CVEs from 2019

3,413 normalized CVEs published or assigned in this year.

Total
3,413
critical
critical 232
high
high 332
medium
medium 301
low
low 72
% Critical
6.8%
% with KEV
3.5%
% with exploit
3.5%

Top vendors

Top products

  • u-boot 20
  • nsauditor 1
  • crypto 1
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Published Description Impact
CVE-2019-15166 medium 5.5 lmp_print_data_link_subobjs() in print-lmp.c in tcpdump before 4.9.3 lacks certain bounds checks. suserockylinuxdebian
CVE-2019-25041 medium 5.5 Unbound before 1.9.5 allows an assertion failure via a compressed name in dname_pkt_copy. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unboun… suserockylinuxdebian
CVE-2019-8396 medium 5.5 A buffer overflow in H5O__layout_encode in H5Olayout.c in the HDF HDF5 through 1.10.4 library allows attackers to cause a denial of service via a crafted HDF5 file. This issue was triggered while rep… archsusedebian
CVE-2019-13615 medium 5.5 libebml before 1.3.6, as used in the MKV module in VideoLAN VLC Media Player binaries before 3.0.3, has a heap-based buffer over-read in EbmlElement::FindNextElement. archdebian
CVE-2019-19917 medium 5.5 arbitrary code execution in lout arch
CVE-2019-12210 medium 5.5 In Yubico pam-u2f 1.0.7, when configured with debug and a custom debug log file is set using debug_file, that file descriptor is not closed when a new process is spawned. This leads to the file descr… archsusedebian
CVE-2019-3832 medium 5.5 It was discovered the fix for CVE-2018-19758 (libsndfile) was not complete and still allows a read beyond the limits of a buffer in wav_write_header() function in wav.c. A local attacker may use this… archdebian
CVE-2019-6988 medium 5.5 An issue was discovered in OpenJPEG 2.3.0. It allows remote attackers to cause a denial of service (attempted excessive memory allocation) in opj_calloc in openjp2/opj_malloc.c, when called from opj_… archdebian
CVE-2019-16680 medium 5.5 Moderate: file-roller security update susedebianrockylinux
CVE-2019-25035 medium 5.5 Unbound before 1.9.5 allows an out-of-bounds write in sldns_bget_token_par. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation… suserockylinuxdebian
CVE-2019-25036 medium 5.5 Unbound before 1.9.5 allows an assertion failure and denial of service in synth_cname. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound i… suserockylinuxdebian
CVE-2019-3807 medium 5.5 An issue has been found in PowerDNS Recursor versions 4.1.x before 4.1.9 where records in the answer section of responses received from authoritative servers with the AA flag not set were not properl… archdebian
CVE-2019-3806 medium 5.5 An issue has been found in PowerDNS Recursor versions after 4.1.3 before 4.1.9 where Lua hooks are not properly applied to queries received over TCP in some specific combination of settings, possibly… archdebian
CVE-2019-20790 medium 5.5 OpenDMARC through 1.3.2 and 1.4.x, when used with pypolicyd-spf 2.0.2, allows attacks that bypass SPF and DMARC authentication in situations where the HELO field is inconsistent with the MAIL FROM fi… archdebian
CVE-2019-9199 medium 5.5 PoDoFo::Impose::PdfTranslator::setSource() in pdftranslator.cpp in PoDoFo 0.9.6 has a NULL pointer dereference that can (for example) be triggered by sending a crafted PDF file to the podofoimpose bi… archsusedebian
CVE-2019-7149 medium 5.5 A heap-based buffer over-read was discovered in the function read_srclines in dwarf_getsrclines.c in libdw in elfutils 0.175. A crafted input can cause segmentation faults, leading to denial-of-servi… archdebian
CVE-2019-7663 medium 5.5 An Invalid Address dereference was discovered in TIFFWriteDirectoryTagTransferfunction in libtiff/tif_dirwrite.c in LibTIFF 4.0.10, affecting the cpSeparateBufToContigBuf function in tiffcp.c. Remote… archsusedebian
CVE-2019-5482 medium 5.5 Heap buffer overflow in the TFTP protocol handler in cURL 7.19.4 to 7.65.3. archsusedebian
CVE-2019-10209 medium 5.5 multiple issues in postgresql-libs, postgresql arch
CVE-2019-18281 medium 5.5 An out-of-bounds memory access in the generateDirectionalRuns() function in qtextengine.cpp in Qt qtbase 5.11.x and 5.12.x before 5.12.5 allows attackers to cause a denial of service by crashing an a… rockylinuxdebian
