CVEs from 2019

3,413 normalized CVEs published or assigned in this year.

Total
3,413
critical
critical 232
high
high 332
medium
medium 301
low
low 72
% Critical
6.8%
% with KEV
3.5%
% with exploit
3.5%

Top vendors

Top products

  • u-boot 20
  • nsauditor 1
  • crypto 1
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Published Description Impact
CVE-2019-5823 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5822 critical 9.5 multiple issues in chromium archdebian
CVE-2019-13730 critical 9.5 Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. archdebian
CVE-2019-7222 critical 9.5 The KVM implementation in the Linux kernel through 4.20.5 has an Information Leak. archsusedebian
CVE-2019-5820 critical 9.5 multiple issues in chromium archdebian
CVE-2019-9802 critical 9.5 If a Sandbox content process is compromised, it can initiate an FTP download which will then use a child process to render the downloaded data. The downloaded data can then be passed to the Chrome pr… archdebian
CVE-2019-5818 critical 9.5 multiple issues in chromium archdebian
CVE-2019-9809 critical 9.5 If the source for resources on a page is through an FTP connection, it is possible to trigger a series of modal alert messages for these resources through invalid credentials or locations. These mess… archdebian
CVE-2019-11763 critical 9.5 Failure to correctly handle null bytes when processing HTML entities resulted in Firefox incorrectly parsing these entities. This could have led to HTML comment text being treated as HTML which could… archdebian
CVE-2019-7314 critical 9.5 multiple issues in live-media arch
CVE-2019-5821 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5819 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5813 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5755 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5814 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5772 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5809 critical 9.5 multiple issues in chromium archdebian
CVE-2019-11698 critical 9.5 If a crafted hyperlink is dragged and dropped to the bookmark bar or sidebar and the resulting bookmark is subsequently dragged and dropped into the web content area, an arbitrary query of a user's b… archsusedebian
CVE-2019-5810 critical 9.5 multiple issues in chromium archdebian
CVE-2019-9814 critical 9.5 Mozilla developers and community members reported memory safety bugs present in Firefox 66. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of… archsusedebian
CVE-2019-5805 critical 9.5 multiple issues in chromium archdebian
CVE-2019-13732 critical 9.5 Use-after-free in WebAudio in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. archdebian
CVE-2019-5782 critical 9.5 multiple issues in chromium archdebian
CVE-2019-9821 critical 9.5 A use-after-free vulnerability can occur in AssertWorkerThread due to a race condition with shared workers. This results in a potentially exploitable crash. This vulnerability affects Firefox < 67. archsusedebian
CVE-2019-5780 critical 9.5 multiple issues in chromium archdebian
CVE-2019-0217 critical 9.5 multiple issues in apache debianarchsuse
CVE-2019-17017 critical 9.5 Due to a missing case handling object types, a type confusion vulnerability could occur, resulting in a crash. We presume that with enough effort that it could be exploited to run arbitrary code. Thi… archdebian
CVE-2019-13749 critical 9.5 Incorrect security UI in Omnibox in Google Chrome on iOS prior to 79.0.3945.79 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. archdebian
CVE-2019-17008 critical 9.5 When using nested workers, a use-after-free could occur during worker destruction. This resulted in a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3,… archsusedebian
CVE-2019-5783 critical 9.5 multiple issues in chromium archdebian
CVE-2019-17016 critical 9.5 When pasting a &lt;style&gt; tag from the clipboard into a rich text editor, the CSS sanitizer incorrectly rewrites a @namespace rule. This could allow for injection into certain types of websites re… archdebian
CVE-2019-13738 critical 9.5 Insufficient policy enforcement in navigation in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to bypass site isolation via a crafted HTML page. archdebian
CVE-2019-13755 critical 9.5 Insufficient policy enforcement in extensions in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to disable extensions via a crafted HTML page. archdebian
CVE-2019-17666 critical 9.5 rtl_p2p_noa_ie in drivers/net/wireless/realtek/rtlwifi/ps.c in the Linux kernel through 5.3.6 lacks a certain upper-bound check, leading to a buffer overflow. archsusedebian
CVE-2019-5806 critical 9.5 multiple issues in chromium archdebian
CVE-2019-19926 critical 9.5 multiple issues in chromium archdebiansuse
CVE-2019-5779 critical 9.5 multiple issues in chromium archdebian
CVE-2019-9797 critical 9.5 Cross-origin images can be read in violation of the same-origin policy by exporting an image after using createImageBitmap to read the image and then rendering the resulting bitmap image within a can… archsusedebian
CVE-2019-5777 critical 9.5 multiple issues in chromium archdebian
CVE-2019-19925 critical 9.5 multiple issues in chromium archdebiansuse
CVE-2019-5775 critical 9.5 multiple issues in chromium archdebian
CVE-2019-17024 critical 9.5 Mozilla developers reported memory safety bugs present in Firefox 71 and Firefox ESR 68.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these… archdebian
CVE-2019-5778 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5774 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5764 critical 9.5 multiple issues in chromium archdebian
CVE-2019-13917 critical 9.5 Exim 4.85 through 4.92 (fixed in 4.92.1) allows remote code execution as root in some unusual configurations that use the ${sort } expansion for items that can be controlled by an attacker (e.g., $lo… archdebian
CVE-2019-5773 critical 9.5 multiple issues in chromium archdebian
CVE-2019-15846 critical 9.5 Exim before 4.92.2 allows remote attackers to execute arbitrary code as root via a trailing backslash. archdebian
CVE-2019-5768 critical 9.5 multiple issues in chromium archdebian
CVE-2019-9793 critical 9.5 A mechanism was discovered that removes some bounds checking for string, array, or typed array accesses if Spectre mitigations have been disabled. This vulnerability could allow an attacker to create… archsusedebian
CVE-2019-13756 critical 9.5 Incorrect security UI in printing in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via a crafted HTML page. archdebian
