CVEs from 2019

3,602 normalized CVEs published or assigned in this year.

Total
3,602
critical
critical 232
high
high 332
medium
medium 301
low
low 72
% Critical
6.4%
% with KEV
3.3%
% with exploit
3.4%

Top vendors

Top products

  • u-boot 20
  • nsauditor 1
  • crypto 1
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Published Description Impact
CVE-2019-5828 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5831 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5832 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5833 critical 9.5 multiple issues in chromium archdebian
CVE-2019-7314 critical 9.5 multiple issues in live-media arch
CVE-2019-11763 critical 9.5 Failure to correctly handle null bytes when processing HTML entities resulted in Firefox incorrectly parsing these entities. This could have led to HTML comment text being treated as HTML which could… archdebian
CVE-2019-5838 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5837 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5839 critical 9.5 multiple issues in chromium archdebian
CVE-2019-5835 critical 9.5 multiple issues in chromium archdebian
CVE-2019-11730 critical 9.5 A vulnerability exists where if a user opens a locally saved HTML file, this file can use file: URIs to access other files in the same directory or sub-directories if the names are known or guessed. … archdebian
CVE-2019-5840 critical 9.5 multiple issues in chromium archdebian
CVE-2019-13721 critical 9.5 arbitrary code execution in chromium archdebian
CVE-2019-19923 critical 9.5 multiple issues in chromium archdebiansuse
CVE-2019-5760 critical 9.5 multiple issues in chromium archdebian
CVE-2019-13744 critical 9.5 Insufficient policy enforcement in cookies in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to leak cross-origin data via a crafted HTML page. archdebian
CVE-2019-19926 critical 9.5 multiple issues in chromium archdebiansuse
CVE-2019-9814 critical 9.5 Mozilla developers and community members reported memory safety bugs present in Firefox 66. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of… archsusedebian
CVE-2019-9821 critical 9.5 A use-after-free vulnerability can occur in AssertWorkerThread due to a race condition with shared workers. This results in a potentially exploitable crash. This vulnerability affects Firefox < 67. archsusedebian
CVE-2019-3861 critical 9.5 An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SSH packets with a padding length value greater than the packet length are parsed. A remote attacker who compromises a SSH… archsusedebian
CVE-2019-9810 critical 9.5 Incorrect alias information in IonMonkey JIT compiler for Array.prototype.slice method may lead to missing bounds check and a buffer overflow. This vulnerability affects Firefox < 66.0.1, Firefox ESR… archsusedebian
CVE-2019-11693 critical 9.5 The bufferdata function in WebGL is vulnerable to a buffer overflow with specific graphics drivers on Linux. This could result in malicious content freezing a tab or triggering a potentially exploita… archsusedebian
CVE-2019-17005 critical 9.5 The plain text serializer used a fixed-size array for the number of <ol> elements it could process; however it was possible to overflow the static-sized array leading to memory corruption and a poten… archsusedebian
CVE-2019-11701 critical 9.5 The default webcal: protocol handler will load a web site vulnerable to cross-site scripting (XSS) attacks. This default was left in place as a legacy feature and has now been removed. *Note: this is… archsusedebian
CVE-2019-11692 critical 9.5 A use-after-free vulnerability can occur when listeners are removed from the event listener manager while still in use, resulting in a potentially exploitable crash. This vulnerability affects Thunde… archsusedebian
CVE-2019-3857 critical 9.5 An integer overflow flaw which could lead to an out of bounds write was discovered in libssh2 before 1.8.1 in the way SSH_MSG_CHANNEL_REQUEST packets with an exit signal are parsed. A remote attacker… archsusedebian