CVE-2019-7148 medium 5.5 An attempted excessive memory allocation was discovered in the function read_long_names in elf_begin.c in libelf in elfutils 0.174. Remote attackers could leverage this vulnerability to cause a denia… archdebian
CVE-2019-6128 medium 5.5 The TIFFFdOpen function in tif_unix.c in LibTIFF 4.0.10 has a memory leak, as demonstrated by pal2rgb. archsusedebian
CVE-2019-25034 medium 5.5 Unbound before 1.9.5 allows an integer overflow in sldns_str2wire_dname_buf_origin, leading to an out-of-bounds write. NOTE: The vendor disputes that this is a vulnerability. Although the code may be… suserockylinuxdebian
CVE-2019-19480 medium 5.5 An issue was discovered in OpenSC through 0.19.0 and 0.20.x through 0.20.0-rc3. libopensc/pkcs15-prkey.c has an incorrect free operation in sc_pkcs15_decode_prkdf_entry. archdebian
CVE-2019-10691 medium 5.5 The JSON encoder in Dovecot before 2.3.5.2 allows attackers to repeatedly crash the authentication service by attempting to authenticate with an invalid UTF-8 sequence as the username. archsusedebian
CVE-2019-14847 medium 5.5 A flaw was found in samba 4.0.0 before samba 4.9.15 and samba 4.10.x before 4.10.10. An attacker can crash AD DC LDAP server via dirsync resulting in denial of service. Privilege escalation is not po… archsusedebian
CVE-2019-9687 medium 5.5 PoDoFo 0.9.6 has a heap-based buffer overflow in PdfString::ConvertUTF16toUTF8 in base/PdfString.cpp. archsusedebian
CVE-2019-8341 medium 5.5 An issue was discovered in Jinja2 2.10. The from_string function is prone to Server Side Template Injection (SSTI) where it takes the "source" parameter as a template object, renders it, and then ret… archsusedebian
CVE-2019-7150 medium 5.5 An issue was discovered in elfutils 0.175. A segmentation fault can occur in the function elf64_xlatetom in libelf/elf32_xlatetom.c, due to dwfl_segment_report_module not checking whether the dyn dat… archsusedebian
CVE-2019-25037 medium 5.5 Unbound before 1.9.5 allows an assertion failure and denial of service in dname_pkt_copy via an invalid packet. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulner… suserockylinuxdebian
CVE-2019-25042 medium 5.5 Unbound before 1.9.5 allows an out-of-bounds write via a compressed name in rdata_copy. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound … suserockylinuxdebian
CVE-2019-14866 medium 5.5 Moderate: cpio security update susedebianrockylinux
CVE-2019-15718 medium 5.5 In systemd 240, bus_open_system_watch_bind_with_description in shared/bus-util.c (as used by systemd-resolved to connect to the system D-Bus instance), calls sd_bus_set_trusted, which disables access… archdebian
CVE-2019-11756 medium 5.5 Moderate: nss and nspr security, bug fix, and enhancement update archdebianrockylinux
CVE-2019-5718 medium 5.5 In Wireshark 2.6.0 to 2.6.5 and 2.4.0 to 2.4.11, the RTSE dissector and other ASN.1 dissectors could crash. This was addressed in epan/charsets.c by adding a get_t61_string length check. archsusedebian
CVE-2019-25040 medium 5.5 Unbound before 1.9.5 allows an infinite loop via a compressed name in dname_pkt_copy. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound in… suserockylinuxdebian
CVE-2019-25032 medium 5.5 Unbound before 1.9.5 allows an integer overflow in the regional allocator via regional_alloc. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Un… suserockylinuxdebian
CVE-2019-12420 medium 5.5 In Apache SpamAssassin before 3.4.3, a message can be crafted in a way to use excessive resources. Upgrading to SA 3.4.3 as soon as possible is the recommended fix but details will not be shared publ… archsusedebian
CVE-2019-16378 medium 5.5 OpenDMARC through 1.3.2 and 1.4.x through 1.4.0-Beta1 is prone to a signature-bypass vulnerability with multiple From: addresses, which might affect applications that consider a domain name to be rel… archdebian
CVE-2019-19918 medium 5.5 arbitrary code execution in lout arch
CVE-2019-14584 medium 5.5 Null pointer dereference in Tianocore EDK2 may allow an authenticated user to potentially enable escalation of privilege via local access. archsusedebian
