CVEs from 2019

4,015 normalized CVEs published or assigned in this year.

Total
4,015
critical
critical 232
high
high 332
medium
medium 301
low
low 72
% Critical
5.8%
% with KEV
2.9%
% with exploit
3.0%

Top vendors

Top products

  • u-boot 20
  • nsauditor 1
  • crypto 1
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Published Description Impact
CVE-2019-5763 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5754 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5759 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5758 critical 9.5 multiple issues in chromium archdebian
CVE-2019-9820 critical 9.5 A use-after-free vulnerability can occur in the chrome event handler when it is freed while still in use. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.… archsusedebian
CVE-2019-9803 critical 9.5 The Upgrade-Insecure-Requests (UIR) specification states that if UIR is enabled through Content Security Policy (CSP), navigation to a same-origin URL must be upgraded to HTTPS. Firefox will incorrec… archdebian
CVE-2019-9802 critical 9.5 If a Sandbox content process is compromised, it can initiate an FTP download which will then use a child process to render the downloaded data. The downloaded data can then be passed to the Chrome pr… archdebian
CVE-2019-11764 critical 9.5 Mozilla developers and community members reported memory safety bugs present in Firefox 69 and Firefox ESR 68.1. Some of these bugs showed evidence of memory corruption and we presume that with enoug… archdebian
CVE-2019-11693 critical 9.5 The bufferdata function in WebGL is vulnerable to a buffer overflow with specific graphics drivers on Linux. This could result in malicious content freezing a tab or triggering a potentially exploita… archsusedebian
CVE-2019-9816 critical 9.5 A possible vulnerability exists where type confusion can occur when manipulating JavaScript objects in object groups, allowing for the bypassing of security checks within these groups. *Note: this vu… archsusedebian
CVE-2019-5819 critical 9.5 multiple issues in chromium archdebian
CVE-2019-9806 critical 9.5 A vulnerability exists during authorization prompting for FTP transaction where successive modal prompts are displayed and cannot be immediately dismissed. This allows for a denial of service (DOS) a… archdebian
CVE-2019-5808 critical 9.5 multiple issues in chromium archdebian
CVE-2019-11720 critical 9.5 Some unicode characters are incorrectly treated as whitespace during the parsing of web content instead of triggering parsing errors. This allows malicious code to then be processed, evading cross-si… archdebian
CVE-2019-11697 critical 9.5 If the ALT and "a" keys are pressed when users receive an extension installation prompt, the extension will be installed without the install prompt delay that keeps the prompt visible in order for us… archsusedebian
CVE-2019-5776 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5818 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5820 critical 9.5 multiple issues in chromium archdebian
CVE-2019-13752 critical 9.5 Out of bounds read in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. archdebian
CVE-2019-17009 critical 9.5 When running, the updater service wrote status and log files to an unrestricted location; potentially allowing an unprivileged process to locate and exploit a vulnerability in file handling in the up… archsusedebian
CVE-2019-13754 critical 9.5 Insufficient policy enforcement in extensions in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. archdebian
CVE-2019-13759 critical 9.5 Incorrect security UI in interstitials in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via a crafted HTML page. archdebian
CVE-2019-13757 critical 9.5 Incorrect security UI in Omnibox in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name. archdebian
CVE-2019-13747 critical 9.5 Uninitialized data in rendering in Google Chrome on Android prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. archdebian
CVE-2019-13746 critical 9.5 Insufficient policy enforcement in Omnibox in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. archdebian
CVE-2019-13743 critical 9.5 Incorrect security UI in external protocol handling in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to spoof security UI via a crafted HTML page. archdebian
CVE-2019-13753 critical 9.5 Out of bounds read in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. archdebian
CVE-2019-3856 critical 9.5 An integer overflow flaw, which could lead to an out of bounds write, was discovered in libssh2 before 1.8.1 in the way keyboard prompt requests are parsed. A remote attacker who compromises a SSH se… archsusedebian
CVE-2019-3855 critical 9.5 An integer overflow flaw which could lead to an out of bounds write was discovered in libssh2 before 1.8.1 in the way packets are read from the server. A remote attacker who compromises a SSH server … archsusedebian
CVE-2019-9817 critical 9.5 Images from a different domain can be read using a canvas object in some circumstances. This could be used to steal image data from a different site in violation of same-origin policy. This vulnerabi… archsusedebian
CVE-2019-3836 critical 9.5 It was discovered in gnutls before version 3.6.7 upstream that there is an uninitialized pointer access in gnutls versions 3.6.3 or later which can be triggered by certain post-handshake messages. archsusedebian
CVE-2019-13730 critical 9.5 Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. archdebian
