CVEs from 2019

4,015 normalized CVEs published or assigned in this year.

Total
4,015
critical
critical 232
high
high 332
medium
medium 301
low
low 72
% Critical
5.8%
% with KEV
2.9%
% with exploit
3.0%

Top vendors

Top products

  • u-boot 20
  • nsauditor 1
  • crypto 1
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Published Description Impact
CVE-2019-9796 critical 9.5 A use-after-free vulnerability can occur when the SMIL animation controller incorrectly registers with the refresh driver twice when only a single registration is expected. When a registration is lat… archsusedebian
CVE-2019-5808 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5821 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5762 critical 9.5 multiple issues in chromium archdebian
CVE-2019-13726 critical 9.5 Buffer overflow in password manager in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to execute arbitrary code via a crafted HTML page. archdebian
CVE-2019-13749 critical 9.5 Incorrect security UI in Omnibox in Google Chrome on iOS prior to 79.0.3945.79 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. archdebian
CVE-2019-3829 critical 9.5 A vulnerability was found in gnutls versions from 3.5.8 before 3.6.7. A memory corruption (double free) vulnerability in the certificate verification API. Any client or server application that verifi… archsusedebian
CVE-2019-13740 critical 9.5 Incorrect security UI in sharing in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via a crafted HTML page. archdebian
CVE-2019-13736 critical 9.5 Integer overflow in PDFium in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. archdebian
CVE-2019-12874 critical 9.5 arbitrary code execution in vlc archdebian
CVE-2019-5439 critical 9.5 arbitrary code execution in vlc archdebian
CVE-2019-19880 critical 9.5 multiple issues in chromium archdebian
CVE-2019-17024 critical 9.5 Mozilla developers reported memory safety bugs present in Firefox 71 and Firefox ESR 68.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these… archdebian
CVE-2019-17016 critical 9.5 When pasting a <style> tag from the clipboard into a rich text editor, the CSS sanitizer incorrectly rewrites a @namespace rule. This could allow for injection into certain types of websites re… archdebian
CVE-2019-11762 critical 9.5 If two same-origin documents set document.domain differently to become cross-origin, it was possible for them to call arbitrary DOM methods/getters/setters on the now-cross-origin window. This vulner… archdebian
CVE-2019-9790 critical 9.5 A use-after-free vulnerability can occur when a raw pointer to a DOM element on a page is obtained using JavaScript and the element is then removed while still in use. This results in a potentially e… archsusedebian
CVE-2019-11696 critical 9.5 Files with the .JNLP extension used for "Java web start" applications are not treated as executable content for download prompts even though they can be executed if Java is installed on the local sys… archsusedebian
CVE-2019-11695 critical 9.5 A custom cursor defined by scripting on a site can position itself over the addressbar to spoof the actual cursor when it should not be allowed outside of the primary web content area. This could be … archsusedebian
CVE-2019-9793 critical 9.5 A mechanism was discovered that removes some bounds checking for string, array, or typed array accesses if Spectre mitigations have been disabled. This vulnerability could allow an attacker to create… archsusedebian
CVE-2019-7222 critical 9.5 The KVM implementation in the Linux kernel through 4.20.5 has an Information Leak. archsusedebian
CVE-2019-17022 critical 9.5 When pasting a <style> tag from the clipboard into a rich text editor, the CSS sanitizer does not escape < and > characters. Because the resulting string is pasted directly into the text … archdebian
CVE-2019-11761 critical 9.5 By using a form with a data URI it was possible to gain access to the privileged JSONView object that had been cloned into content. Impact from exposing this object appears to be minimal, however it … archdebian
CVE-2019-17005 critical 9.5 The plain text serializer used a fixed-size array for the number of <ol> elements it could process; however it was possible to overflow the static-sized array leading to memory corruption and a poten… archsusedebian
CVE-2019-13741 critical 9.5 Insufficient validation of untrusted input in Blink in Google Chrome prior to 79.0.3945.79 allowed a local attacker to bypass same origin policy via crafted clipboard content. archdebian
CVE-2019-13735 critical 9.5 Out of bounds write in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. archdebian
CVE-2019-13739 critical 9.5 Insufficient policy enforcement in Omnibox in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name. archdebian
CVE-2019-13727 critical 9.5 Insufficient policy enforcement in WebSockets in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to bypass same origin policy via a crafted HTML page. archdebian
CVE-2019-13725 critical 9.5 Use-after-free in Bluetooth in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to execute arbitrary code via a crafted HTML page. archdebian