CVE-2019-3858 critical 9.5 An out of bounds read flaw was discovered in libssh2 before 1.8.1 when a specially crafted SFTP packet is received from the server. A remote attacker who compromises a SSH server may be able to cause… archsusedebian
CVE-2019-3862 critical 9.5 An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SSH_MSG_CHANNEL_REQUEST packets with an exit status message and no payload are parsed. A remote attacker who compromises a… archsusedebian
CVE-2019-3863 critical 9.5 A flaw was found in libssh2 before 1.8.1 creating a vulnerability on the SSH client side. A server could send a multiple keyboard interactive response messages whose total length are greater than uns… archsusedebian
CVE-2019-5815 critical 9.5 4y ago multiple issues in chromium archdebianruby
CVE-2019-18197 critical 9.5 4y ago multiple issues in chromium archsusedebianruby
CVE-2019-11708 high 9.5 4y ago Mozilla Firefox and Thunderbird contain a sandbox escape vulnerability that could result in remote code execution. archdebian
CVE-2019-5786 high 9.5 6y ago arbitrary code execution in chromium archdebiannpm
CVE-2019-14197 critical 9.1 9.1 7y ago An issue was discovered in Das U-Boot through 2019.07. There is a read of out-of-bounds data at nfs_read_reply. susedebian
CVE-2019-25650 high 8.4 8.4 2mo ago River Past CamDo 3.7.6 contains a structured exception handler (SEH) buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious string in the Lame_en…
CVE-2019-25651 high 8.3 8.3 2mo ago Ubiquiti UniFi Network Controller prior to 5.10.12 (excluding 5.6.42), UAP FW prior to 4.0.6, UAP-AC, UAP-AC v2, and UAP-AC Outdoor FW prior to 3.8.17, USW FW prior to 4.0.6, USG FW prior to 4.4.34 u…
CVE-2019-25642 high 8.2 8.2 2mo ago Bootstrapy CMS contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through POST parameters. Attackers can…
CVE-2019-25640 high 8.2 8.2 2mo ago Inout Article Base CMS contains SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries through the 'p' and 'u' parameters. Attackers can inject SQL code usi…
CVE-2019-5803 high 8.0 multiple issues in chromium archdebian
CVE-2019-3871 high 8.0 A vulnerability was found in PowerDNS Authoritative Server before 4.0.7 and before 4.1.7. An insufficient validation of data coming from the user when building a HTTP request from a DNS query in the … archsusedebian
CVE-2019-3835 high 8.0 It was found that the superexec operator was available in the internal dictionary in ghostscript before 9.27. A specially crafted PostScript file could use this flaw in order to, for example, have ac… archsusedebian
CVE-2019-12749 high 8.0 dbus before 1.10.28, 1.12.x before 1.12.16, and 1.13.x before 1.13.12, as used in DBusServer in Canonical Upstart in Ubuntu 14.04 (and in some, less common, uses of dbus-daemon), allows cookie spoofi… archsusedebian
CVE-2019-15717 high 8.0 Irssi 1.2.x before 1.2.2 has a use-after-free if the IRC server sends a double CAP. archdebian
CVE-2019-12735 high 8.0 getchar.c in Vim before 8.1.1365 and Neovim before 0.3.6 allows remote attackers to execute arbitrary OS commands via the :source! command in a modeline, as demonstrated by execute in Vim, and assert… archsusedebian
CVE-2019-10182 high 8.0 It was found that icedtea-web though 1.7.2 and 1.8.2 did not properly sanitize paths from <jar/> elements in JNLP files. An attacker could trick a victim into running a specially crafted application … archsusedebian
CVE-2019-10185 high 8.0 It was found that icedtea-web up to and including 1.7.2 and 1.8.2 was vulnerable to a zip-slip attack during auto-extraction of a JAR file. An attacker could use this flaw to write files to arbitrary… archsusedebian
CVE-2019-5436 high 8.0 A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1. archsusedebian
CVE-2019-11748 high 8.0 WebRTC in Firefox will honor persisted permissions given to sites for access to microphone and camera resources even when in a third-party context. In light of recent high profile vulnerabilities in … archsusedebian
