CVEs from 2019

3,419 normalized CVEs published or assigned in this year.

Total
3,419
critical
critical 232
high
high 336
medium
medium 309
low
low 71
% Critical
6.8%
% with KEV
3.5%
% with exploit
3.5%

Top vendors

Top products

  • u-boot 20
  • active_iq_unified_manager 7
  • jdk 5
  • weblogic_server 5
  • oncommand_workflow_automation 5
  • codeready_linux_builder_eus 4
  • oncommand_insight 4
  • libxslt 4
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2019-13742 critical 9.5 Incorrect security UI in Omnibox in Google Chrome on iOS prior to 79.0.3945.79 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.
CVE-2019-5763 critical 9.5 multiple issues in chromium
CVE-2019-13764 critical 9.5 Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2019-11500 critical 9.5 In Dovecot before 2.2.36.4 and 2.3.x before 2.3.7.2 (and Pigeonhole before 0.5.7.2), protocol processing can fail for quoted strings. This occurs because '\0' characters are mishandled, and can lead …
CVE-2019-13725 critical 9.5 Use-after-free in Bluetooth in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to execute arbitrary code via a crafted HTML page.
CVE-2019-9800 critical 9.5 Mozilla developers and community members reported memory safety bugs present in Firefox 66, Firefox ESR 60.6, and Thunderbird 60.6. Some of these bugs showed evidence of memory corruption and we pres…
CVE-2019-5809 critical 9.5 multiple issues in chromium
CVE-2019-5813 critical 9.5 multiple issues in chromium
CVE-2019-5770 critical 9.5 multiple issues in chromium
CVE-2019-5772 critical 9.5 multiple issues in chromium
CVE-2019-5807 critical 9.5 multiple issues in chromium
CVE-2019-13747 critical 9.5 Uninitialized data in rendering in Google Chrome on Android prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2019-5754 critical 9.5 multiple issues in chromium
CVE-2019-5805 critical 9.5 multiple issues in chromium
CVE-2019-9797 critical 9.5 Cross-origin images can be read in violation of the same-origin policy by exporting an image after using createImageBitmap to read the image and then rendering the resulting bitmap image within a can…
CVE-2019-5836 critical 9.5 multiple issues in chromium
CVE-2019-5822 critical 9.5 multiple issues in chromium
CVE-2019-11759 critical 9.5 An attacker could have caused 4 bytes of HMAC output to be written past the end of a buffer stored on the stack. This could be used by an attacker to execute arbitrary code or more likely lead to a c…
CVE-2019-17009 critical 9.5 When running, the updater service wrote status and log files to an unrestricted location; potentially allowing an unprivileged process to locate and exploit a vulnerability in file handling in the up…
CVE-2019-11695 critical 9.5 A custom cursor defined by scripting on a site can position itself over the addressbar to spoof the actual cursor when it should not be allowed outside of the primary web content area. This could be …
CVE-2019-3836 critical 9.5 It was discovered in gnutls before version 3.6.7 upstream that there is an uninitialized pointer access in gnutls versions 3.6.3 or later which can be triggered by certain post-handshake messages.
CVE-2019-5837 critical 9.5 multiple issues in chromium
CVE-2019-13746 critical 9.5 Insufficient policy enforcement in Omnibox in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
CVE-2019-17000 critical 9.5 An object tag with a data URI did not correctly inherit the document's Content Security Policy. This allowed a CSP bypass in a cross-origin frame if the document's policy explicitly allowed data: URI…
CVE-2019-11701 critical 9.5 The default webcal: protocol handler will load a web site vulnerable to cross-site scripting (XSS) attacks. This default was left in place as a legacy feature and has now been removed. *Note: this is…
CVE-2019-7222 critical 9.5 The KVM implementation in the Linux kernel through 4.20.5 has an Information Leak.
CVE-2019-3856 critical 9.5 An integer overflow flaw, which could lead to an out of bounds write, was discovered in libssh2 before 1.8.1 in the way keyboard prompt requests are parsed. A remote attacker who compromises a SSH se…
CVE-2019-5759 critical 9.5 multiple issues in chromium
CVE-2019-17011 critical 9.5 Under certain conditions, when retrieving a document from a DocShell in the antitracking code, a race condition could cause a use-after-free condition and a potentially exploitable crash. This vulner…
