CVEs from 2019

3,412 normalized CVEs published or assigned in this year.

Total
3,412
critical
critical 232
high
high 332
medium
medium 301
low
low 72
% Critical
6.8%
% with KEV
3.5%
% with exploit
3.5%

Top vendors

Top products

  • u-boot 20
  • nsauditor 1
  • crypto 1
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Published Description Impact
CVE-2019-14287 high 8.0 In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and session PAM modules, and can cause incorrect logging, by invoking sudo with a cra… archsusedebian
CVE-2019-11744 high 8.0 Some HTML elements, such as <title> and <textarea>, can contain literal angle brackets without treating them as markup. It is possible to pass a literal closing tag to .innerHTML on these… archsusedebian
CVE-2019-16866 high 8.0 Unbound before 1.9.4 accesses uninitialized memory, which allows remote attackers to trigger a crash via a crafted NOTIFY query. The source IP address of the query must match an access-control rule. archdebian
CVE-2019-19882 high 8.0 shadow 4.8, in certain circumstances affecting at least Gentoo, Arch Linux, and Void Linux, allows local users to obtain root access because setuid programs are misconfigured. Specifically, this affe… archdebian
CVE-2019-14812 high 8.0 A flaw was found in all ghostscript versions 9.x before 9.50, in the .setuserparams2 procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions… archsusedebian
CVE-2019-13694 high 8.0 multiple issues in chromium archdebian
CVE-2019-5791 high 8.0 multiple issues in chromium archdebian
CVE-2019-1349 high 8.0 A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-201… archdebian
CVE-2019-5867 high 8.0 arbitrary code execution in chromium archdebian
CVE-2019-8376 high 8.0 An issue was discovered in Tcpreplay 4.3.1. A NULL pointer dereference occurred in the function get_layer4_v6() located at get.c. This can be triggered by sending a crafted pcap file to the tcpreplay… archdebian
CVE-2019-13708 high 8.0 multiple issues in chromium archdebian
CVE-2019-5787 high 8.0 multiple issues in chromium archdebian
CVE-2019-13702 high 8.0 multiple issues in chromium archdebian
CVE-2019-13696 high 8.0 multiple issues in chromium archdebian
CVE-2019-12735 high 8.0 getchar.c in Vim before 8.1.1365 and Neovim before 0.3.6 allows remote attackers to execute arbitrary OS commands via the :source! command in a modeline, as demonstrated by execute in Vim, and assert… archsusedebian
CVE-2019-1353 high 8.0 An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. When running Git in the Windows Subsystem for Linux (also known… archdebian
CVE-2019-25016 high 8.0 In OpenDoas from 6.6 to 6.8 the users PATH variable was incorrectly inherited by authenticated executions if the authenticating rule allowed the user to execute any command. Rules that only allowed t… archdebian
CVE-2019-11139 high 8.0 Improper conditions check in the voltage modulation interface for some Intel(R) Xeon(R) Scalable Processors may allow a privileged user to potentially enable denial of service via local access. archdebian
CVE-2019-11738 high 8.0 If a Content Security Policy (CSP) directive is defined that uses a hash-based source that takes the empty string as input, execution of any javascript: URIs will be allowed. This could allow for mal… archsusedebian
CVE-2019-5797 high 8.0 multiple issues in chromium archdebian
CVE-2019-11742 high 8.0 A same-origin policy violation occurs allowing the theft of cross-origin images through a combination of SVG filters and a <canvas> element due to an error in how same-origin policy is applied … archsusedebian
CVE-2019-6472 high 8.0 A packet containing a malformed DUID can cause the Kea DHCPv6 server process (kea-dhcp6) to exit due to an assertion failure. Versions affected: 1.4.0 to 1.5.0, 1.6.0-beta1, and 1.6.0-beta2. archdebian