CVE-2019-11735 high 8.0 Mozilla developers and community members reported memory safety bugs present in Firefox 68 and Firefox ESR 68. Some of these bugs showed evidence of memory corruption and we presume that with enough … archsusedebian
CVE-2019-2201 high 8.0 In generate_jsimd_ycc_rgb_convert_neon of jsimd_arm64_neon.S, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution in an unprivileged proces… archsusedebian
CVE-2019-6116 high 8.0 In Artifex Ghostscript through 9.26, ephemeral or transient procedures can allow access to system operators, leading to remote code execution. archsusedebian
CVE-2019-13709 high 8.0 multiple issues in chromium archdebian
CVE-2019-13711 high 8.0 multiple issues in chromium archdebian
CVE-2019-14811 high 8.0 A flaw was found in, ghostscript versions prior to 9.50, in the .pdf_hook_DSC_Creator procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restriction… archsusedebian
CVE-2019-8906 high 8.0 do_core_note in readelf.c in libmagic.a in file 5.35 has an out-of-bounds read because memcpy is misused. archsusedebian
CVE-2019-3814 high 8.0 It was discovered that Dovecot before versions 2.2.36.1 and 2.3.4.1 incorrectly handled client certificates. A remote attacker in possession of a valid certificate with an empty username field could … archsusedebian
CVE-2019-5853 high 8.0 multiple issues in chromium archdebian
CVE-2019-10181 high 8.0 It was found that in icedtea-web up to and including 1.7.2 and 1.8.2 executable code could be injected in a JAR file without compromising the signature verification. An attacker could use this flaw t… archsusedebian
CVE-2019-8337 high 8.0 In msmtp 1.8.2 and mpop 1.4.3, when tls_trust_file has its default configuration, certificate-verification results are not properly checked. archdebian
CVE-2019-5865 high 8.0 multiple issues in chromium archdebian
CVE-2019-5864 high 8.0 multiple issues in chromium archdebian
CVE-2019-6472 high 8.0 A packet containing a malformed DUID can cause the Kea DHCPv6 server process (kea-dhcp6) to exit due to an assertion failure. Versions affected: 1.4.0 to 1.5.0, 1.6.0-beta1, and 1.6.0-beta2. archdebian
CVE-2019-9686 high 8.0 arbitrary code execution in pacman arch
CVE-2019-14868 high 8.0 In ksh version 20120801, a flaw was found in the way it evaluates certain environment variables. An attacker could use this flaw to override or bypass environment restrictions to execute shell comman… archsusedebian
CVE-2019-1350 high 8.0 A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-201… archdebian
CVE-2019-8943 high 8.0 WordPress through 5.0.3 allows Path Traversal in wp_crop_image(). An attacker (who has privileges to crop an image) can write the output image to an arbitrary directory via a filename containing two … archdebian
CVE-2019-9849 high 8.0 LibreOffice has a 'stealth mode' in which only documents from locations deemed 'trusted' are allowed to retrieve remote resources. This mode is not the default mode, but can be enabled by users who w… archsusedebian
CVE-2019-3838 high 8.0 It was found that the forceput operator could be extracted from the DefineResource method in ghostscript before 9.27. A specially crafted PostScript file could use this flaw in order to, for example,… archsusedebian
CVE-2019-5797 high 8.0 multiple issues in chromium archdebian
CVE-2019-1000020 high 8.0 libarchive version commit 5a98dcf8a86364b3c2c469c85b93647dfb139961 onwards (version v2.8.0 onwards) contains a CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in ISO9660… archsusedebian
CVE-2019-5842 high 8.0 arbitrary code execution in chromium archdebian
CVE-2019-5848 high 8.0 multiple issues in chromium archdebian
CVE-2019-19977 high 8.0 libESMTP through 1.0.6 mishandles domain copying into a fixed-size buffer in ntlm_build_type_2 in ntlm/ntlmstruct.c, as demonstrated by a stack-based buffer over-read. archsusedebian
CVE-2019-7524 high 8.0 In Dovecot before 2.2.36.3 and 2.3.x before 2.3.5.1, a local attacker can cause a buffer overflow in the indexer-worker process, which can be used to elevate to root. This occurs because of missing c… archsusedebian