CVE-2019-7664 medium 5.5 In elfutils 0.175, a negative-sized memcpy is attempted in elf_cvt_note in libelf/note_xlate.h because of an incorrect overflow check. Crafted elf input causes a segmentation fault, leading to denial… archsusedebian
CVE-2019-15945 medium 5.5 OpenSC before 0.20.0-rc1 has an out-of-bounds access of an ASN.1 Bitstring in decode_bit_string in libopensc/asn1.c. archsusedebian
CVE-2019-6475 medium 5.5 Mirror zones are a BIND feature allowing recursive servers to pre-cache zone data provided by other servers. A mirror zone is similar to a zone of type secondary, except that its data is subject to D… debianarchsuse
CVE-2019-5716 medium 5.5 In Wireshark 2.6.0 to 2.6.5, the 6LoWPAN dissector could crash. This was addressed in epan/dissectors/packet-6lowpan.c by avoiding use of a TVB before its creation. archsusedebian
CVE-2019-11499 medium 5.5 In the IMAP Server in Dovecot 2.3.3 through 2.3.5.2, the submission-login component crashes if AUTH PLAIN is attempted over a TLS secured channel with an unacceptable authentication message. archdebian
CVE-2019-12209 medium 5.5 Yubico pam-u2f 1.0.7 attempts parsing of the configured authfile (default $HOME/.config/Yubico/u2f_keys) as root (unless openasuser was enabled), and does not properly verify that the path lacks syml… archsusedebian
CVE-2019-16927 medium 5.5 Xpdf 4.01.01 has an out-of-bounds write in the vertProfile part of the TextPage::findGaps function in TextOutputDev.cc, a different vulnerability than CVE-2019-9877. archsusedebian
CVE-2019-5719 medium 5.5 In Wireshark 2.6.0 to 2.6.5 and 2.4.0 to 2.4.11, the ISAKMP dissector could crash. This was addressed in epan/dissectors/packet-isakmp.c by properly handling the case of a missing decryption data blo… archsusedebian
CVE-2019-10218 medium 5.5 A flaw was found in the samba client, all samba versions before samba 4.11.2, 4.10.10 and 4.9.15, where a malicious server can supply a pathname to the client with separators. This could allow the cl… archsusedebian
CVE-2019-5717 medium 5.5 In Wireshark 2.6.0 to 2.6.5 and 2.4.0 to 2.4.11, the P_MUL dissector could crash. This was addressed in epan/dissectors/packet-p_mul.c by rejecting the invalid sequence number of zero. archsusedebian
CVE-2019-20388 medium 5.5 xmlSchemaPreRun in xmlschemas.c in libxml2 2.9.10 allows an xmlSchemaValidateStream memory leak. archsusedebian
CVE-2019-19721 medium 5.5 An off-by-one error in the DecodeBlock function in codec/sdl_image.c in VideoLAN VLC media player before 3.0.9 allows remote attackers to cause a denial of service (memory corruption) via a crafted i… archdebian
CVE-2019-19481 medium 5.5 An issue was discovered in OpenSC through 0.19.0 and 0.20.x through 0.20.0-rc3. libopensc/card-cac1.c mishandles buffer limits for CAC certificates. archsusedebian
CVE-2019-6290 medium 5.5 An infinite recursion issue was discovered in eval.c in Netwide Assembler (NASM) through 2.14.02. There is a stack exhaustion problem resulting from infinite recursion in the functions expr, rexp, be… archdebian
CVE-2019-25038 medium 5.5 Unbound before 1.9.5 allows an integer overflow in a size calculation in dnscrypt/dnscrypt.c. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Un… suserockylinuxdebian
CVE-2019-5481 medium 5.5 Double-free vulnerability in the FTP-kerberos code in cURL 7.52.0 to 7.65.3. archsusedebian
CVE-2019-25597 medium 5.5 5.5 2mo ago NSauditor 3.1.2.0 contains a buffer overflow vulnerability in the SNMP Auditor Community field that allows local attackers to crash the application by supplying an excessively long string. Attackers …
CVE-2019-17543 medium 5.5 11mo ago Moderate: lz4 security update rockylinuxsusedebian
CVE-2019-19012 medium 5.5 1y ago Moderate: oniguruma security update rockylinuxdebian
CVE-2019-12900 medium 5.5 1y ago Moderate: bzip2 security update redhatdebianrockylinuxsuse
CVE-2019-25162 medium 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: i2c: Fix a potential use after free Free the adap structure only after we are done using it. This patch just moves the put_device… redhatrockylinuxsusedebian
CVE-2019-15505 medium 5.5 2y ago drivers/media/usb/dvb-usb/technisat-usb2.c in the Linux kernel through 5.2.9 has an out-of-bounds read via crafted USB device traffic (which may be remote via usbip or usbredir). rockylinuxsusedebian