CVE-2019-9805 critical 9.5 A latent vulnerability exists in the Prio library where data may be read from uninitialized memory for some functions, leading to potential memory corruption. This vulnerability affects Firefox < 66. archdebian
CVE-2019-9796 critical 9.5 A use-after-free vulnerability can occur when the SMIL animation controller incorrectly registers with the refresh driver twice when only a single registration is expected. When a registration is lat… archsusedebian
CVE-2019-5809 critical 9.5 multiple issues in chromium archdebian
CVE-2019-13745 critical 9.5 Insufficient policy enforcement in audio in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to leak cross-origin data via a crafted HTML page. archdebian
CVE-2019-7733 critical 9.5 multiple issues in live-media arch
CVE-2019-9799 critical 9.5 Insufficient bounds checking of data during inter-process communication might allow a compromised content process to be able to read memory from the parent process under certain conditions. This vuln… archdebian
CVE-2019-13737 critical 9.5 Insufficient policy enforcement in autocomplete in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML pag… archdebian
CVE-2019-13726 critical 9.5 Buffer overflow in password manager in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to execute arbitrary code via a crafted HTML page. archdebian
CVE-2019-17008 critical 9.5 When using nested workers, a use-after-free could occur during worker destruction. This resulted in a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3,… archsusedebian
CVE-2019-5813 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5814 critical 9.5 multiple issues in chromium archdebian
CVE-2019-11691 critical 9.5 A use-after-free vulnerability can occur when working with XMLHttpRequest (XHR) in an event loop, causing the XHR main thread to be called after it has been freed. This results in a potentially explo… archsusedebian
CVE-2019-11713 critical 9.5 A use-after-free vulnerability can occur in HTTP/2 when a cached HTTP/2 stream is closed while still in use, resulting in a potentially exploitable crash. This vulnerability affects Firefox ESR < 60.… archsusedebian
CVE-2019-17010 critical 9.5 Under certain conditions, when checking the Resist Fingerprinting preference during device orientation checks, a race condition could have caused a use-after-free and a potentially exploitable crash.… archsusedebian
CVE-2019-5756 critical 9.5 multiple issues in chromium archdebian
CVE-2019-17022 critical 9.5 When pasting a &lt;style&gt; tag from the clipboard into a rich text editor, the CSS sanitizer does not escape &lt; and &gt; characters. Because the resulting string is pasted directly into the text … archdebian
CVE-2019-9793 critical 9.5 A mechanism was discovered that removes some bounds checking for string, array, or typed array accesses if Spectre mitigations have been disabled. This vulnerability could allow an attacker to create… archsusedebian
CVE-2019-13734 critical 9.5 Out of bounds write in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. archdebian
CVE-2019-11500 critical 9.5 In Dovecot before 2.2.36.4 and 2.3.x before 2.3.7.2 (and Pigeonhole before 0.5.7.2), protocol processing can fail for quoted strings. This occurs because '\0' characters are mishandled, and can lead … archsusedebian
CVE-2019-9810 critical 9.5 Incorrect alias information in IonMonkey JIT compiler for Array.prototype.slice method may lead to missing bounds check and a buffer overflow. This vulnerability affects Firefox < 66.0.1, Firefox ESR… archsusedebian
CVE-2019-3859 critical 9.5 An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the _libssh2_packet_require and _libssh2_packet_requirev functions. A remote attacker who compromises a SSH server may be able to … archsusedebian
CVE-2019-3861 critical 9.5 An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SSH packets with a padding length value greater than the packet length are parsed. A remote attacker who compromises a SSH… archsusedebian
CVE-2019-11719 critical 9.5 When importing a curve25519 private key in PKCS#8format with leading 0x00 bytes, it is possible to trigger an out-of-bounds read in the Network Security Services (NSS) library. This could lead to inf… archsusedebian
CVE-2019-3860 critical 9.5 An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SFTP packets with empty payloads are parsed. A remote attacker who compromises a SSH server may be able to cause a Denial … archsusedebian
CVE-2019-3813 critical 9.5 Spice, versions 0.5.2 through 0.14.1, are vulnerable to an out-of-bounds read due to an off-by-one error in memslot_get_virt. This may lead to a denial of service, or, in the worst case, code-executi… archsusedebian
CVE-2019-9791 critical 9.5 The type inference system allows the compilation of functions that can cause type confusions between arbitrary objects when compiled through the IonMonkey just-in-time (JIT) compiler and when the con… archsusedebian
CVE-2019-11745 critical 9.5 When encrypting with a block cipher, if a call to NSC_EncryptUpdate was made with data smaller than the block size, a small out of bounds write could occur. This could have caused heap corruption and… archsusedebian
CVE-2019-17666 critical 9.5 rtl_p2p_noa_ie in drivers/net/wireless/realtek/rtlwifi/ps.c in the Linux kernel through 5.3.6 lacks a certain upper-bound check, leading to a buffer overflow. archsusedebian