CVE-2019-5765 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5757 critical 9.5 multiple issues in chromium archdebian
CVE-2019-8942 critical 9.5 WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry can be changed to an arbitrary string, such as one ending with a .jpg?file.php su… archdebian
CVE-2019-5770 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5840 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5767 critical 9.5 multiple issues in chromium archdebian
CVE-2019-13762 critical 9.5 Insufficient policy enforcement in downloads in Google Chrome on Windows prior to 79.0.3945.79 allowed a local attacker to spoof downloaded files via local code. archdebian
CVE-2019-5807 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5766 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5761 critical 9.5 multiple issues in chromium archdebian
CVE-2019-11761 critical 9.5 By using a form with a data URI it was possible to gain access to the privileged JSONView object that had been cloned into content. Impact from exposing this object appears to be minimal, however it … archdebian
CVE-2019-5763 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5839 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5754 critical 9.5 multiple issues in chromium archdebian
CVE-2019-13741 critical 9.5 Insufficient validation of untrusted input in Blink in Google Chrome prior to 79.0.3945.79 allowed a local attacker to bypass same origin policy via crafted clipboard content. archdebian
CVE-2019-5759 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5837 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5758 critical 9.5 multiple issues in chromium archdebian
CVE-2019-11712 critical 9.5 POST requests made by NPAPI plugins, such as Flash, that receive a status 308 redirect response can bypass CORS requirements. This can allow an attacker to perform Cross-Site Request Forgery (CSRF) a… archdebian
CVE-2019-17000 critical 9.5 An object tag with a data URI did not correctly inherit the document's Content Security Policy. This allowed a CSP bypass in a cross-origin frame if the document's policy explicitly allowed data: URI… archdebian
CVE-2019-7221 critical 9.5 The KVM implementation in the Linux kernel through 4.20.5 has a Use-after-Free. archsusedebian
CVE-2019-12874 critical 9.5 arbitrary code execution in vlc archdebian
CVE-2019-13764 critical 9.5 Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. archdebian
CVE-2019-11699 critical 9.5 A malicious page can briefly cause the wrong name to be highlighted as the domain name in the addressbar during page navigations. This could result in user confusion of which site is currently loaded… archdebian
CVE-2019-17022 critical 9.5 When pasting a &lt;style&gt; tag from the clipboard into a rich text editor, the CSS sanitizer does not escape &lt; and &gt; characters. Because the resulting string is pasted directly into the text … archdebian
CVE-2019-13728 critical 9.5 Out of bounds write in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. archdebian
CVE-2019-13748 critical 9.5 Insufficient policy enforcement in developer tools in Google Chrome prior to 79.0.3945.79 allowed a local attacker to obtain potentially sensitive information from process memory via a crafted HTML p… archdebian
CVE-2019-5838 critical 9.5 multiple issues in chromium archdebian
CVE-2019-3829 critical 9.5 A vulnerability was found in gnutls versions from 3.5.8 before 3.6.7. A memory corruption (double free) vulnerability in the certificate verification API. Any client or server application that verifi… archsusedebian
CVE-2019-0215 critical 9.5 multiple issues in apache debianarch
CVE-2019-5830 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5833 critical 9.5 multiple issues in chromium archdebian
CVE-2019-9805 critical 9.5 A latent vulnerability exists in the Prio library where data may be read from uninitialized memory for some functions, leading to potential memory corruption. This vulnerability affects Firefox < 66. archdebian
CVE-2019-7733 critical 9.5 multiple issues in live-media arch
CVE-2019-13754 critical 9.5 Insufficient policy enforcement in extensions in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. archdebian
CVE-2019-13759 critical 9.5 Incorrect security UI in interstitials in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via a crafted HTML page. archdebian
CVE-2019-13757 critical 9.5 Incorrect security UI in Omnibox in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name. archdebian
CVE-2019-11725 critical 9.5 When a user navigates to site marked as unsafe by the Safebrowsing API, warning messages are displayed and navigation is interrupted but resources from the same site loaded through websockets are not… archdebian
CVE-2019-13761 critical 9.5 Incorrect security UI in Omnibox in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name. archdebian
CVE-2019-5771 critical 9.5 multiple issues in chromium archdebian
CVE-2019-13763 critical 9.5 Insufficient policy enforcement in payments in Google Chrome prior to 79.0.3945.79 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. archdebian
CVE-2019-13767 critical 9.5 Use after free in media picker in Google Chrome prior to 79.0.3945.88 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. archdebian
CVE-2019-13742 critical 9.5 Incorrect security UI in Omnibox in Google Chrome on iOS prior to 79.0.3945.79 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name. archdebian
CVE-2019-13729 critical 9.5 Use-after-free in WebSockets in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. archdebian
CVE-2019-13725 critical 9.5 Use-after-free in Bluetooth in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to execute arbitrary code via a crafted HTML page. archdebian
CVE-2019-13727 critical 9.5 Insufficient policy enforcement in WebSockets in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to bypass same origin policy via a crafted HTML page. archdebian
CVE-2019-13739 critical 9.5 Insufficient policy enforcement in Omnibox in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name. archdebian
CVE-2019-13735 critical 9.5 Out of bounds write in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. archdebian
CVE-2019-8912 critical 9.5 In the Linux kernel through 4.20.11, af_alg_release() in crypto/af_alg.c neglects to set a NULL value for a certain structure member, which leads to a use-after-free in sockfs_setattr. archsusedebian