CVEs from 2019

3,413 normalized CVEs published or assigned in this year.

Total
3,413
critical
critical 232
high
high 332
medium
medium 301
low
low 72
% Critical
6.8%
% with KEV
3.5%
% with exploit
3.5%

Top vendors

Top products

  • u-boot 20
  • nsauditor 1
  • crypto 1
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Published Description Impact
CVE-2019-17023 medium 5.5 After a HelloRetryRequest has been sent, the client may negotiate a lower protocol that TLS 1.3, resulting in an invalid state transition in the TLS State Machine. If the client gets into this state,… archdebianrockylinux
CVE-2019-3459 medium 5.5 A heap address information leak while using L2CAP_GET_CONF_OPT was discovered in the Linux kernel before 5.1-rc1. archsusedebian
CVE-2019-3460 medium 5.5 A heap data infoleak in multiple locations including L2CAP_PARSE_CONF_RSP was found in the Linux kernel before 5.1-rc1. archsusedebian
CVE-2019-3806 medium 5.5 An issue has been found in PowerDNS Recursor versions after 4.1.3 before 4.1.9 where Lua hooks are not properly applied to queries received over TCP in some specific combination of settings, possibly… archdebian
CVE-2019-3807 medium 5.5 An issue has been found in PowerDNS Recursor versions 4.1.x before 4.1.9 where records in the answer section of responses received from authoritative servers with the AA flag not set were not properl… archdebian
CVE-2019-25042 medium 5.5 Unbound before 1.9.5 allows an out-of-bounds write via a compressed name in rdata_copy. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound … suserockylinuxdebian
CVE-2019-3842 medium 5.5 In systemd before v242-rc4, it was discovered that pam_systemd does not properly sanitize the environment before using the XDG_SEAT variable. It is possible for an attacker, in some particular config… suserockylinuxdebian
CVE-2019-12209 medium 5.5 Yubico pam-u2f 1.0.7 attempts parsing of the configured authfile (default $HOME/.config/Yubico/u2f_keys) as root (unless openasuser was enabled), and does not properly verify that the path lacks syml… archsusedebian
CVE-2019-5718 medium 5.5 In Wireshark 2.6.0 to 2.6.5 and 2.4.0 to 2.4.11, the RTSE dissector and other ASN.1 dissectors could crash. This was addressed in epan/charsets.c by adding a get_t61_string length check. archsusedebian
CVE-2019-11499 medium 5.5 In the IMAP Server in Dovecot 2.3.3 through 2.3.5.2, the submission-login component crashes if AUTH PLAIN is attempted over a TLS secured channel with an unacceptable authentication message. archdebian
CVE-2019-15946 medium 5.5 OpenSC before 0.20.0-rc1 has an out-of-bounds access of an ASN.1 Octet string in asn1_decode_entry in libopensc/asn1.c. archsusedebian
CVE-2019-20637 medium 5.5 An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x before 6.2.2, and 6.3.x before 6.3.1. It does not clear a pointer between the handling of one client request and the next re… rockylinuxdebian
CVE-2019-6476 medium 5.5 A defect in code added to support QNAME minimization can cause named to exit with an assertion failure if a forwarder returns a referral rather than resolving the query. This affects BIND versions 9.… debianarchsuse
CVE-2019-10209 medium 5.5 multiple issues in postgresql-libs, postgresql arch
CVE-2019-7149 medium 5.5 A heap-based buffer over-read was discovered in the function read_srclines in dwarf_getsrclines.c in libdw in elfutils 0.175. A crafted input can cause segmentation faults, leading to denial-of-servi… archdebian