CVE-2019-9812 high 8.0 Given a compromised sandboxed content process due to a separate vulnerability, it is possible to escape that sandbox by loading accounts.firefox.com in that process and forcing a log-in to a maliciou… archsusedebian
CVE-2019-9893 high 8.0 libseccomp before 2.4.0 did not correctly generate 64-bit syscall argument comparisons using the arithmetic operators (LT, GT, LE, GE), which might able to lead to bypassing seccomp filters and poten… archsusedebian
CVE-2019-6133 high 8.0 In PolicyKit (aka polkit) 0.115, the "start time" protection mechanism can be bypassed because fork() is not atomic, and therefore authorization decisions are improperly cached. This is related to la… archsusedebian
CVE-2019-14811 high 8.0 A flaw was found in, ghostscript versions prior to 9.50, in the .pdf_hook_DSC_Creator procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restriction… archsusedebian
CVE-2019-11741 high 8.0 A compromised sandboxed content process can perform a Universal Cross-site Scripting (UXSS) attack on content from any site it can cause to be loaded in the same process. Because addons.mozilla.org a… archdebian
CVE-2019-5868 high 8.0 arbitrary code execution in chromium archdebian
CVE-2019-5489 high 8.0 The mincore() implementation in mm/mincore.c in the Linux kernel through 4.19.13 allowed local attackers to observe page cache access patterns of other processes on the same system, potentially allow… archsusedebian
CVE-2019-5436 high 8.0 A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1. archsusedebian
CVE-2019-9686 high 8.0 arbitrary code execution in pacman arch
CVE-2019-11706 high 8.0 A flaw in Thunderbird's implementation of iCal causes a type confusion in icaltimezone_get_vtimezone_properties when processing certain email messages, resulting in a crash. This vulnerability affect… archsusedebian
CVE-2019-3814 high 8.0 It was discovered that Dovecot before versions 2.2.36.1 and 2.3.4.1 incorrectly handled client certificates. A remote attacker in possession of a valid certificate with an empty username field could … archsusedebian
CVE-2019-3871 high 8.0 A vulnerability was found in PowerDNS Authoritative Server before 4.0.7 and before 4.1.7. An insufficient validation of data coming from the user when building a HTTP request from a DNS query in the … archsusedebian
CVE-2019-13695 high 8.0 multiple issues in chromium archdebian
CVE-2019-11740 high 8.0 Mozilla developers and community members reported memory safety bugs present in Firefox 68, Firefox ESR 68, and Firefox 60.8. Some of these bugs showed evidence of memory corruption and we presume th… archsusedebian
CVE-2019-5842 high 8.0 arbitrary code execution in chromium archdebian
CVE-2019-2201 high 8.0 In generate_jsimd_ycc_rgb_convert_neon of jsimd_arm64_neon.S, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution in an unprivileged proces… archsusedebian
CVE-2019-6109 high 8.0 An issue was discovered in OpenSSH 7.9. Due to missing character encoding in the progress display, a malicious server (or Man-in-The-Middle attacker) can employ crafted object names to manipulate the… archsusedebian
CVE-2019-13717 high 8.0 multiple issues in chromium archdebian
CVE-2019-1352 high 8.0 A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-201… archdebian
CVE-2019-10181 high 8.0 It was found that in icedtea-web up to and including 1.7.2 and 1.8.2 executable code could be injected in a JAR file without compromising the signature verification. An attacker could use this flaw t… archsusedebian
CVE-2019-5792 high 8.0 multiple issues in chromium archdebian
CVE-2019-13705 high 8.0 multiple issues in chromium archdebian
CVE-2019-12749 high 8.0 dbus before 1.10.28, 1.12.x before 1.12.16, and 1.13.x before 1.13.12, as used in DBusServer in Canonical Upstart in Ubuntu 14.04 (and in some, less common, uses of dbus-daemon), allows cookie spoofi… archsusedebian