CVE-2019-11717 critical 9.5 A vulnerability exists where the caret ("^") character is improperly escaped constructing some URIs due to it being used as a separator, allowing for possible spoofing of origin attributes. This vuln… archsusedebian
CVE-2019-17005 critical 9.5 The plain text serializer used a fixed-size array for the number of <ol> elements it could process; however it was possible to overflow the static-sized array leading to memory corruption and a poten… archsusedebian
CVE-2019-11701 critical 9.5 The default webcal: protocol handler will load a web site vulnerable to cross-site scripting (XSS) attacks. This default was left in place as a legacy feature and has now been removed. *Note: this is… archsusedebian
CVE-2019-19925 critical 9.5 multiple issues in chromium archdebiansuse
CVE-2019-19923 critical 9.5 multiple issues in chromium archdebiansuse
CVE-2019-13721 critical 9.5 arbitrary code execution in chromium archdebian
CVE-2019-5840 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5835 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5839 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5837 critical 9.5 multiple issues in chromium archdebian
CVE-2019-11695 critical 9.5 A custom cursor defined by scripting on a site can position itself over the addressbar to spoof the actual cursor when it should not be allowed outside of the primary web content area. This could be … archsusedebian
CVE-2019-11696 critical 9.5 Files with the .JNLP extension used for "Java web start" applications are not treated as executable content for download prompts even though they can be executed if Java is installed on the local sys… archsusedebian
CVE-2019-5838 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5833 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5832 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5831 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5828 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5829 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5823 critical 9.5 multiple issues in chromium archdebian
CVE-2019-8912 critical 9.5 In the Linux kernel through 4.20.11, af_alg_release() in crypto/af_alg.c neglects to set a NULL value for a certain structure member, which leads to a use-after-free in sockfs_setattr. archsusedebian
CVE-2019-13917 critical 9.5 Exim 4.85 through 4.92 (fixed in 4.92.1) allows remote code execution as root in some unusual configurations that use the ${sort } expansion for items that can be controlled by an attacker (e.g., $lo… archdebian
CVE-2019-15846 critical 9.5 Exim before 4.92.2 allows remote attackers to execute arbitrary code as root via a trailing backslash. archdebian
CVE-2019-5830 critical 9.5 multiple issues in chromium archdebian
CVE-2019-13742 critical 9.5 Incorrect security UI in Omnibox in Google Chrome on iOS prior to 79.0.3945.79 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name. archdebian
CVE-2019-13729 critical 9.5 Use-after-free in WebSockets in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. archdebian
CVE-2019-13725 critical 9.5 Use-after-free in Bluetooth in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to execute arbitrary code via a crafted HTML page. archdebian
CVE-2019-13727 critical 9.5 Insufficient policy enforcement in WebSockets in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to bypass same origin policy via a crafted HTML page. archdebian
CVE-2019-13739 critical 9.5 Insufficient policy enforcement in Omnibox in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name. archdebian
CVE-2019-13735 critical 9.5 Out of bounds write in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. archdebian
CVE-2019-13741 critical 9.5 Insufficient validation of untrusted input in Blink in Google Chrome prior to 79.0.3945.79 allowed a local attacker to bypass same origin policy via crafted clipboard content. archdebian
CVE-2019-13764 critical 9.5 Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. archdebian
CVE-2019-13758 critical 9.5 Insufficient policy enforcement in navigation in Google Chrome on Android prior to 79.0.3945.79 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. archdebian
CVE-2019-13762 critical 9.5 Insufficient policy enforcement in downloads in Google Chrome on Windows prior to 79.0.3945.79 allowed a local attacker to spoof downloaded files via local code. archdebian
CVE-2019-11714 critical 9.5 Necko can access a child on the wrong thread during UDP connections, resulting in a potentially exploitable crash in some instances. This vulnerability affects Firefox < 68. archdebian
CVE-2019-11711 critical 9.5 When an inner window is reused, it does not consider the use of document.domain for cross-origin protections. If pages on different subdomains ever cooperatively use document.domain, then either page… archdebian
CVE-2019-11698 critical 9.5 If a crafted hyperlink is dragged and dropped to the bookmark bar or sidebar and the resulting bookmark is subsequently dragged and dropped into the web content area, an arbitrary query of a user's b… archsusedebian
CVE-2019-5772 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5769 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5836 critical 9.5 multiple issues in chromium archdebian
CVE-2019-13744 critical 9.5 Insufficient policy enforcement in cookies in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to leak cross-origin data via a crafted HTML page. archdebian