CVE-2019-12420 medium 5.5 In Apache SpamAssassin before 3.4.3, a message can be crafted in a way to use excessive resources. Upgrading to SA 3.4.3 as soon as possible is the recommended fix but details will not be shared publ… archsusedebian
CVE-2019-10179 medium 5.5 Moderate: pki-core:10.6 and pki-deps:10.6 security, bug fix, and enhancement update debianrockylinux
CVE-2019-6291 medium 5.5 An issue was discovered in the function expr6 in eval.c in Netwide Assembler (NASM) through 2.14.02. There is a stack exhaustion problem caused by the expr6 function making recursive calls to itself … archdebian
CVE-2019-13627 medium 5.5 Moderate: libgcrypt security, bug fix, and enhancement update archsusedebianrockylinux
CVE-2019-15892 medium 5.5 An issue was discovered in Varnish Cache before 6.0.4 LTS, and 6.1.x and 6.2.x before 6.2.1. An HTTP/1 parsing failure allows a remote attacker to trigger an assert by sending crafted HTTP/1 requests… rockylinuxdebian
CVE-2019-15043 medium 5.5 denial of service in grafana archsuse
CVE-2019-11756 medium 5.5 Moderate: nss and nspr security, bug fix, and enhancement update archdebianrockylinux
CVE-2019-7663 medium 5.5 An Invalid Address dereference was discovered in TIFFWriteDirectoryTagTransferfunction in libtiff/tif_dirwrite.c in LibTIFF 4.0.10, affecting the cpSeparateBufToContigBuf function in tiffcp.c. Remote… archsusedebian
CVE-2019-5717 medium 5.5 In Wireshark 2.6.0 to 2.6.5 and 2.4.0 to 2.4.11, the P_MUL dissector could crash. This was addressed in epan/dissectors/packet-p_mul.c by rejecting the invalid sequence number of zero. archsusedebian
CVE-2019-5719 medium 5.5 In Wireshark 2.6.0 to 2.6.5 and 2.4.0 to 2.4.11, the ISAKMP dissector could crash. This was addressed in epan/dissectors/packet-isakmp.c by properly handling the case of a missing decryption data blo… archsusedebian
CVE-2019-25597 medium 5.5 5.5 2mo ago NSauditor 3.1.2.0 contains a buffer overflow vulnerability in the SNMP Auditor Community field that allows local attackers to crash the application by supplying an excessively long string. Attackers …
CVE-2019-17543 medium 5.5 11mo ago Moderate: lz4 security update rockylinuxsusedebian
CVE-2019-19012 medium 5.5 1y ago Moderate: oniguruma security update rockylinuxdebian
CVE-2019-12900 medium 5.5 1y ago Moderate: bzip2 security update redhatdebianrockylinuxsuse
CVE-2019-25162 medium 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: i2c: Fix a potential use after free Free the adap structure only after we are done using it. This patch just moves the put_device… redhatrockylinuxsusedebian
CVE-2019-15505 medium 5.5 2y ago drivers/media/usb/dvb-usb/technisat-usb2.c in the Linux kernel through 5.2.9 has an out-of-bounds read via crafted USB device traffic (which may be remote via usbip or usbredir). rockylinuxsusedebian
CVE-2019-13631 medium 5.5 2y ago In parse_hid_report_descriptor in drivers/input/tablet/gtco.c in the Linux kernel through 5.2.1, a malicious USB device can send an HID report that triggers an out-of-bounds write during generation o… suserockylinuxdebian
CVE-2019-19204 medium 5.5 2y ago Moderate: php:7.3 security, bug fix, and enhancement update susedebianrockylinux
CVE-2019-13224 medium 5.5 2y ago Moderate: php:7.3 security, bug fix, and enhancement update susedebianrockylinux
CVE-2019-16163 medium 5.5 2y ago Moderate: php:7.3 security, bug fix, and enhancement update susedebianrockylinux
CVE-2019-19203 medium 5.5 2y ago Moderate: php:7.3 security, bug fix, and enhancement update susedebianrockylinux
CVE-2019-19499 medium 5.5 2y ago Moderate: grafana security, bug fix, and enhancement update susegolang