CVE-2019-13729 critical 9.5 Use-after-free in WebSockets in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. archdebian
CVE-2019-13742 critical 9.5 Incorrect security UI in Omnibox in Google Chrome on iOS prior to 79.0.3945.79 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name. archdebian
CVE-2019-5830 critical 9.5 multiple issues in chromium archdebian
CVE-2019-17009 critical 9.5 When running, the updater service wrote status and log files to an unrestricted location; potentially allowing an unprivileged process to locate and exploit a vulnerability in file handling in the up… archsusedebian
CVE-2019-6974 critical 9.5 In the Linux kernel before 4.20.8, kvm_ioctl_create_device in virt/kvm/kvm_main.c mishandles reference counting because of a race condition, leading to a use-after-free. archsusedebian
CVE-2019-5758 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5759 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5754 critical 9.5 multiple issues in chromium archdebian
CVE-2019-11693 critical 9.5 The bufferdata function in WebGL is vulnerable to a buffer overflow with specific graphics drivers on Linux. This could result in malicious content freezing a tab or triggering a potentially exploita… archsusedebian
CVE-2019-5763 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5761 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5766 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5767 critical 9.5 multiple issues in chromium archdebian
CVE-2019-11719 critical 9.5 When importing a curve25519 private key in PKCS#8format with leading 0x00 bytes, it is possible to trigger an out-of-bounds read in the Network Security Services (NSS) library. This could lead to inf… archsusedebian
CVE-2019-5770 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5757 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5765 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5768 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5773 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5764 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5774 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5775 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5777 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5779 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5806 critical 9.5 multiple issues in chromium archdebian
CVE-2019-11724 critical 9.5 Application permissions give additional remote troubleshooting permission to the site input.mozilla.org, which has been retired and now redirects to another site. This additional permission is unnece… archsusedebian
CVE-2019-9814 critical 9.5 Mozilla developers and community members reported memory safety bugs present in Firefox 66. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of… archsusedebian
CVE-2019-9821 critical 9.5 A use-after-free vulnerability can occur in AssertWorkerThread due to a race condition with shared workers. This results in a potentially exploitable crash. This vulnerability affects Firefox < 67. archsusedebian
CVE-2019-11698 critical 9.5 If a crafted hyperlink is dragged and dropped to the bookmark bar or sidebar and the resulting bookmark is subsequently dragged and dropped into the web content area, an arbitrary query of a user's b… archsusedebian
CVE-2019-5776 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5836 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5755 critical 9.5 multiple issues in chromium archdebian
CVE-2019-13744 critical 9.5 Insufficient policy enforcement in cookies in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to leak cross-origin data via a crafted HTML page. archdebian
CVE-2019-9819 critical 9.5 A vulnerability where a JavaScript compartment mismatch can occur while working with the fetch API, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7, Firefo… archsusedebian
CVE-2019-0217 critical 9.5 multiple issues in apache debianarchsuse
CVE-2019-5760 critical 9.5 multiple issues in chromium archdebian
CVE-2019-9809 critical 9.5 If the source for resources on a page is through an FTP connection, it is possible to trigger a series of modal alert messages for these resources through invalid credentials or locations. These mess… archdebian
CVE-2019-9807 critical 9.5 When arbitrary text is sent over an FTP connection and a page reload is initiated, it is possible to create a modal alert message with this text as the content. This could potentially be used for soc… archdebian
CVE-2019-9802 critical 9.5 If a Sandbox content process is compromised, it can initiate an FTP download which will then use a child process to render the downloaded data. The downloaded data can then be passed to the Chrome pr… archdebian
CVE-2019-17025 critical 9.5 Mozilla developers reported memory safety bugs present in Firefox 71. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been expl… archdebian
CVE-2019-17020 critical 9.5 If an XML file is served with a Content Security Policy and the XML file includes an XSL stylesheet, the Content Security Policy will not be applied to the contents of the XSL stylesheet. If the XSL … archdebian
