CVEs from 2019

3,412 normalized CVEs published or assigned in this year.

Total
3,412
critical
critical 232
high
high 332
medium
medium 301
low
low 72
% Critical
6.8%
% with KEV
3.5%
% with exploit
3.5%

Top vendors

Top products

  • u-boot 20
  • nsauditor 1
  • crypto 1
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Published Description Impact
CVE-2019-10185 high 8.0 It was found that icedtea-web up to and including 1.7.2 and 1.8.2 was vulnerable to a zip-slip attack during auto-extraction of a JAR file. An attacker could use this flaw to write files to arbitrary… archsusedebian
CVE-2019-13710 high 8.0 multiple issues in chromium archdebian
CVE-2019-13703 high 8.0 multiple issues in chromium archdebian
CVE-2019-5796 high 8.0 multiple issues in chromium archdebian
CVE-2019-13713 high 8.0 multiple issues in chromium archdebian
CVE-2019-3822 high 8.0 libcurl versions from 7.36.0 to before 7.64.0 are vulnerable to a stack-based buffer overflow. The function creating an outgoing NTLM type-3 header (`lib/vauth/ntlm.c:Curl_auth_create_ntlm_type3_mess… archsusedebian
CVE-2019-13715 high 8.0 multiple issues in chromium archdebian
CVE-2019-13716 high 8.0 multiple issues in chromium archdebian
CVE-2019-8343 high 8.0 In Netwide Assembler (NASM) 2.14.02, there is a use-after-free in paste_tokens in asm/preproc.c. archsusedebian
CVE-2019-5794 high 8.0 multiple issues in chromium archdebian
CVE-2019-13704 high 8.0 multiple issues in chromium archdebian
CVE-2019-10182 high 8.0 It was found that icedtea-web though 1.7.2 and 1.8.2 did not properly sanitize paths from <jar/> elements in JNLP files. An attacker could trick a victim into running a specially crafted application … archsusedebian
CVE-2019-11738 high 8.0 If a Content Security Policy (CSP) directive is defined that uses a hash-based source that takes the empty string as input, execution of any javascript: URIs will be allowed. This could allow for mal… archsusedebian
CVE-2019-11461 high 8.0 An issue was discovered in GNOME Nautilus 3.30 prior to 3.30.6 and 3.32 prior to 3.32.1. A compromised thumbnailer may escape the bubblewrap sandbox used to confine thumbnailers by using the TIOCSTI … archsusedebian
CVE-2019-5788 high 8.0 multiple issues in chromium archdebian
CVE-2019-16866 high 8.0 Unbound before 1.9.4 accesses uninitialized memory, which allows remote attackers to trigger a crash via a crafted NOTIFY query. The source IP address of the query must match an access-control rule. archdebian
CVE-2019-1354 high 8.0 A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-201… archsusedebian
CVE-2019-5858 high 8.0 multiple issues in chromium archdebian
CVE-2019-5790 high 8.0 multiple issues in chromium archdebian
CVE-2019-18634 high 8.0 In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the privileged sudo process. (pwfeedback is a default setting in Linux Mint and ele… archsusedebian
CVE-2019-20503 high 8.0 multiple issues in chromium archdebiansuse
CVE-2019-13719 high 8.0 multiple issues in chromium archdebian
CVE-2019-11748 high 8.0 WebRTC in Firefox will honor persisted permissions given to sites for access to microphone and camera resources even when in a third-party context. In light of recent high profile vulnerabilities in … archsusedebian
CVE-2019-5856 high 8.0 multiple issues in chromium archdebian
CVE-2019-5862 high 8.0 multiple issues in chromium archdebian
CVE-2019-15903 high 8.0 multiple issues in chromium archdebiansuserockylinux
CVE-2019-13708 high 8.0 multiple issues in chromium archdebian
CVE-2019-5867 high 8.0 arbitrary code execution in chromium archdebian
CVE-2019-5855 high 8.0 multiple issues in chromium archdebian
CVE-2019-13697 high 8.0 multiple issues in chromium archdebian
CVE-2019-13707 high 8.0 multiple issues in chromium archdebian
CVE-2019-6454 high 8.0 denial of service in systemd archsusedebian
CVE-2019-14817 high 8.0 A flaw was found in, ghostscript versions prior to 9.50, in the .pdfexectoken and other procedures where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrict… archsusedebian
