CVEs from 2019

4,187 normalized CVEs published or assigned in this year.

Total
4,187
critical
critical 232
high
high 332
medium
medium 301
low
low 72
% Critical
5.5%
% with KEV
2.8%
% with exploit
2.9%

Top vendors

Top products

  • u-boot 20
  • nsauditor 1
  • crypto 1
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Published Description Impact
CVE-2019-17022 critical 9.5 When pasting a <style> tag from the clipboard into a rich text editor, the CSS sanitizer does not escape < and > characters. Because the resulting string is pasted directly into the text … archdebian
CVE-2019-7221 critical 9.5 The KVM implementation in the Linux kernel through 4.20.5 has a Use-after-Free. archsusedebian
CVE-2019-11759 critical 9.5 An attacker could have caused 4 bytes of HMAC output to be written past the end of a buffer stored on the stack. This could be used by an attacker to execute arbitrary code or more likely lead to a c… archdebian
CVE-2019-11760 critical 9.5 A fixed-size stack buffer could overflow in nrappkit when doing WebRTC signaling. This resulted in a potentially exploitable crash in some instances. This vulnerability affects Firefox < 70, Thunderb… archdebian
CVE-2019-11762 critical 9.5 If two same-origin documents set document.domain differently to become cross-origin, it was possible for them to call arbitrary DOM methods/getters/setters on the now-cross-origin window. This vulner… archdebian
CVE-2019-17016 critical 9.5 When pasting a &lt;style&gt; tag from the clipboard into a rich text editor, the CSS sanitizer incorrectly rewrites a @namespace rule. This could allow for injection into certain types of websites re… archdebian
CVE-2019-17024 critical 9.5 Mozilla developers reported memory safety bugs present in Firefox 71 and Firefox ESR 68.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these… archdebian
CVE-2019-17017 critical 9.5 Due to a missing case handling object types, a type confusion vulnerability could occur, resulting in a crash. We presume that with enough effort that it could be exploited to run arbitrary code. Thi… archdebian
CVE-2019-19880 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5439 critical 9.5 arbitrary code execution in vlc archdebian
CVE-2019-3829 critical 9.5 A vulnerability was found in gnutls versions from 3.5.8 before 3.6.7. A memory corruption (double free) vulnerability in the certificate verification API. Any client or server application that verifi… archsusedebian
CVE-2019-9797 critical 9.5 Cross-origin images can be read in violation of the same-origin policy by exporting an image after using createImageBitmap to read the image and then rendering the resulting bitmap image within a can… archsusedebian
CVE-2019-17008 critical 9.5 When using nested workers, a use-after-free could occur during worker destruction. This resulted in a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3,… archsusedebian
CVE-2019-13738 critical 9.5 Insufficient policy enforcement in navigation in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to bypass site isolation via a crafted HTML page. archdebian
CVE-2019-13732 critical 9.5 Use-after-free in WebAudio in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. archdebian
CVE-2019-13755 critical 9.5 Insufficient policy enforcement in extensions in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to disable extensions via a crafted HTML page. archdebian
CVE-2019-13756 critical 9.5 Incorrect security UI in printing in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via a crafted HTML page. archdebian
CVE-2019-13737 critical 9.5 Insufficient policy enforcement in autocomplete in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML pag… archdebian
CVE-2019-13730 critical 9.5 Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. archdebian
CVE-2019-13753 critical 9.5 Out of bounds read in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. archdebian
CVE-2019-13743 critical 9.5 Incorrect security UI in external protocol handling in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to spoof security UI via a crafted HTML page. archdebian
CVE-2019-13746 critical 9.5 Insufficient policy enforcement in Omnibox in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. archdebian
CVE-2019-13747 critical 9.5 Uninitialized data in rendering in Google Chrome on Android prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. archdebian
CVE-2019-13752 critical 9.5 Out of bounds read in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. archdebian
CVE-2019-17012 critical 9.5 Mozilla developers reported memory safety bugs present in Firefox 70 and Firefox ESR 68.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these… archsusedebian
CVE-2019-9808 critical 9.5 If WebRTC permission is requested from documents with data: or blob: URLs, the permission notifications do not properly display the originating domain. The notification states "Unknown origin" as the… archdebian
CVE-2019-11757 critical 9.5 When following the value's prototype chain, it was possible to retain a reference to a locale, delete it, and subsequently reference it. This resulted in a use-after-free and a potentially exploitabl… archdebian
CVE-2019-17002 critical 9.5 If upgrade-insecure-requests was specified in the Content Security Policy, and a link was dragged and dropped from that page, the link was not upgraded to https. This vulnerability affects Firefox < … archdebian
CVE-2019-5781 critical 9.5 multiple issues in chromium archdebian
CVE-2019-17014 critical 9.5 If an image had not loaded correctly (such as when it is not actually an image), it could be dragged and dropped cross-domain, resulting in a cross-origin information leak. This vulnerability affects… archdebian
CVE-2019-5760 critical 9.5 multiple issues in chromium archdebian
CVE-2019-13744 critical 9.5 Insufficient policy enforcement in cookies in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to leak cross-origin data via a crafted HTML page. archdebian
CVE-2019-5755 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5836 critical 9.5 multiple issues in chromium archdebian
CVE-2019-11711 critical 9.5 When an inner window is reused, it does not consider the use of document.domain for cross-origin protections. If pages on different subdomains ever cooperatively use document.domain, then either page… archdebian
CVE-2019-11714 critical 9.5 Necko can access a child on the wrong thread during UDP connections, resulting in a potentially exploitable crash in some instances. This vulnerability affects Firefox < 68. archdebian
CVE-2019-9814 critical 9.5 Mozilla developers and community members reported memory safety bugs present in Firefox 66. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of… archsusedebian