CVE-2019-5758 critical 9.5 multiple issues in chromium
CVE-2019-5815 critical 9.5 4y ago multiple issues in chromium
CVE-2019-11708 high 9.5 4y ago Mozilla Firefox and Thunderbird contain a sandbox escape vulnerability that could result in remote code execution.
CVE-2019-5786 high 9.5 6y ago arbitrary code execution in chromium
CVE-2019-14197 critical 9.1 9.1 7y ago An issue was discovered in Das U-Boot through 2019.07. There is a read of out-of-bounds data at nfs_read_reply.
CVE-2019-13721 high 8.8 8.8 7y ago Use after free in PDFium in Google Chrome prior to 78.0.3904.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2019-25650 high 8.4 8.4 2mo ago River Past CamDo 3.7.6 contains a structured exception handler (SEH) buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious string in the Lame_en…
CVE-2019-25651 high 8.3 8.3 2mo ago Ubiquiti UniFi Network Controller prior to 5.10.12 (excluding 5.6.42), UAP FW prior to 4.0.6, UAP-AC, UAP-AC v2, and UAP-AC Outdoor FW prior to 3.8.17, USW FW prior to 4.0.6, USG FW prior to 4.4.34 u…
CVE-2019-25642 high 8.2 8.2 2mo ago Bootstrapy CMS contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through POST parameters. Attackers can…
CVE-2019-25640 high 8.2 8.2 2mo ago Inout Article Base CMS contains SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries through the 'p' and 'u' parameters. Attackers can inject SQL code usi…
CVE-2019-6820 high 8.2 8.2 7y ago A CWE-306: Missing Authentication for Critical Function vulnerability exists which could cause a modification of device IP configuration (IP address, network mask and gateway IP address) when a speci…
CVE-2019-11747 high 8.0 The "Forget about this site" feature in the History pane is intended to remove all saved user data that indicates a user has visited a site. This includes removing any HTTP Strict Transport Security …
CVE-2019-11683 high 8.0 udp_gro_receive_segment in net/ipv4/udp_offload.c in the Linux kernel 5.x before 5.0.13 allows remote attackers to cause a denial of service (slab-out-of-bounds memory corruption) or possibly have un…
CVE-2019-14869 high 8.0 A flaw was found in all versions of ghostscript 9.x before 9.50, where the `.charkeys` procedure, where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restricti…
CVE-2019-3822 high 8.0 libcurl versions from 7.36.0 to before 7.64.0 are vulnerable to a stack-based buffer overflow. The function creating an outgoing NTLM type-3 header (`lib/vauth/ntlm.c:Curl_auth_create_ntlm_type3_mess…
CVE-2019-6465 high 8.0 Controls for zone transfers may not be properly applied to Dynamically Loadable Zones (DLZs) if the zones are writable Versions affected: BIND 9.9.0 -> 9.10.8-P1, 9.11.0 -> 9.11.5-P2, 9.12.0 -> 9.12.…
CVE-2019-14318 high 8.0 Crypto++ 8.3.0 and earlier contains a timing side channel in ECDSA signature generation. This allows a local or remote attacker, able to measure the duration of hundreds to thousands of signing opera…
CVE-2019-11706 high 8.0 A flaw in Thunderbird's implementation of iCal causes a type confusion in icaltimezone_get_vtimezone_properties when processing certain email messages, resulting in a crash. This vulnerability affect…
CVE-2019-18634 high 8.0 In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the privileged sudo process. (pwfeedback is a default setting in Linux Mint and ele…
CVE-2019-5855 high 8.0 multiple issues in chromium
CVE-2019-11744 high 8.0 Some HTML elements, such as <title> and <textarea>, can contain literal angle brackets without treating them as markup. It is possible to pass a literal closing tag to .innerHTML on these…
CVE-2019-11740 high 8.0 Mozilla developers and community members reported memory safety bugs present in Firefox 68, Firefox ESR 68, and Firefox 60.8. Some of these bugs showed evidence of memory corruption and we presume th…
CVE-2019-8376 high 8.0 An issue was discovered in Tcpreplay 4.3.1. A NULL pointer dereference occurred in the function get_layer4_v6() located at get.c. This can be triggered by sending a crafted pcap file to the tcpreplay…
CVE-2019-18222 high 8.0 The ECDSA signature implementation in ecdsa.c in Arm Mbed Crypto 2.1 and Mbed TLS through 2.19.1 does not reduce the blinded scalar before computing the inverse, which allows a local attacker to reco…
CVE-2019-0190 high 8.0 multiple issues in apache
CVE-2019-25016 high 8.0 In OpenDoas from 6.6 to 6.8 the users PATH variable was incorrectly inherited by authenticated executions if the authenticating rule allowed the user to execute any command. Rules that only allowed t…