CVE-2019-5865 high 8.0 multiple issues in chromium archdebian
CVE-2019-6473 high 8.0 An invalid hostname option can trigger an assertion failure in the Kea DHCPv4 server process (kea-dhcp4), causing the server process to exit. Versions affected: 1.4.0 to 1.5.0, 1.6.0-beta1, and 1.6.0… archdebian
CVE-2019-5864 high 8.0 multiple issues in chromium archdebian
CVE-2019-1348 high 8.0 An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. The --export-marks option of git fast-import is exposed also vi… archsusedebian
CVE-2019-11735 high 8.0 Mozilla developers and community members reported memory safety bugs present in Firefox 68 and Firefox ESR 68. Some of these bugs showed evidence of memory corruption and we presume that with enough … archsusedebian
CVE-2019-8337 high 8.0 In msmtp 1.8.2 and mpop 1.4.3, when tls_trust_file has its default configuration, certificate-verification results are not properly checked. archdebian
CVE-2019-10063 high 8.0 Flatpak before 1.0.8, 1.1.x and 1.2.x before 1.2.4, and 1.3.x before 1.3.1 allows a sandbox bypass. Flatpak versions since 0.8.1 address CVE-2017-5226 by using a seccomp filter to prevent sandboxed a… archsusedebian
CVE-2019-11750 high 8.0 A type confusion vulnerability exists in Spidermonkey, which results in a non-exploitable crash. This vulnerability affects Firefox < 69 and Firefox ESR < 68.1. archsusedebian
CVE-2019-5848 high 8.0 multiple issues in chromium archdebian
CVE-2019-10193 high 8.0 A stack-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x before 4.0.14 and 5.x before 5.0.4. By corrupting a hyperloglog using the SETRA… rockylinuxdebian
CVE-2019-2201 high 8.0 In generate_jsimd_ycc_rgb_convert_neon of jsimd_arm64_neon.S, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution in an unprivileged proces… archsusedebian
CVE-2019-14813 high 8.0 A flaw was found in ghostscript, versions 9.x before 9.50, in the setsystemparams procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A… archsusedebian
CVE-2019-6956 high 8.0 An issue was discovered in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. It is a buffer over-read in ps_mix_phase in libfaad/ps_dec.c. archdebian
CVE-2019-8377 high 8.0 An issue was discovered in Tcpreplay 4.3.1. A NULL pointer dereference occurred in the function get_ipv6_l4proto() located at get.c. This can be triggered by sending a crafted pcap file to the tcprep… archdebian
CVE-2019-0190 high 8.0 multiple issues in apache debianarch
CVE-2019-5789 high 8.0 multiple issues in chromium archdebian
CVE-2019-5799 high 8.0 multiple issues in chromium archdebian
CVE-2019-5802 high 8.0 multiple issues in chromium archdebian
CVE-2019-3871 high 8.0 A vulnerability was found in PowerDNS Authoritative Server before 4.0.7 and before 4.1.7. An insufficient validation of data coming from the user when building a HTTP request from a DNS query in the … archsusedebian
CVE-2019-0117 high 8.0 multiple issues in intel-ucode arch
CVE-2019-19604 high 8.0 Arbitrary command execution is possible in Git before 2.20.2, 2.21.x before 2.21.1, 2.22.x before 2.22.2, 2.23.x before 2.23.1, and 2.24.x before 2.24.1 because a "git submodule update" operation can… archdebian
CVE-2019-13709 high 8.0 multiple issues in chromium archdebian
CVE-2019-12881 high 8.0 i915_gem_userptr_get_pages in drivers/gpu/drm/i915/i915_gem_userptr.c in the Linux kernel 4.15.0 on Ubuntu 18.04.2 allows local users to cause a denial of service (NULL pointer dereference and BUG) o… archsusedebian
CVE-2019-5793 high 8.0 multiple issues in chromium archdebian
CVE-2019-5800 high 8.0 multiple issues in chromium archdebian
CVE-2019-5850 high 8.0 multiple issues in chromium archdebian
CVE-2019-5798 high 8.0 multiple issues in chromium archdebian
CVE-2019-5860 high 8.0 multiple issues in chromium archdebian
CVE-2019-5795 high 8.0 multiple issues in chromium archdebian
CVE-2019-5851 high 8.0 multiple issues in chromium archdebian
CVE-2019-5852 high 8.0 multiple issues in chromium archdebian