CVE-2019-5822 critical 9.5 multiple issues in chromium archdebian
CVE-2019-11757 critical 9.5 When following the value's prototype chain, it was possible to retain a reference to a locale, delete it, and subsequently reference it. This resulted in a use-after-free and a potentially exploitabl… archdebian
CVE-2019-11692 critical 9.5 A use-after-free vulnerability can occur when listeners are removed from the event listener manager while still in use, resulting in a potentially exploitable crash. This vulnerability affects Thunde… archsusedebian
CVE-2019-17011 critical 9.5 Under certain conditions, when retrieving a document from a DocShell in the antitracking code, a race condition could cause a use-after-free condition and a potentially exploitable crash. This vulner… archsusedebian
CVE-2019-9800 critical 9.5 Mozilla developers and community members reported memory safety bugs present in Firefox 66, Firefox ESR 60.6, and Thunderbird 60.6. Some of these bugs showed evidence of memory corruption and we pres… archsusedebian
CVE-2019-11765 critical 9.5 A compromised content process could send a message to the parent process that would cause the 'Click to Play' permission prompt to be shown. However, due to lack of validation from the parent process… archdebian
CVE-2019-17001 critical 9.5 A Content-Security-Policy that blocks in-line scripts could be bypassed using an object tag to execute JavaScript in the protected document (cross-site scripting). This is a separate bypass from CVE-… archdebian
CVE-2019-3857 critical 9.5 An integer overflow flaw which could lead to an out of bounds write was discovered in libssh2 before 1.8.1 in the way SSH_MSG_CHANNEL_REQUEST packets with an exit signal are parsed. A remote attacker… archsusedebian
CVE-2019-13762 critical 9.5 Insufficient policy enforcement in downloads in Google Chrome on Windows prior to 79.0.3945.79 allowed a local attacker to spoof downloaded files via local code. archdebian
CVE-2019-13758 critical 9.5 Insufficient policy enforcement in navigation in Google Chrome on Android prior to 79.0.3945.79 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. archdebian
CVE-2019-13764 critical 9.5 Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. archdebian
CVE-2019-9788 critical 9.5 Mozilla developers and community members reported memory safety bugs present in Firefox 65, Firefox ESR 60.5, and Thunderbird 60.5. Some of these bugs showed evidence of memory corruption and we pres… archsusedebian
CVE-2019-11500 critical 9.5 In Dovecot before 2.2.36.4 and 2.3.x before 2.3.7.2 (and Pigeonhole before 0.5.7.2), protocol processing can fail for quoted strings. This occurs because '\0' characters are mishandled, and can lead … archsusedebian
CVE-2019-9810 critical 9.5 Incorrect alias information in IonMonkey JIT compiler for Array.prototype.slice method may lead to missing bounds check and a buffer overflow. This vulnerability affects Firefox < 66.0.1, Firefox ESR… archsusedebian
CVE-2019-17013 critical 9.5 Mozilla developers reported memory safety bugs present in Firefox 70. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been expl… archdebian
CVE-2019-11727 critical 9.5 A vulnerability exists where it possible to force Network Security Services (NSS) to sign CertificateVerify with PKCS#1 v1.5 signatures when those are the only ones advertised by server in Certificat… archsusedebian
CVE-2019-9789 critical 9.5 Mozilla developers and community members reported memory safety bugs present in Firefox 65. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of… archdebian
CVE-2019-9813 critical 9.5 Incorrect handling of __proto__ mutations may lead to type confusion in IonMonkey JIT code and can be leveraged for arbitrary memory read and write. This vulnerability affects Firefox < 66.0.1, Firef… archsusedebian
CVE-2019-11709 critical 9.5 Mozilla developers and community members reported memory safety bugs present in Firefox 67 and Firefox ESR 60.7. Some of these bugs showed evidence of memory corruption and we presume that with enoug… archdebian
CVE-2019-9797 critical 9.5 Cross-origin images can be read in violation of the same-origin policy by exporting an image after using createImageBitmap to read the image and then rendering the resulting bitmap image within a can… archsusedebian
CVE-2019-17010 critical 9.5 Under certain conditions, when checking the Resist Fingerprinting preference during device orientation checks, a race condition could have caused a use-after-free and a potentially exploitable crash.… archsusedebian
CVE-2019-5835 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5839 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5837 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5838 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5833 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5832 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5831 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5828 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5829 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5823 critical 9.5 multiple issues in chromium archdebian