CVE-2019-19921 medium 5.5 3y ago Moderate: container-tools:rhel8 security, bug fix, and enhancement update rockylinuxredhatdebiangolang
CVE-2019-14560 medium 5.5 3y ago Moderate: edk2 security, bug fix, and enhancement update archredhatsuse
CVE-2019-25058 medium 5.5 3y ago An issue was discovered in USBGuard before 1.1.0. On systems with the usbguard-dbus daemon running, an unprivileged user could make USBGuard allow all USB devices to be connected in the future. redhatsuserockylinuxdebian
CVE-2019-14809 medium 5.5 4y ago Incorrect parsing validation in net/url archgolang
CVE-2019-6446 medium 5.5 4y ago Moderate: python27:2.7 security and bug fix update suserockylinuxpython
CVE-2019-17596 medium 5.5 4y ago Panic on invalid DSA public keys in crypto/dsa archsusegolang
CVE-2019-10383 medium 5.5 4y ago Improper Neutralization of Input During Web Page Generation in Jenkins archjava
CVE-2019-10384 medium 5.5 4y ago Cross-Site Request Forgery in Jenkins archjava
CVE-2019-6486 medium 5.5 4y ago Denial of service affecting P-521 and P-384 curves in crypto/elliptic archsusegolang
CVE-2019-11236 medium 5.5 4y ago Moderate: python27:2.7 security, bug fix, and enhancement update rockylinuxdebianpython
CVE-2019-1003050 medium 5.5 4y ago Improper Neutralization of Input During Web Page Generation in Jenkins archjava
CVE-2019-1003049 medium 5.5 4y ago Insufficient Session Expiration in Jenkins archjava
CVE-2019-25051 medium 5.5 4y ago Moderate: aspell security update debianarchsuserockylinux
CVE-2019-19004 medium 5.5 5y ago Moderate: autotrace security update
CVE-2019-19005 medium 5.5 5y ago Moderate: autotrace security update
CVE-2019-17594 medium 5.5 5y ago Moderate: ncurses security update suserockylinuxdebian
CVE-2019-17595 medium 5.5 5y ago Moderate: ncurses security update suserockylinuxdebian
CVE-2019-13750 medium 5.5 5y ago Moderate: sqlite security update archdebianrockylinux
CVE-2019-19603 medium 5.5 5y ago Moderate: sqlite security update suserockylinuxdebian
CVE-2019-13751 medium 5.5 5y ago Moderate: sqlite security update archdebianrockylinux
CVE-2019-5827 medium 5.5 5y ago Moderate: sqlite security update debianrockylinux
CVE-2019-18218 medium 5.5 5y ago Moderate: file security update archsusedebianrockylinux
CVE-2019-14615 medium 5.5 5y ago Insufficient control flow in certain data structures for some Intel(R) Processors with Intel(R) Processor Graphics may allow an unauthenticated user to potentially enable information disclosure via l… susedebian
CVE-2019-12973 medium 5.5 5y ago Moderate: openjpeg2 security update archsuserockylinuxdebian
CVE-2019-15845 medium 5.5 5y ago Moderate: ruby:2.5 security, bug fix, and enhancement update archsuserockylinuxdebian
CVE-2019-16255 medium 5.5 5y ago Moderate: ruby:2.6 security, bug fix, and enhancement update archsuserockylinuxdebian
CVE-2019-16201 medium 5.5 5y ago Moderate: ruby:2.6 security, bug fix, and enhancement update archsuserockylinuxdebian
CVE-2019-16254 medium 5.5 5y ago Moderate: ruby:2.6 security, bug fix, and enhancement update archsuserockylinuxdebian
CVE-2019-20916 medium 5.5 5y ago Moderate: python27:2.7 security update suserockylinuxdebianpython
CVE-2019-16168 medium 5.5 5y ago Moderate: mingw packages security and bug fix update rockylinuxsusedebian
CVE-2019-20839 medium 5.5 5y ago Moderate: libvncserver security update suserockylinuxdebian
CVE-2019-13012 medium 5.5 5y ago Moderate: GNOME security, bug fix, and enhancement update susedebianrockylinux
CVE-2019-9169 medium 5.5 5y ago Moderate: glibc security, bug fix, and enhancement update archsusedebianrockylinux