CVE-2019-9821 critical 9.5 A use-after-free vulnerability can occur in AssertWorkerThread due to a race condition with shared workers. This results in a potentially exploitable crash. This vulnerability affects Firefox < 67. archsusedebian
CVE-2019-9795 critical 9.5 A vulnerability where type-confusion in the IonMonkey just-in-time (JIT) compiler could potentially be used by malicious JavaScript to trigger a potentially exploitable crash. This vulnerability affe… archsusedebian
CVE-2019-9811 critical 9.5 As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack and then opening a browser feature that used the compromised translation. This v… archsusedebian
CVE-2019-11500 critical 9.5 In Dovecot before 2.2.36.4 and 2.3.x before 2.3.7.2 (and Pigeonhole before 0.5.7.2), protocol processing can fail for quoted strings. This occurs because '\0' characters are mishandled, and can lead … archsusedebian
CVE-2019-5837 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5838 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5833 critical 9.5 multiple issues in chromium archdebian
CVE-2019-12874 critical 9.5 arbitrary code execution in vlc archdebian
CVE-2019-5832 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5831 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5828 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5829 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5823 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5820 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5818 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5819 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5813 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5814 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5809 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5810 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5805 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5782 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5780 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5771 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5807 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5778 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5806 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5783 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5779 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5777 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5775 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5774 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5764 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5773 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5768 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5765 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5757 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5770 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5767 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5766 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5761 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5763 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5754 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5759 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5758 critical 9.5 multiple issues in chromium archdebian
CVE-2019-9810 critical 9.5 Incorrect alias information in IonMonkey JIT compiler for Array.prototype.slice method may lead to missing bounds check and a buffer overflow. This vulnerability affects Firefox < 66.0.1, Firefox ESR… archsusedebian
CVE-2019-19926 critical 9.5 multiple issues in chromium archdebiansuse
CVE-2019-13917 critical 9.5 Exim 4.85 through 4.92 (fixed in 4.92.1) allows remote code execution as root in some unusual configurations that use the ${sort } expansion for items that can be controlled by an attacker (e.g., $lo… archdebian
CVE-2019-15846 critical 9.5 Exim before 4.92.2 allows remote attackers to execute arbitrary code as root via a trailing backslash. archdebian
CVE-2019-11693 critical 9.5 The bufferdata function in WebGL is vulnerable to a buffer overflow with specific graphics drivers on Linux. This could result in malicious content freezing a tab or triggering a potentially exploita… archsusedebian
CVE-2019-9816 critical 9.5 A possible vulnerability exists where type confusion can occur when manipulating JavaScript objects in object groups, allowing for the bypassing of security checks within these groups. *Note: this vu… archsusedebian
CVE-2019-5830 critical 9.5 multiple issues in chromium archdebian
CVE-2019-3813 critical 9.5 Spice, versions 0.5.2 through 0.14.1, are vulnerable to an out-of-bounds read due to an off-by-one error in memslot_get_virt. This may lead to a denial of service, or, in the worst case, code-executi… archsusedebian
CVE-2019-13764 critical 9.5 Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. archdebian
CVE-2019-13758 critical 9.5 Insufficient policy enforcement in navigation in Google Chrome on Android prior to 79.0.3945.79 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. archdebian
CVE-2019-13762 critical 9.5 Insufficient policy enforcement in downloads in Google Chrome on Windows prior to 79.0.3945.79 allowed a local attacker to spoof downloaded files via local code. archdebian
CVE-2019-19925 critical 9.5 multiple issues in chromium archdebiansuse
CVE-2019-17009 critical 9.5 When running, the updater service wrote status and log files to an unrestricted location; potentially allowing an unprivileged process to locate and exploit a vulnerability in file handling in the up… archsusedebian
CVE-2019-11745 critical 9.5 When encrypting with a block cipher, if a call to NSC_EncryptUpdate was made with data smaller than the block size, a small out of bounds write could occur. This could have caused heap corruption and… archsusedebian
CVE-2019-17666 critical 9.5 rtl_p2p_noa_ie in drivers/net/wireless/realtek/rtlwifi/ps.c in the Linux kernel through 5.3.6 lacks a certain upper-bound check, leading to a buffer overflow. archsusedebian
CVE-2019-9793 critical 9.5 A mechanism was discovered that removes some bounds checking for string, array, or typed array accesses if Spectre mitigations have been disabled. This vulnerability could allow an attacker to create… archsusedebian
CVE-2019-19923 critical 9.5 multiple issues in chromium archdebiansuse
CVE-2019-3856 critical 9.5 An integer overflow flaw, which could lead to an out of bounds write, was discovered in libssh2 before 1.8.1 in the way keyboard prompt requests are parsed. A remote attacker who compromises a SSH se… archsusedebian