CVEs from 2019

3,419 normalized CVEs published or assigned in this year.

Total
3,419
critical
critical 232
high
high 336
medium
medium 309
low
low 71
% Critical
6.8%
% with KEV
3.5%
% with exploit
3.5%

Top vendors

Top products

  • u-boot 20
  • active_iq_unified_manager 7
  • jdk 5
  • weblogic_server 5
  • oncommand_workflow_automation 5
  • codeready_linux_builder_eus 4
  • oncommand_insight 4
  • libxslt 4
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Published Description Impact
CVE-2019-12874 critical 9.5 arbitrary code execution in vlc archdebian
CVE-2019-9817 critical 9.5 Images from a different domain can be read using a canvas object in some circumstances. This could be used to steal image data from a different site in violation of same-origin policy. This vulnerabi… archsusedebian
CVE-2019-5830 critical 9.5 multiple issues in chromium archdebian
CVE-2019-3836 critical 9.5 It was discovered in gnutls before version 3.6.7 upstream that there is an uninitialized pointer access in gnutls versions 3.6.3 or later which can be triggered by certain post-handshake messages. archsusedebian
CVE-2019-11701 critical 9.5 The default webcal: protocol handler will load a web site vulnerable to cross-site scripting (XSS) attacks. This default was left in place as a legacy feature and has now been removed. *Note: this is… archsusedebian
CVE-2019-13736 critical 9.5 Integer overflow in PDFium in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. archdebian
CVE-2019-11695 critical 9.5 A custom cursor defined by scripting on a site can position itself over the addressbar to spoof the actual cursor when it should not be allowed outside of the primary web content area. This could be … archsusedebian
CVE-2019-13749 critical 9.5 Incorrect security UI in Omnibox in Google Chrome on iOS prior to 79.0.3945.79 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. archdebian
CVE-2019-13755 critical 9.5 Insufficient policy enforcement in extensions in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to disable extensions via a crafted HTML page. archdebian
CVE-2019-13756 critical 9.5 Incorrect security UI in printing in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via a crafted HTML page. archdebian
CVE-2019-13726 critical 9.5 Buffer overflow in password manager in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to execute arbitrary code via a crafted HTML page. archdebian
CVE-2019-5762 critical 9.5 multiple issues in chromium archdebian
CVE-2019-11696 critical 9.5 Files with the .JNLP extension used for "Java web start" applications are not treated as executable content for download prompts even though they can be executed if Java is installed on the local sys… archsusedebian
CVE-2019-5821 critical 9.5 multiple issues in chromium archdebian
CVE-2019-11718 critical 9.5 Activity Stream can display content from sent from the Snippet Service website. This content is written to innerHTML on the Activity Stream page without sanitization, allowing for a potential access … archdebian
CVE-2019-11723 critical 9.5 A vulnerability exists during the installation of add-ons where the initial fetch ignored the origin attributes of the browsing context. This could leak cookies in private browsing mode or across dif… archdebian
CVE-2019-11725 critical 9.5 When a user navigates to site marked as unsafe by the Safebrowsing API, warning messages are displayed and navigation is interrupted but resources from the same site loaded through websockets are not… archdebian
CVE-2019-11720 critical 9.5 Some unicode characters are incorrectly treated as whitespace during the parsing of web content instead of triggering parsing errors. This allows malicious code to then be processed, evading cross-si… archdebian
CVE-2019-11691 critical 9.5 A use-after-free vulnerability can occur when working with XMLHttpRequest (XHR) in an event loop, causing the XHR main thread to be called after it has been freed. This results in a potentially explo… archsusedebian
