-19604 high 8.0 Arbitrary command execution is possible in Git before 2.20.2, 2.21.x before 2.21.1, 2.22.x before 2.22.2, 2.23.x before 2.23.1, and 2.24.x before 2.24.1 because a "git submodule update" operation can… archdebian
CVE-2019-0117 high 8.0 multiple issues in intel-ucode arch
CVE-2019-14318 high 8.0 Crypto++ 8.3.0 and earlier contains a timing side channel in ECDSA signature generation. This allows a local or remote attacker, able to measure the duration of hundreds to thousands of signing opera… archdebian
CVE-2019-0190 high 8.0 multiple issues in apache debianarch
CVE-2019-10182 high 8.0 It was found that icedtea-web though 1.7.2 and 1.8.2 did not properly sanitize paths from <jar/> elements in JNLP files. An attacker could trick a victim into running a specially crafted application … archsusedebian
CVE-2019-10185 high 8.0 It was found that icedtea-web up to and including 1.7.2 and 1.8.2 was vulnerable to a zip-slip attack during auto-extraction of a JAR file. An attacker could use this flaw to write files to arbitrary… archsusedebian
CVE-2019-8381 high 8.0 An issue was discovered in Tcpreplay 4.3.1. An invalid memory access occurs in do_checksum in checksum.c. It can be triggered by sending a crafted pcap file to the tcpreplay-edit binary. It allows an… archdebian
CVE-2019-1348 high 8.0 An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. The --export-marks option of git fast-import is exposed also vi… archsusedebian
CVE-2019-8337 high 8.0 In msmtp 1.8.2 and mpop 1.4.3, when tls_trust_file has its default configuration, certificate-verification results are not properly checked. archdebian
CVE-2019-5865 high 8.0 multiple issues in chromium archdebian
CVE-2019-6454 high 8.0 An issue was discovered in sd-bus in systemd 239. bus_process_object() in libsystemd/sd-bus/bus-objects.c allocates a variable-length stack buffer for temporarily storing the object path of incoming … archsusedebian
CVE-2019-5864 high 8.0 multiple issues in chromium archdebian
CVE-2019-5842 high 8.0 arbitrary code execution in chromium archdebian
CVE-2019-5848 high 8.0 multiple issues in chromium archdebian
CVE-2019-5789 high 8.0 multiple issues in chromium archdebian
CVE-2019-5799 high 8.0 multiple issues in chromium archdebian
CVE-2019-5802 high 8.0 multiple issues in chromium archdebian
CVE-2019-5793 high 8.0 multiple issues in chromium archdebian
CVE-2019-11749 high 8.0 A vulnerability exists in WebRTC where malicious web content can use probing techniques on the getUserMedia API using constraints to reveal device properties of cameras on the system without triggeri… archsusedebian
CVE-2019-5800 high 8.0 multiple issues in chromium archdebian
CVE-2019-5850 high 8.0 multiple issues in chromium archdebian
CVE-2019-5798 high 8.0 multiple issues in chromium archdebian
CVE-2019-3838 high 8.0 It was found that the forceput operator could be extracted from the DefineResource method in ghostscript before 9.27. A specially crafted PostScript file could use this flaw in order to, for example,… archsusedebian
CVE-2019-5860 high 8.0 multiple issues in chromium archdebian
CVE-2019-5795 high 8.0 multiple issues in chromium archdebian
CVE-2019-5851 high 8.0 multiple issues in chromium archdebian
CVE-2019-5852 high 8.0 multiple issues in chromium archdebian
CVE-2019-3835 high 8.0 It was found that the superexec operator was available in the internal dictionary in ghostscript before 9.27. A specially crafted PostScript file could use this flaw in order to, for example, have ac… archsusedebian
CVE-2019-5854 high 8.0 multiple issues in chromium archdebian
CVE-2019-19450 high 8.0 3y ago Important: python-reportlab security update susedebianpython
CVE-2019-18466 high 8.0 4y ago Important: container-tools:rhel8 security and bug fix update susedebianrockylinuxgolang
CVE-2019-9514 high 8.0 4y ago Important: nodejs:10 security update archsusedebianrockylinux+1
CVE-2019-9512 high 8.0 4y ago Important: container-tools:rhel8 security and bug fix update archsusedebianrockylinux+1
CVE-2019-10354 high 8.0 4y ago Missing Authorization in Jenkins archjava
CVE-2019-10352 high 8.0 4y ago Improper Limitation of a Pathname to a Restricted Directory in Jenkins archjava
CVE-2019-10353 high 8.0 4y ago Cross-Site Request Forgery in Jenkins archjava
CVE-2019-16276 high 8.0 4y ago Request smuggling due to accepting invalid headers in net/http via net/textproto archsusegolang
CVE-2019-2435 high 8.0 4y ago Improper Access Control in MySQL Connector Python archsusedebianpython
CVE-2019-5885 high 8.0 4y ago Matrix Synapse before 0.34.0.1, when the macaroon_secret_key authentication parameter is not set, uses a predictable value to derive a secret key and other secrets which could allow remote attackers … archdebianpython
CVE-2019-16884 high 8.0 4y ago Important: container-tools:rhel8 security and bug fix update susedebianrockylinuxgolang
CVE-2019-10214 high 8.0 4y ago Important: container-tools:rhel8 security, bug fix, and enhancement update susedebianrockylinuxgolang
CVE-2019-19523 high 8.0 5y ago Important: kernel security, bug fix, and enhancement update susedebian
CVE-2019-18811 high 8.0 5y ago Important: kernel security, bug fix, and enhancement update susedebian
CVE-2019-19528 high 8.0 5y ago Important: kernel security, bug fix, and enhancement update susedebian
CVE-2019-2974 high 8.0 6y ago Important: mysql:8.0 security update suserockylinux
CVE-2019-2938 high 8.0 6y ago Important: mysql:8.0 security update suserockylinux
CVE-2019-15890 high 8.0 6y ago Important: container-tools:rhel8 security, bug fix, and enhancement update suserockylinuxdebian
CVE-2019-2998 high 8.0 6y ago Important: mysql:8.0 security update suserockylinux
CVE-2019-2991 high 8.0 6y ago Important: mysql:8.0 security update suserockylinux
CVE-2019-2997 high 8.0 6y ago Important: mysql:8.0 security update suserockylinux
CVE-2019-3004 high 8.0 6y ago Important: mysql:8.0 security update suserockylinux
CVE-2019-2982 high 8.0 6y ago Important: mysql:8.0 security update suserockylinux
CVE-2019-2966 high 8.0 6y ago Important: mysql:8.0 security update suserockylinux
CVE-2019-2957 high 8.0 6y ago Important: mysql:8.0 security update suserockylinux
CVE-2019-3009 high 8.0 6y ago Important: mysql:8.0 security update suserockylinux
CVE-2019-3011 high 8.0 6y ago Important: mysql:8.0 security update suserockylinuxalmalinux