CVE-2019-11479 high 8.0 Jonathan Looney discovered that the Linux kernel default MSS is hard-coded to 48 bytes. This allows a remote peer to fragment TCP resend queues significantly more than if a larger MSS were enforced. … archsusedebian
CVE-2019-5435 high 8.0 An integer overflow in curl's URL API results in a buffer overflow in libcurl 7.62.0 to and including 7.64.1. archdebian
CVE-2019-11746 high 8.0 A use-after-free vulnerability can occur while manipulating video elements if the body is freed while still in use. This results in a potentially exploitable crash. This vulnerability affects Firefox… archsusedebian
CVE-2019-10193 high 8.0 A stack-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x before 4.0.14 and 5.x before 5.0.4. By corrupting a hyperloglog using the SETRA… rockylinuxdebian
CVE-2019-11683 high 8.0 udp_gro_receive_segment in net/ipv4/udp_offload.c in the Linux kernel 5.x before 5.0.13 allows remote attackers to cause a denial of service (slab-out-of-bounds memory corruption) or possibly have un… archsusedebian
CVE-2019-15717 high 8.0 Irssi 1.2.x before 1.2.2 has a use-after-free if the IRC server sends a double CAP. archdebian
CVE-2019-5790 high 8.0 multiple issues in chromium archdebian
CVE-2019-6465 high 8.0 Controls for zone transfers may not be properly applied to Dynamically Loadable Zones (DLZs) if the zones are writable Versions affected: BIND 9.9.0 -> 9.10.8-P1, 9.11.0 -> 9.11.5-P2, 9.12.0 -> 9.12.… debianarchsuse
CVE-2019-11750 high 8.0 A type confusion vulnerability exists in Spidermonkey, which results in a non-exploitable crash. This vulnerability affects Firefox < 69 and Firefox ESR < 68.1. archsusedebian
CVE-2019-13709 high 8.0 multiple issues in chromium archdebian
CVE-2019-3823 high 8.0 libcurl versions from 7.34.0 to before 7.64.0 are vulnerable to a heap out-of-bounds read in the code handling the end-of-response for SMTP. If the buffer passed to `smtp_endofresp()` isn't NUL termi… archsusedebian
CVE-2019-13693 high 8.0 multiple issues in chromium archdebian
CVE-2019-8337 high 8.0 In msmtp 1.8.2 and mpop 1.4.3, when tls_trust_file has its default configuration, certificate-verification results are not properly checked. archdebian
CVE-2019-5864 high 8.0 multiple issues in chromium archdebian
CVE-2019-10192 high 8.0 A heap-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x before 4.0.14 and 5.x before 5.0.4. By carefully corrupting a hyperloglog using … rockylinuxdebian
CVE-2019-11703 high 8.0 A flaw in Thunderbird's implementation of iCal causes a heap buffer overflow in parser_get_next_char when processing certain email messages, resulting in a potentially exploitable crash. This vulnera… archsusedebian
CVE-2019-5848 high 8.0 multiple issues in chromium archdebian
CVE-2019-11478 high 8.0 Jonathan Looney discovered that the TCP retransmission queue implementation in tcp_fragment in the Linux kernel could be fragmented when handling certain TCP Selective Acknowledgment (SACK) sequences… archsusedebian
CVE-2019-18183 high 8.0 arbitrary command execution in pacman arch
CVE-2019-14318 high 8.0 Crypto++ 8.3.0 and earlier contains a timing side channel in ECDSA signature generation. This allows a local or remote attacker, able to measure the duration of hundreds to thousands of signing opera… archdebian
CVE-2019-11477 high 8.0 Jonathan Looney discovered that the TCP_SKB_CB(skb)->tcp_gso_segs value was subject to an integer overflow in the Linux kernel when handling TCP Selective Acknowledgments (SACKs). A remote attacker c… archsusedebian
CVE-2019-1348 high 8.0 An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. The --export-marks option of git fast-import is exposed also vi… archsusedebian
CVE-2019-13699 high 8.0 multiple issues in chromium archdebian
CVE-2019-13701 high 8.0 multiple issues in chromium archdebian