CVE-2019-11713 critical 9.5 A use-after-free vulnerability can occur in HTTP/2 when a cached HTTP/2 stream is closed while still in use, resulting in a potentially exploitable crash. This vulnerability affects Firefox ESR < 60.… archsusedebian
CVE-2019-17012 critical 9.5 Mozilla developers reported memory safety bugs present in Firefox 70 and Firefox ESR 68.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these… archsusedebian
CVE-2019-9795 critical 9.5 A vulnerability where type-confusion in the IonMonkey just-in-time (JIT) compiler could potentially be used by malicious JavaScript to trigger a potentially exploitable crash. This vulnerability affe… archsusedebian
CVE-2019-9792 critical 9.5 The IonMonkey just-in-time (JIT) compiler can leak an internal JS_OPTIMIZED_OUT magic value to the running script during a bailout. This magic value can then be used by JavaScript to achieve memory c… archsusedebian
CVE-2019-9821 critical 9.5 A use-after-free vulnerability can occur in AssertWorkerThread due to a race condition with shared workers. This results in a potentially exploitable crash. This vulnerability affects Firefox < 67. archsusedebian
CVE-2019-11714 critical 9.5 Necko can access a child on the wrong thread during UDP connections, resulting in a potentially exploitable crash in some instances. This vulnerability affects Firefox < 68. archdebian
CVE-2019-13757 critical 9.5 Incorrect security UI in Omnibox in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name. archdebian
CVE-2019-11697 critical 9.5 If the ALT and "a" keys are pressed when users receive an extension installation prompt, the extension will be installed without the install prompt delay that keeps the prompt visible in order for us… archsusedebian
CVE-2019-11699 critical 9.5 A malicious page can briefly cause the wrong name to be highlighted as the domain name in the addressbar during page navigations. This could result in user confusion of which site is currently loaded… archdebian
CVE-2019-11721 critical 9.5 The unicode latin 'kra' character can be used to spoof a standard 'k' character in the addressbar. This allows for domain spoofing attacks as do not display as punycode text, allowing for user confus… archdebian
CVE-2019-11716 critical 9.5 Until explicitly accessed by script, window.globalThis is not enumerable and, as a result, is not visible to code such as Object.getOwnPropertyNames(window). Sites that deploy a sandboxing that depen… archdebian
CVE-2019-5815 critical 9.5 4y ago multiple issues in chromium archdebianruby
CVE-2019-11708 high 9.5 4y ago Mozilla Firefox and Thunderbird contain a sandbox escape vulnerability that could result in remote code execution. archdebian
CVE-2019-5786 high 9.5 6y ago arbitrary code execution in chromium archdebiannpm
CVE-2019-14197 critical 9.1 9.1 7y ago An issue was discovered in Das U-Boot through 2019.07. There is a read of out-of-bounds data at nfs_read_reply. susedebian
CVE-2019-13721 high 8.8 8.8 7y ago Use after free in PDFium in Google Chrome prior to 78.0.3904.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. archdebiangcp
CVE-2019-25650 high 8.4 8.4 2mo ago River Past CamDo 3.7.6 contains a structured exception handler (SEH) buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious string in the Lame_en…
CVE-2019-25651 high 8.3 8.3 2mo ago Ubiquiti UniFi Network Controller prior to 5.10.12 (excluding 5.6.42), UAP FW prior to 4.0.6, UAP-AC, UAP-AC v2, and UAP-AC Outdoor FW prior to 3.8.17, USW FW prior to 4.0.6, USG FW prior to 4.4.34 u…
CVE-2019-25642 high 8.2 8.2 2mo ago Bootstrapy CMS contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through POST parameters. Attackers can…
CVE-2019-25640 high 8.2 8.2 2mo ago Inout Article Base CMS contains SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries through the 'p' and 'u' parameters. Attackers can inject SQL code usi…
CVE-2019-6820 high 8.2 8.2 7y ago A CWE-306: Missing Authentication for Critical Function vulnerability exists which could cause a modification of device IP configuration (IP address, network mask and gateway IP address) when a speci…