CVE-2019-11749 high 8.0 A vulnerability exists in WebRTC where malicious web content can use probing techniques on the getUserMedia API using constraints to reveal device properties of cameras on the system without triggeri… archsusedebian
CVE-2019-5788 high 8.0 multiple issues in chromium archdebian
CVE-2019-3823 high 8.0 libcurl versions from 7.34.0 to before 7.64.0 are vulnerable to a heap out-of-bounds read in the code handling the end-of-response for SMTP. If the buffer passed to `smtp_endofresp()` isn't NUL termi… archsusedebian
CVE-2019-5435 high 8.0 An integer overflow in curl's URL API results in a buffer overflow in libcurl 7.62.0 to and including 7.64.1. archdebian
CVE-2019-5792 high 8.0 multiple issues in chromium archdebian
CVE-2019-9278 high 8.0 In libexif, there is a possible out of bounds write due to an integer overflow. This could lead to remote escalation of privilege in the media content provider with no additional execution privileges… archsusedebian
CVE-2019-11742 high 8.0 A same-origin policy violation occurs allowing the theft of cross-origin images through a combination of SVG filters and a &lt;canvas&gt; element due to an error in how same-origin policy is applied … archsusedebian
CVE-2019-11139 high 8.0 Improper conditions check in the voltage modulation interface for some Intel(R) Xeon(R) Scalable Processors may allow a privileged user to potentially enable denial of service via local access. archdebian
CVE-2019-1353 high 8.0 An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. When running Git in the Windows Subsystem for Linux (also known… archdebian
CVE-2019-8343 high 8.0 In Netwide Assembler (NASM) 2.14.02, there is a use-after-free in paste_tokens in asm/preproc.c. archsusedebian
CVE-2019-5858 high 8.0 multiple issues in chromium archdebian
CVE-2019-13694 high 8.0 multiple issues in chromium archdebian
CVE-2019-9848 high 8.0 LibreOffice has a feature where documents can specify that pre-installed scripts can be executed on various document events such as mouse-over, etc. LibreOffice is typically also bundled with LibreLo… archsusedebian
CVE-2019-1349 high 8.0 A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-201… archdebian
CVE-2019-1352 high 8.0 A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-201… archdebian
CVE-2019-1387 high 8.0 An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. Recursive clones are currently affected by a vulnerability that… archdebian
CVE-2019-11461 high 8.0 An issue was discovered in GNOME Nautilus 3.30 prior to 3.30.6 and 3.32 prior to 3.32.1. A compromised thumbnailer may escape the bubblewrap sandbox used to confine thumbnailers by using the TIOCSTI … archsusedebian
CVE-2019-11706 high 8.0 A flaw in Thunderbird's implementation of iCal causes a type confusion in icaltimezone_get_vtimezone_properties when processing certain email messages, resulting in a crash. This vulnerability affect… archsusedebian
CVE-2019-6109 high 8.0 An issue was discovered in OpenSSH 7.9. Due to missing character encoding in the progress display, a malicious server (or Man-in-The-Middle attacker) can employ crafted object names to manipulate the… archsusedebian
CVE-2019-6465 high 8.0 Controls for zone transfers may not be properly applied to Dynamically Loadable Zones (DLZs) if the zones are writable Versions affected: BIND 9.9.0 -> 9.10.8-P1, 9.11.0 -> 9.11.5-P2, 9.12.0 -> 9.12.… debianarchsuse
CVE-2019-1000019 high 8.0 libarchive version commit bf9aec176c6748f0ee7a678c5f9f9555b9a757c1 onwards (release v3.0.2 onwards) contains a CWE-125: Out-of-bounds Read vulnerability in 7zip decompression, archive_read_support_fo… archsusedebian
CVE-2019-13706 high 8.0 multiple issues in chromium archdebian
CVE-2019-13705 high 8.0 multiple issues in chromium archdebian
CVE-2019-13701 high 8.0 multiple issues in chromium archdebian
CVE-2019-13699 high 8.0 multiple issues in chromium archdebian
CVE-2019-13717 high 8.0 multiple issues in chromium archdebian