CVEs from 2019

3,413 normalized CVEs published or assigned in this year.

Total
3,413
critical
critical 232
high
high 332
medium
medium 301
low
low 72
% Critical
6.8%
% with KEV
3.5%
% with exploit
3.5%

Top vendors

Top products

  • u-boot 20
  • nsauditor 1
  • crypto 1
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Published Description Impact
CVE-2019-14287 high 8.0 In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and session PAM modules, and can cause incorrect logging, by invoking sudo with a cra… archsusedebian
CVE-2019-9812 high 8.0 Given a compromised sandboxed content process due to a separate vulnerability, it is possible to escape that sandbox by loading accounts.firefox.com in that process and forcing a log-in to a maliciou… archsusedebian
CVE-2019-3822 high 8.0 libcurl versions from 7.36.0 to before 7.64.0 are vulnerable to a stack-based buffer overflow. The function creating an outgoing NTLM type-3 header (`lib/vauth/ntlm.c:Curl_auth_create_ntlm_type3_mess… archsusedebian
CVE-2019-1350 high 8.0 A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-201… archdebian
CVE-2019-5854 high 8.0 multiple issues in chromium archdebian
CVE-2019-1354 high 8.0 A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-201… archsusedebian
CVE-2019-5861 high 8.0 multiple issues in chromium archdebian
CVE-2019-14817 high 8.0 A flaw was found in, ghostscript versions prior to 9.50, in the .pdfexectoken and other procedures where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrict… archsusedebian
CVE-2019-2201 high 8.0 In generate_jsimd_ycc_rgb_convert_neon of jsimd_arm64_neon.S, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution in an unprivileged proces… archsusedebian
CVE-2019-11703 high 8.0 A flaw in Thunderbird's implementation of iCal causes a heap buffer overflow in parser_get_next_char when processing certain email messages, resulting in a potentially exploitable crash. This vulnera… archsusedebian
CVE-2019-5858 high 8.0 multiple issues in chromium archdebian
CVE-2019-5862 high 8.0 multiple issues in chromium archdebian
CVE-2019-6956 high 8.0 An issue was discovered in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. It is a buffer over-read in ps_mix_phase in libfaad/ps_dec.c. archdebian
CVE-2019-13697 high 8.0 multiple issues in chromium archdebian
CVE-2019-11738 high 8.0 If a Content Security Policy (CSP) directive is defined that uses a hash-based source that takes the empty string as input, execution of any javascript: URIs will be allowed. This could allow for mal… archsusedebian
CVE-2019-13704 high 8.0 multiple issues in chromium archdebian
CVE-2019-13710 high 8.0 multiple issues in chromium archdebian
CVE-2019-10182 high 8.0 It was found that icedtea-web though 1.7.2 and 1.8.2 did not properly sanitize paths from <jar/> elements in JNLP files. An attacker could trick a victim into running a specially crafted application … archsusedebian
CVE-2019-13713 high 8.0 multiple issues in chromium archdebian
CVE-2019-11479 high 8.0 Jonathan Looney discovered that the Linux kernel default MSS is hard-coded to 48 bytes. This allows a remote peer to fragment TCP resend queues significantly more than if a larger MSS were enforced. … archsusedebian
CVE-2019-13715 high 8.0 multiple issues in chromium archdebian
CVE-2019-11744 high 8.0 Some HTML elements, such as &lt;title&gt; and &lt;textarea&gt;, can contain literal angle brackets without treating them as markup. It is possible to pass a literal closing tag to .innerHTML on these… archsusedebian
CVE-2019-13716 high 8.0 multiple issues in chromium archdebian
CVE-2019-5794 high 8.0 multiple issues in chromium archdebian
CVE-2019-10185 high 8.0 It was found that icedtea-web up to and including 1.7.2 and 1.8.2 was vulnerable to a zip-slip attack during auto-extraction of a JAR file. An attacker could use this flaw to write files to arbitrary… archsusedebian
CVE-2019-5796 high 8.0 multiple issues in chromium archdebian
CVE-2019-11746 high 8.0 A use-after-free vulnerability can occur while manipulating video elements if the body is freed while still in use. This results in a potentially exploitable crash. This vulnerability affects Firefox… archsusedebian
CVE-2019-13703 high 8.0 multiple issues in chromium archdebian
CVE-2019-5855 high 8.0 multiple issues in chromium archdebian
CVE-2019-13707 high 8.0 multiple issues in chromium archdebian
CVE-2019-8943 high 8.0 WordPress through 5.0.3 allows Path Traversal in wp_crop_image(). An attacker (who has privileges to crop an image) can write the output image to an arbitrary directory via a filename containing two … archdebian