CVE-2019-13702 high 8.0 multiple issues in chromium
CVE-2019-13708 high 8.0 multiple issues in chromium
CVE-2019-1353 high 8.0 An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. When running Git in the Windows Subsystem for Linux (also known…
CVE-2019-13696 high 8.0 multiple issues in chromium
CVE-2019-11738 high 8.0 If a Content Security Policy (CSP) directive is defined that uses a hash-based source that takes the empty string as input, execution of any javascript: URIs will be allowed. This could allow for mal…
CVE-2019-6472 high 8.0 A packet containing a malformed DUID can cause the Kea DHCPv6 server process (kea-dhcp6) to exit due to an assertion failure. Versions affected: 1.4.0 to 1.5.0, 1.6.0-beta1, and 1.6.0-beta2.
CVE-2019-9686 high 8.0 arbitrary code execution in pacman
CVE-2019-5789 high 8.0 multiple issues in chromium
CVE-2019-11752 high 8.0 It is possible to delete an IndexedDB key value and subsequently try to extract it during conversion. This results in a use-after-free and a potentially exploitable crash. This vulnerability affects …
CVE-2019-9812 high 8.0 Given a compromised sandboxed content process due to a separate vulnerability, it is possible to escape that sandbox by loading accounts.firefox.com in that process and forcing a log-in to a maliciou…
CVE-2019-9893 high 8.0 libseccomp before 2.4.0 did not correctly generate 64-bit syscall argument comparisons using the arithmetic operators (LT, GT, LE, GE), which might able to lead to bypassing seccomp filters and poten…
CVE-2019-5793 high 8.0 multiple issues in chromium
CVE-2019-8343 high 8.0 In Netwide Assembler (NASM) 2.14.02, there is a use-after-free in paste_tokens in asm/preproc.c.
CVE-2019-5800 high 8.0 multiple issues in chromium
CVE-2019-5850 high 8.0 multiple issues in chromium
CVE-2019-5847 high 8.0 multiple issues in chromium
CVE-2019-5860 high 8.0 multiple issues in chromium
CVE-2019-11704 high 8.0 A flaw in Thunderbird's implementation of iCal causes a heap buffer overflow in icalmemory_strdup_and_dequote when processing certain email messages, resulting in a potentially exploitable crash. Thi…
CVE-2019-5851 high 8.0 multiple issues in chromium
CVE-2019-8907 high 8.0 do_core_note in readelf.c in libmagic.a in file 5.35 allows remote attackers to cause a denial of service (stack corruption and application crash) or possibly have unspecified other impact.
CVE-2019-5795 high 8.0 multiple issues in chromium
CVE-2019-5852 high 8.0 multiple issues in chromium
CVE-2019-5854 high 8.0 multiple issues in chromium
CVE-2019-5859 high 8.0 multiple issues in chromium
CVE-2019-5861 high 8.0 multiple issues in chromium
CVE-2019-5857 high 8.0 multiple issues in chromium
CVE-2019-5868 high 8.0 arbitrary code execution in chromium
CVE-2019-5436 high 8.0 A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1.
CVE-2019-5862 high 8.0 multiple issues in chromium
CVE-2019-13697 high 8.0 multiple issues in chromium
CVE-2019-13706 high 8.0 multiple issues in chromium
CVE-2019-13704 high 8.0 multiple issues in chromium
CVE-2019-13710 high 8.0 multiple issues in chromium
CVE-2019-5435 high 8.0 An integer overflow in curl's URL API results in a buffer overflow in libcurl 7.62.0 to and including 7.64.1.
CVE-2019-5792 high 8.0 multiple issues in chromium
CVE-2019-5858 high 8.0 multiple issues in chromium
CVE-2019-13713 high 8.0 multiple issues in chromium
CVE-2019-13715 high 8.0 multiple issues in chromium
CVE-2019-14811 high 8.0 A flaw was found in, ghostscript versions prior to 9.50, in the .pdf_hook_DSC_Creator procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restriction…
CVE-2019-11703 high 8.0 A flaw in Thunderbird's implementation of iCal causes a heap buffer overflow in parser_get_next_char when processing certain email messages, resulting in a potentially exploitable crash. This vulnera…
CVE-2019-13716 high 8.0 multiple issues in chromium
CVE-2019-5794 high 8.0 multiple issues in chromium
CVE-2019-2201 high 8.0 In generate_jsimd_ycc_rgb_convert_neon of jsimd_arm64_neon.S, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution in an unprivileged proces…
CVE-2019-8337 high 8.0 In msmtp 1.8.2 and mpop 1.4.3, when tls_trust_file has its default configuration, certificate-verification results are not properly checked.
CVE-2019-13703 high 8.0 multiple issues in chromium