CVE-2019-6133 high 8.0 In PolicyKit (aka polkit) 0.115, the "start time" protection mechanism can be bypassed because fork() is not atomic, and therefore authorization decisions are improperly cached. This is related to la… archsusedebian
CVE-2019-5854 high 8.0 multiple issues in chromium archdebian
CVE-2019-5859 high 8.0 multiple issues in chromium archdebian
CVE-2019-5861 high 8.0 multiple issues in chromium archdebian
CVE-2019-14287 high 8.0 In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and session PAM modules, and can cause incorrect logging, by invoking sudo with a cra… archsusedebian
CVE-2019-5857 high 8.0 multiple issues in chromium archdebian
CVE-2019-13714 high 8.0 multiple issues in chromium archdebian
CVE-2019-1352 high 8.0 A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-201… archdebian
CVE-2019-1387 high 8.0 An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. Recursive clones are currently affected by a vulnerability that… archdebian
CVE-2019-19450 high 8.0 3y ago Important: python-reportlab security update susedebianpython
CVE-2019-18466 high 8.0 4y ago Important: container-tools:rhel8 security and bug fix update susedebianrockylinuxgolang
CVE-2019-9514 high 8.0 4y ago Important: nodejs:10 security update archsusedebianrockylinux+1
CVE-2019-9512 high 8.0 4y ago Important: container-tools:rhel8 security and bug fix update archsusedebianrockylinux+1
CVE-2019-10353 high 8.0 4y ago Cross-Site Request Forgery in Jenkins archjava
CVE-2019-10352 high 8.0 4y ago Improper Limitation of a Pathname to a Restricted Directory in Jenkins archjava
CVE-2019-10354 high 8.0 4y ago Missing Authorization in Jenkins archjava
CVE-2019-16276 high 8.0 4y ago Request smuggling due to accepting invalid headers in net/http via net/textproto archsusegolang
CVE-2019-2435 high 8.0 4y ago Improper Access Control in MySQL Connector Python archsusedebianpython
CVE-2019-5885 high 8.0 4y ago Matrix Synapse before 0.34.0.1, when the macaroon_secret_key authentication parameter is not set, uses a predictable value to derive a secret key and other secrets which could allow remote attackers … archdebianpython
CVE-2019-16884 high 8.0 4y ago Important: container-tools:rhel8 security and bug fix update susedebianrockylinuxgolang
CVE-2019-10214 high 8.0 4y ago Important: container-tools:rhel8 security, bug fix, and enhancement update susedebianrockylinuxgolang
CVE-2019-19528 high 8.0 5y ago In the Linux kernel before 5.3.7, there is a use-after-free bug that can be caused by a malicious USB device in the drivers/usb/misc/iowarrior.c driver, aka CID-edc4746f253d. susedebian
CVE-2019-19523 high 8.0 5y ago In the Linux kernel before 5.3.7, there is a use-after-free bug that can be caused by a malicious USB device in the drivers/usb/misc/adutux.c driver, aka CID-44efc269db79. susedebian
CVE-2019-18811 high 8.0 5y ago A memory leak in the sof_set_get_large_ctrl_data() function in sound/soc/sof/ipc.c in the Linux kernel through 5.3.9 allows attackers to cause a denial of service (memory consumption) by triggering s… susedebian
CVE-2019-2938 high 8.0 6y ago Important: mysql:8.0 security update suserockylinux
CVE-2019-2974 high 8.0 6y ago Important: mysql:8.0 security update suserockylinux
CVE-2019-15890 high 8.0 6y ago Important: container-tools:rhel8 security, bug fix, and enhancement update suserockylinuxdebian
CVE-2019-3009 high 8.0 6y ago Important: mysql:8.0 security update suserockylinux
CVE-2019-2968 high 8.0 6y ago Important: mysql:8.0 security update suserockylinux
CVE-2019-2967 high 8.0 6y ago Important: mysql:8.0 security update suserockylinux
CVE-2019-2946 high 8.0 6y ago Important: mysql:8.0 security update suserockylinux
CVE-2019-2998 high 8.0 6y ago Important: mysql:8.0 security update suserockylinux
CVE-2019-2991 high 8.0 6y ago Important: mysql:8.0 security update suserockylinux
CVE-2019-2982 high 8.0 6y ago Important: mysql:8.0 security update suserockylinux
CVE-2019-3004 high 8.0 6y ago Important: mysql:8.0 security update suserockylinux
CVE-2019-2966 high 8.0 6y ago Important: mysql:8.0 security update suserockylinux