CVE-2019-9278 high 8.0 In libexif, there is a possible out of bounds write due to an integer overflow. This could lead to remote escalation of privilege in the media content provider with no additional execution privileges… archsusedebian
CVE-2019-13697 high 8.0 multiple issues in chromium archdebian
CVE-2019-3822 high 8.0 libcurl versions from 7.36.0 to before 7.64.0 are vulnerable to a stack-based buffer overflow. The function creating an outgoing NTLM type-3 header (`lib/vauth/ntlm.c:Curl_auth_create_ntlm_type3_mess… archsusedebian
CVE-2019-13701 high 8.0 multiple issues in chromium archdebian
CVE-2019-13693 high 8.0 multiple issues in chromium archdebian
CVE-2019-5858 high 8.0 multiple issues in chromium archdebian
CVE-2019-11743 high 8.0 Navigation events were not fully adhering to the W3C's "Navigation-Timing Level 2" draft specification in some instances for the unload event, which restricts access to detailed timing attributes to … archsusedebian
CVE-2019-5848 high 8.0 multiple issues in chromium archdebian
CVE-2019-11752 high 8.0 It is possible to delete an IndexedDB key value and subsequently try to extract it during conversion. This results in a use-after-free and a potentially exploitable crash. This vulnerability affects … archsusedebian
CVE-2019-3835 high 8.0 It was found that the superexec operator was available in the internal dictionary in ghostscript before 9.27. A specially crafted PostScript file could use this flaw in order to, for example, have ac… archsusedebian
CVE-2019-14811 high 8.0 A flaw was found in, ghostscript versions prior to 9.50, in the .pdf_hook_DSC_Creator procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restriction… archsusedebian
CVE-2019-5854 high 8.0 multiple issues in chromium archdebian
CVE-2019-10181 high 8.0 It was found that in icedtea-web up to and including 1.7.2 and 1.8.2 executable code could be injected in a JAR file without compromising the signature verification. An attacker could use this flaw t… archsusedebian
CVE-2019-5435 high 8.0 An integer overflow in curl's URL API results in a buffer overflow in libcurl 7.62.0 to and including 7.64.1. archdebian
CVE-2019-5796 high 8.0 multiple issues in chromium archdebian
CVE-2019-5794 high 8.0 multiple issues in chromium archdebian
CVE-2019-5802 high 8.0 multiple issues in chromium archdebian
CVE-2019-5799 high 8.0 multiple issues in chromium archdebian
CVE-2019-1000020 high 8.0 libarchive version commit 5a98dcf8a86364b3c2c469c85b93647dfb139961 onwards (version v2.8.0 onwards) contains a CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in ISO9660… archsusedebian
CVE-2019-11750 high 8.0 A type confusion vulnerability exists in Spidermonkey, which results in a non-exploitable crash. This vulnerability affects Firefox < 69 and Firefox ESR < 68.1. archsusedebian
CVE-2019-3814 high 8.0 It was discovered that Dovecot before versions 2.2.36.1 and 2.3.4.1 incorrectly handled client certificates. A remote attacker in possession of a valid certificate with an empty username field could … archsusedebian
CVE-2019-20503 high 8.0 multiple issues in chromium archdebiansuse
CVE-2019-3823 high 8.0 libcurl versions from 7.34.0 to before 7.64.0 are vulnerable to a heap out-of-bounds read in the code handling the end-of-response for SMTP. If the buffer passed to `smtp_endofresp()` isn't NUL termi… archsusedebian
CVE-2019-13699 high 8.0 multiple issues in chromium archdebian
CVE-2019-11705 high 8.0 A flaw in Thunderbird's implementation of iCal causes a stack buffer overflow in icalrecur_add_bydayrules when processing certain email messages, resulting in a potentially exploitable crash. This vu… archsusedebian
CVE-2019-5856 high 8.0 multiple issues in chromium archdebian
CVE-2019-8343 high 8.0 In Netwide Assembler (NASM) 2.14.02, there is a use-after-free in paste_tokens in asm/preproc.c. archsusedebian