CVE-2019-15903 high 8.0 multiple issues in chromium archdebiansuserockylinux
CVE-2019-13719 high 8.0 multiple issues in chromium archdebian
CVE-2019-14811 high 8.0 A flaw was found in, ghostscript versions prior to 9.50, in the .pdf_hook_DSC_Creator procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restriction… archsusedebian
CVE-2019-20503 high 8.0 multiple issues in chromium archdebiansuse
CVE-2019-11683 high 8.0 udp_gro_receive_segment in net/ipv4/udp_offload.c in the Linux kernel 5.x before 5.0.13 allows remote attackers to cause a denial of service (slab-out-of-bounds memory corruption) or possibly have un… archsusedebian
CVE-2019-7524 high 8.0 In Dovecot before 2.2.36.3 and 2.3.x before 2.3.5.1, a local attacker can cause a buffer overflow in the indexer-worker process, which can be used to elevate to root. This occurs because of missing c… archsusedebian
CVE-2019-13709 high 8.0 multiple issues in chromium archdebian
CVE-2019-13693 high 8.0 multiple issues in chromium archdebian
CVE-2019-6133 high 8.0 In PolicyKit (aka polkit) 0.115, the "start time" protection mechanism can be bypassed because fork() is not atomic, and therefore authorization decisions are improperly cached. This is related to la… archsusedebian
CVE-2019-1348 high 8.0 An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. The --export-marks option of git fast-import is exposed also vi… archsusedebian
CVE-2019-11477 high 8.0 Jonathan Looney discovered that the TCP_SKB_CB(skb)->tcp_gso_segs value was subject to an integer overflow in the Linux kernel when handling TCP Selective Acknowledgments (SACKs). A remote attacker c… archsusedebian
CVE-2019-13695 high 8.0 multiple issues in chromium archdebian
CVE-2019-5489 high 8.0 The mincore() implementation in mm/mincore.c in the Linux kernel through 4.19.13 allowed local attackers to observe page cache access patterns of other processes on the same system, potentially allow… archsusedebian
CVE-2019-13717 high 8.0 multiple issues in chromium archdebian
CVE-2019-13711 high 8.0 multiple issues in chromium archdebian
CVE-2019-11740 high 8.0 Mozilla developers and community members reported memory safety bugs present in Firefox 68, Firefox ESR 68, and Firefox 60.8. Some of these bugs showed evidence of memory corruption and we presume th… archsusedebian
CVE-2019-13699 high 8.0 multiple issues in chromium archdebian
CVE-2019-1349 high 8.0 A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-201… archdebian
CVE-2019-11749 high 8.0 A vulnerability exists in WebRTC where malicious web content can use probing techniques on the getUserMedia API using constraints to reveal device properties of cameras on the system without triggeri… archsusedebian
CVE-2019-10063 high 8.0 Flatpak before 1.0.8, 1.1.x and 1.2.x before 1.2.4, and 1.3.x before 1.3.1 allows a sandbox bypass. Flatpak versions since 0.8.1 address CVE-2017-5226 by using a seccomp filter to prevent sandboxed a… archsusedebian
CVE-2019-1000019 high 8.0 libarchive version commit bf9aec176c6748f0ee7a678c5f9f9555b9a757c1 onwards (release v3.0.2 onwards) contains a CWE-125: Out-of-bounds Read vulnerability in 7zip decompression, archive_read_support_fo… archsusedebian
CVE-2019-10192 high 8.0 A heap-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x before 4.0.14 and 5.x before 5.0.4. By carefully corrupting a hyperloglog using … rockylinuxdebian
CVE-2019-13701 high 8.0 multiple issues in chromium archdebian
CVE-2019-6474 high 8.0 A missing check on incoming client requests can be exploited to cause a situation where the Kea server's lease storage contains leases which are rejected as invalid when the server tries to load leas… archdebian
CVE-2019-13705 high 8.0 multiple issues in chromium archdebian
CVE-2019-5857 high 8.0 multiple issues in chromium archdebian
CVE-2019-11478 high 8.0 Jonathan Looney discovered that the TCP retransmission queue implementation in tcp_fragment in the Linux kernel could be fragmented when handling certain TCP Selective Acknowledgment (SACK) sequences… archsusedebian
CVE-2019-13694 high 8.0 multiple issues in chromium archdebian
CVE-2019-13706 high 8.0 multiple issues in chromium archdebian
CVE-2019-5859 high 8.0 multiple issues in chromium archdebian
CVE-2019-11734 high 8.0 Mozilla developers and community members reported memory safety bugs present in Firefox 68. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of… archdebian
CVE-2019-5847 high 8.0 multiple issues in chromium archdebian
CVE-2019-8337 high 8.0 In msmtp 1.8.2 and mpop 1.4.3, when tls_trust_file has its default configuration, certificate-verification results are not properly checked. archdebian