CVE-2019-25013 medium 5.5 5y ago Moderate: glibc security, bug fix, and enhancement update archsusedebianrockylinux
CVE-2019-20477 medium 5.5 5y ago Moderate: python38:3.8 security, bug fix, and enhancement update rockylinuxdebianpython
CVE-2019-13225 medium 5.5 6y ago Moderate: php:7.3 security, bug fix, and enhancement update suserockylinuxdebian
CVE-2019-10092 medium 5.5 6y ago Moderate: httpd:2.4 security, bug fix, and enhancement update debiansuserockylinux
CVE-2019-10082 medium 5.5 6y ago Moderate: httpd:2.4 security, bug fix, and enhancement update debiansuserockylinux
CVE-2019-10081 medium 5.5 6y ago Moderate: httpd:2.4 security, bug fix, and enhancement update debiansuserockylinux
CVE-2019-0197 medium 5.5 6y ago Moderate: httpd:2.4 security, bug fix, and enhancement update debianarchrockylinux
CVE-2019-10097 medium 5.5 6y ago Moderate: httpd:2.4 security, bug fix, and enhancement update debiansuserockylinux
CVE-2019-10098 medium 5.5 6y ago Moderate: httpd:2.4 security, bug fix, and enhancement update debiansuserockylinux
CVE-2019-0196 medium 5.5 6y ago Moderate: httpd:2.4 security, bug fix, and enhancement update debianarchsuserockylinux
CVE-2019-18676 medium 5.5 6y ago Moderate: squid:4 security, bug fix, and enhancement update suserockylinuxdebian
CVE-2019-12521 medium 5.5 6y ago Moderate: squid:4 security, bug fix, and enhancement update archsuserockylinuxdebian
CVE-2019-12524 medium 5.5 6y ago Moderate: squid:4 security, bug fix, and enhancement update suserockylinuxdebian
CVE-2019-18679 medium 5.5 6y ago Moderate: squid:4 security, bug fix, and enhancement update archsuserockylinuxdebian
CVE-2019-18678 medium 5.5 6y ago Moderate: squid:4 security, bug fix, and enhancement update archsuserockylinuxdebian
CVE-2019-12528 medium 5.5 6y ago Moderate: squid:4 security, bug fix, and enhancement update suserockylinuxdebian
CVE-2019-12523 medium 5.5 6y ago Moderate: squid:4 security, bug fix, and enhancement update suserockylinuxdebian
CVE-2019-12526 medium 5.5 6y ago Moderate: squid:4 security, bug fix, and enhancement update archsuserockylinuxdebian
CVE-2019-12520 medium 5.5 6y ago Moderate: squid:4 security, bug fix, and enhancement update suserockylinuxdebian
CVE-2019-12529 medium 5.5 6y ago Moderate: squid:4 security, bug fix, and enhancement update suserockylinuxdebian
CVE-2019-18860 medium 5.5 6y ago Moderate: squid:4 security, bug fix, and enhancement update suserockylinuxdebian
CVE-2019-18677 medium 5.5 6y ago Moderate: squid:4 security, bug fix, and enhancement update suserockylinuxdebian
CVE-2019-12854 medium 5.5 6y ago Moderate: squid:4 security, bug fix, and enhancement update suserockylinuxdebian
CVE-2019-20446 medium 5.5 6y ago Moderate: librsvg2 security update suserockylinuxdebian
CVE-2019-3833 medium 5.5 6y ago Moderate: openwsman security update suserockylinux
CVE-2019-20485 medium 5.5 6y ago Moderate: virt:rhel and virt-devel:rhel security, bug fix, and enhancement update suserockylinuxdebian
CVE-2019-6977 medium 5.5 6y ago Moderate: gd security update archsusedebianrockylinux
CVE-2019-20907 medium 5.5 6y ago Moderate: python38:3.8 security, bug fix, and enhancement update suserockylinuxdebian
CVE-2019-17546 medium 5.5 6y ago tif_getimage.c in LibTIFF through 4.0.10, as used in GDAL through 3.0.1 and other products, has an integer overflow that potentially causes a heap-based buffer overflow via a crafted RGBA image, rela… susedebianrockylinux
CVE-2019-9232 medium 5.5 6y ago Moderate: libvpx security update suserockylinuxdebian