CVE-2019-13631 medium 5.5 2y ago In parse_hid_report_descriptor in drivers/input/tablet/gtco.c in the Linux kernel through 5.2.1, a malicious USB device can send an HID report that triggers an out-of-bounds write during generation o… suserockylinuxdebian
CVE-2019-13224 medium 5.5 2y ago Moderate: php:7.3 security, bug fix, and enhancement update susedebianrockylinux
CVE-2019-19203 medium 5.5 2y ago Moderate: php:7.3 security, bug fix, and enhancement update susedebianrockylinux
CVE-2019-16163 medium 5.5 2y ago Moderate: php:7.3 security, bug fix, and enhancement update susedebianrockylinux
CVE-2019-19204 medium 5.5 2y ago Moderate: php:7.3 security, bug fix, and enhancement update susedebianrockylinux
CVE-2019-19499 medium 5.5 2y ago Moderate: grafana security, bug fix, and enhancement update susegolang
CVE-2019-19921 medium 5.5 3y ago Moderate: container-tools:rhel8 security, bug fix, and enhancement update rockylinuxredhatdebiangolang
CVE-2019-14560 medium 5.5 3y ago Moderate: edk2 security, bug fix, and enhancement update archredhatsuse
CVE-2019-25058 medium 5.5 3y ago An issue was discovered in USBGuard before 1.1.0. On systems with the usbguard-dbus daemon running, an unprivileged user could make USBGuard allow all USB devices to be connected in the future. redhatsuserockylinuxdebian
CVE-2019-14809 medium 5.5 4y ago Incorrect parsing validation in net/url archgolang
CVE-2019-6446 medium 5.5 4y ago Moderate: python27:2.7 security and bug fix update suserockylinuxpython
CVE-2019-17596 medium 5.5 4y ago Panic on invalid DSA public keys in crypto/dsa archsusegolang
CVE-2019-10383 medium 5.5 4y ago Improper Neutralization of Input During Web Page Generation in Jenkins archjava
CVE-2019-10384 medium 5.5 4y ago Cross-Site Request Forgery in Jenkins archjava
CVE-2019-6486 medium 5.5 4y ago Denial of service affecting P-521 and P-384 curves in crypto/elliptic archsusegolang
CVE-2019-11236 medium 5.5 4y ago Moderate: python27:2.7 security, bug fix, and enhancement update rockylinuxdebianpython
CVE-2019-1003049 medium 5.5 4y ago Insufficient Session Expiration in Jenkins archjava
CVE-2019-1003050 medium 5.5 4y ago Improper Neutralization of Input During Web Page Generation in Jenkins archjava
CVE-2019-25051 medium 5.5 4y ago Moderate: aspell security update debianarchsuserockylinux
CVE-2019-19005 medium 5.5 5y ago Moderate: autotrace security update
CVE-2019-19004 medium 5.5 5y ago Moderate: autotrace security update
CVE-2019-17595 medium 5.5 5y ago Moderate: ncurses security update suserockylinuxdebian
CVE-2019-17594 medium 5.5 5y ago Moderate: ncurses security update suserockylinuxdebian
CVE-2019-19603 medium 5.5 5y ago Moderate: sqlite security update suserockylinuxdebian
CVE-2019-5827 medium 5.5 5y ago Moderate: sqlite security update debianrockylinux
CVE-2019-13750 medium 5.5 5y ago Moderate: sqlite security update archdebianrockylinux
CVE-2019-13751 medium 5.5 5y ago Moderate: sqlite security update archdebianrockylinux
CVE-2019-18218 medium 5.5 5y ago Moderate: file security update archsusedebianrockylinux
CVE-2019-14615 medium 5.5 5y ago Insufficient control flow in certain data structures for some Intel(R) Processors with Intel(R) Processor Graphics may allow an unauthenticated user to potentially enable information disclosure via l… susedebian
CVE-2019-12973 medium 5.5 5y ago Moderate: openjpeg2 security update archsuserockylinuxdebian
CVE-2019-15845 medium 5.5 5y ago Moderate: ruby:2.5 security, bug fix, and enhancement update archsuserockylinuxdebian
CVE-2019-16255 medium 5.5 5y ago Moderate: ruby:2.6 security, bug fix, and enhancement update archsuserockylinuxdebian
CVE-2019-16201 medium 5.5 5y ago Moderate: ruby:2.6 security, bug fix, and enhancement update archsuserockylinuxdebian
CVE-2019-16254 medium 5.5 5y ago Moderate: ruby:2.6 security, bug fix, and enhancement update archsuserockylinuxdebian
CVE-2019-20916 medium 5.5 5y ago Moderate: python27:2.7 security update suserockylinuxdebianpython
CVE-2019-16168 medium 5.5 5y ago Moderate: mingw packages security and bug fix update rockylinuxsusedebian
CVE-2019-20839 medium 5.5 5y ago Moderate: libvncserver security update suserockylinuxdebian