CVE-2019-5852 high 8.0 multiple issues in chromium archdebian
CVE-2019-1387 high 8.0 An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. Recursive clones are currently affected by a vulnerability that… archdebian
CVE-2019-11741 high 8.0 A compromised sandboxed content process can perform a Universal Cross-site Scripting (UXSS) attack on content from any site it can cause to be loaded in the same process. Because addons.mozilla.org a… archdebian
CVE-2019-12749 high 8.0 dbus before 1.10.28, 1.12.x before 1.12.16, and 1.13.x before 1.13.12, as used in DBusServer in Canonical Upstart in Ubuntu 14.04 (and in some, less common, uses of dbus-daemon), allows cookie spoofi… archsusedebian
CVE-2019-5795 high 8.0 multiple issues in chromium archdebian
CVE-2019-10193 high 8.0 A stack-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x before 4.0.14 and 5.x before 5.0.4. By corrupting a hyperloglog using the SETRA… rockylinuxdebian
CVE-2019-6111 high 8.0 An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses which files/directories are sent to the client. However, the scp client only perf… archsusedebian
CVE-2019-14813 high 8.0 A flaw was found in ghostscript, versions 9.x before 9.50, in the setsystemparams procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A… archsusedebian
CVE-2019-5798 high 8.0 multiple issues in chromium archdebian
CVE-2019-13718 high 8.0 multiple issues in chromium archdebian
CVE-2019-13700 high 8.0 multiple issues in chromium archdebian
CVE-2019-16866 high 8.0 Unbound before 1.9.4 accesses uninitialized memory, which allows remote attackers to trigger a crash via a crafted NOTIFY query. The source IP address of the query must match an access-control rule. archdebian
CVE-2019-13702 high 8.0 multiple issues in chromium archdebian
CVE-2019-14869 high 8.0 A flaw was found in all versions of ghostscript 9.x before 9.50, where the `.charkeys` procedure, where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restricti… archsusedebian
CVE-2019-13708 high 8.0 multiple issues in chromium archdebian
CVE-2019-13696 high 8.0 multiple issues in chromium archdebian
CVE-2019-5867 high 8.0 arbitrary code execution in chromium archdebian
CVE-2019-8377 high 8.0 An issue was discovered in Tcpreplay 4.3.1. A NULL pointer dereference occurred in the function get_ipv6_l4proto() located at get.c. This can be triggered by sending a crafted pcap file to the tcprep… archdebian
CVE-2019-5788 high 8.0 multiple issues in chromium archdebian
CVE-2019-5790 high 8.0 multiple issues in chromium archdebian
CVE-2019-5791 high 8.0 multiple issues in chromium archdebian
CVE-2019-6473 high 8.0 An invalid hostname option can trigger an assertion failure in the Kea DHCPv4 server process (kea-dhcp4), causing the server process to exit. Versions affected: 1.4.0 to 1.5.0, 1.6.0-beta1, and 1.6.0… archdebian
CVE-2019-5797 high 8.0 multiple issues in chromium archdebian
CVE-2019-11139 high 8.0 Improper conditions check in the voltage modulation interface for some Intel(R) Xeon(R) Scalable Processors may allow a privileged user to potentially enable denial of service via local access. archdebian
CVE-2019-9686 high 8.0 arbitrary code execution in pacman arch
CVE-2019-1353 high 8.0 An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. When running Git in the Windows Subsystem for Linux (also known… archdebian
CVE-2019-11750 high 8.0 A type confusion vulnerability exists in Spidermonkey, which results in a non-exploitable crash. This vulnerability affects Firefox < 69 and Firefox ESR < 68.1. archsusedebian
CVE-2019-5865 high 8.0 multiple issues in chromium archdebian
CVE-2019-10181 high 8.0 It was found that in icedtea-web up to and including 1.7.2 and 1.8.2 executable code could be injected in a JAR file without compromising the signature verification. An attacker could use this flaw t… archsusedebian
CVE-2019-5864 high 8.0 multiple issues in chromium archdebian
CVE-2019-5848 high 8.0 multiple issues in chromium archdebian
CVE-2019-5842 high 8.0 arbitrary code execution in chromium archdebian
CVE-2019-12881 high 8.0 i915_gem_userptr_get_pages in drivers/gpu/drm/i915/i915_gem_userptr.c in the Linux kernel 4.15.0 on Ubuntu 18.04.2 allows local users to cause a denial of service (NULL pointer dereference and BUG) o… archsusedebian
CVE-2019-6116 high 8.0 In Artifex Ghostscript through 9.26, ephemeral or transient procedures can allow access to system operators, leading to remote code execution. archsusedebian
CVE-2019-8906 high 8.0 do_core_note in readelf.c in libmagic.a in file 5.35 has an out-of-bounds read because memcpy is misused. archsusedebian
CVE-2019-5803 high 8.0 multiple issues in chromium archdebian