CVE-2019-11752 high 8.0 It is possible to delete an IndexedDB key value and subsequently try to extract it during conversion. This results in a use-after-free and a potentially exploitable crash. This vulnerability affects … archsusedebian
CVE-2019-13706 high 8.0 multiple issues in chromium archdebian
CVE-2019-9848 high 8.0 LibreOffice has a feature where documents can specify that pre-installed scripts can be executed on various document events such as mouse-over, etc. LibreOffice is typically also bundled with LibreLo… archsusedebian
CVE-2019-8377 high 8.0 An issue was discovered in Tcpreplay 4.3.1. A NULL pointer dereference occurred in the function get_ipv6_l4proto() located at get.c. This can be triggered by sending a crafted pcap file to the tcprep… archdebian
CVE-2019-19450 high 8.0 3y ago Important: python-reportlab security update susedebianpython
CVE-2019-18466 high 8.0 4y ago Important: container-tools:rhel8 security and bug fix update susedebianrockylinuxgolang
CVE-2019-9512 high 8.0 4y ago Important: container-tools:rhel8 security and bug fix update archsusedebianrockylinux+1
CVE-2019-9514 high 8.0 4y ago Important: nodejs:10 security update archsusedebianrockylinux+1
CVE-2019-10352 high 8.0 4y ago Improper Limitation of a Pathname to a Restricted Directory in Jenkins archjava
CVE-2019-10353 high 8.0 4y ago Cross-Site Request Forgery in Jenkins archjava
CVE-2019-10354 high 8.0 4y ago Missing Authorization in Jenkins archjava
CVE-2019-16276 high 8.0 4y ago Request smuggling due to accepting invalid headers in net/http via net/textproto archsusegolang
CVE-2019-2435 high 8.0 4y ago Improper Access Control in MySQL Connector Python archsusedebianpython
CVE-2019-5885 high 8.0 4y ago Matrix Synapse before 0.34.0.1, when the macaroon_secret_key authentication parameter is not set, uses a predictable value to derive a secret key and other secrets which could allow remote attackers … archdebianpython
CVE-2019-16884 high 8.0 4y ago Important: container-tools:rhel8 security and bug fix update susedebianrockylinuxgolang
CVE-2019-10214 high 8.0 4y ago Important: container-tools:rhel8 security, bug fix, and enhancement update susedebianrockylinuxgolang
CVE-2019-19523 high 8.0 5y ago In the Linux kernel before 5.3.7, there is a use-after-free bug that can be caused by a malicious USB device in the drivers/usb/misc/adutux.c driver, aka CID-44efc269db79. susedebian
CVE-2019-19528 high 8.0 5y ago In the Linux kernel before 5.3.7, there is a use-after-free bug that can be caused by a malicious USB device in the drivers/usb/misc/iowarrior.c driver, aka CID-edc4746f253d. susedebian
CVE-2019-18811 high 8.0 5y ago A memory leak in the sof_set_get_large_ctrl_data() function in sound/soc/sof/ipc.c in the Linux kernel through 5.3.9 allows attackers to cause a denial of service (memory consumption) by triggering s… susedebian
CVE-2019-2974 high 8.0 6y ago Important: mysql:8.0 security update suserockylinux
CVE-2019-2938 high 8.0 6y ago Important: mysql:8.0 security update suserockylinux
CVE-2019-15890 high 8.0 6y ago Important: container-tools:rhel8 security, bug fix, and enhancement update suserockylinuxdebian
CVE-2019-3011 high 8.0 6y ago Important: mysql:8.0 security update suserockylinuxalmalinux
CVE-2019-2946 high 8.0 6y ago Important: mysql:8.0 security update suserockylinux
CVE-2019-2967 high 8.0 6y ago Important: mysql:8.0 security update suserockylinux
CVE-2019-2993 high 8.0 6y ago Important: mysql:8.0 security update suserockylinux
CVE-2019-2960 high 8.0 6y ago Important: mysql:8.0 security update suserockylinux
CVE-2019-2991 high 8.0 6y ago Important: mysql:8.0 security update suserockylinux
CVE-2019-2914 high 8.0 6y ago Important: mysql:8.0 security update suserockylinux
CVE-2019-2968 high 8.0 6y ago Important: mysql:8.0 security update suserockylinux
CVE-2019-3009 high 8.0 6y ago Important: mysql:8.0 security update suserockylinux