CVE-2019-11735 high 8.0 Mozilla developers and community members reported memory safety bugs present in Firefox 68 and Firefox ESR 68. Some of these bugs showed evidence of memory corruption and we presume that with enough … archsusedebian
CVE-2019-13705 high 8.0 multiple issues in chromium archdebian
CVE-2019-19977 high 8.0 libESMTP through 1.0.6 mishandles domain copying into a fixed-size buffer in ntlm_build_type_2 in ntlm/ntlmstruct.c, as demonstrated by a stack-based buffer over-read. archsusedebian
CVE-2019-13710 high 8.0 multiple issues in chromium archdebian
CVE-2019-5798 high 8.0 multiple issues in chromium archdebian
CVE-2019-5860 high 8.0 multiple issues in chromium archdebian
CVE-2019-5859 high 8.0 multiple issues in chromium archdebian
CVE-2019-13706 high 8.0 multiple issues in chromium archdebian
CVE-2019-5789 high 8.0 multiple issues in chromium archdebian
CVE-2019-15903 high 8.0 multiple issues in chromium archdebiansuserockylinux
CVE-2019-6473 high 8.0 An invalid hostname option can trigger an assertion failure in the Kea DHCPv4 server process (kea-dhcp4), causing the server process to exit. Versions affected: 1.4.0 to 1.5.0, 1.6.0-beta1, and 1.6.0… archdebian
CVE-2019-13703 high 8.0 multiple issues in chromium archdebian
CVE-2019-14868 high 8.0 In ksh version 20120801, a flaw was found in the way it evaluates certain environment variables. An attacker could use this flaw to override or bypass environment restrictions to execute shell comman… archsusedebian
CVE-2019-19604 high 8.0 Arbitrary command execution is possible in Git before 2.20.2, 2.21.x before 2.21.1, 2.22.x before 2.22.2, 2.23.x before 2.23.1, and 2.24.x before 2.24.1 because a "git submodule update" operation can… archdebian
CVE-2019-0117 high 8.0 multiple issues in intel-ucode arch
CVE-2019-5851 high 8.0 multiple issues in chromium archdebian
CVE-2019-11747 high 8.0 The "Forget about this site" feature in the History pane is intended to remove all saved user data that indicates a user has visited a site. This includes removing any HTTP Strict Transport Security … archsusedebian
CVE-2019-13717 high 8.0 multiple issues in chromium archdebian
CVE-2019-5800 high 8.0 multiple issues in chromium archdebian
CVE-2019-11740 high 8.0 Mozilla developers and community members reported memory safety bugs present in Firefox 68, Firefox ESR 68, and Firefox 60.8. Some of these bugs showed evidence of memory corruption and we presume th… archsusedebian
CVE-2019-5850 high 8.0 multiple issues in chromium archdebian
CVE-2019-11748 high 8.0 WebRTC in Firefox will honor persisted permissions given to sites for access to microphone and camera resources even when in a third-party context. In light of recent high profile vulnerabilities in … archsusedebian
CVE-2019-13695 high 8.0 multiple issues in chromium archdebian
CVE-2019-11749 high 8.0 A vulnerability exists in WebRTC where malicious web content can use probing techniques on the getUserMedia API using constraints to reveal device properties of cameras on the system without triggeri… archsusedebian
CVE-2019-14817 high 8.0 A flaw was found in, ghostscript versions prior to 9.50, in the .pdfexectoken and other procedures where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrict… archsusedebian
CVE-2019-13704 high 8.0 multiple issues in chromium archdebian
CVE-2019-13719 high 8.0 multiple issues in chromium archdebian
CVE-2019-14813 high 8.0 A flaw was found in ghostscript, versions 9.x before 9.50, in the setsystemparams procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A… archsusedebian
CVE-2019-0190 high 8.0 multiple issues in apache debianarch
CVE-2019-8376 high 8.0 An issue was discovered in Tcpreplay 4.3.1. A NULL pointer dereference occurred in the function get_layer4_v6() located at get.c. This can be triggered by sending a crafted pcap file to the tcpreplay… archdebian
CVE-2019-5793 high 8.0 multiple issues in chromium archdebian
CVE-2019-5867 high 8.0 arbitrary code execution in chromium archdebian
CVE-2019-5787 high 8.0 multiple issues in chromium archdebian