2019 CVE Vulnerabilities

17,624 CVEs published in 2019.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2019-25059HIGH7.8Artifex Ghostscript through 9.26 mishandles .completefont. NOTE: this issue exists because of an incomplete fix for CVE-...
CVE-2019-6834HIGH7.8A CWE-502: Deserialization of Untrusted Data vulnerability exists which could allow an attacker to execute arbitrary cod...
CVE-2019-14839HIGH7.5It was observed that while login into Business-central console, HTTP request discloses sensitive information like userna...
CVE-2019-25058HIGH7.8An issue was discovered in USBGuard before 1.1.0. On systems with the usbguard-dbus daemon running, an unprivileged user...
CVE-2019-25057HIGH7.5In Corda before 4.1, the meaning of serialized data can be modified via an attacker-controlled CustomSerializer.
CVE-2019-16864HIGH8.8CompleteFTPService.exe in the server in EnterpriseDT CompleteFTP before 12.1.4 allows Remote Code Execution by leveragin...
CVE-2019-25055HIGH7.5An issue was discovered in the libpulse-binding crate before 2.6.0 for Rust. It mishandles a panic that crosses a Foreig...
CVE-2019-25054HIGH7.5An issue was discovered in the pnet crate before 0.27.2 for Rust. There is a segmentation fault (upon attempted derefere...
CVE-2019-19138HIGH7.5Ivanti Workspace Control before 10.4.50.0 allows attackers to degrade integrity.
CVE-2019-8922HIGH8.8A heap-based buffer overflow was discovered in bluetoothd in BlueZ through 5.48. There isn't any check on whether there ...
CVE-2019-18912HIGH7.8A potential security vulnerability has been identified for certain HP printers and MFPs with Troy solutions. For affecte...
CVE-2019-18916HIGH7.8A potential security vulnerability has been identified for HP LaserJet Solution Software (for certain HP LaserJet Printe...
CVE-2019-3556HIGH8.1HHVM supports the use of an "admin" server which accepts administrative requests over HTTP. One of those request handler...
CVE-2019-9060HIGH7.5An issue was discovered in CMS Made Simple 2.2.8. It is possible to achieve unauthenticated path traversal in the CGExte...
CVE-2019-14453HIGH8.8An issue was discovered in Comelit "App lejos de casa (web)" 2.8.0. It allows privilege escalation via modified domus an...
CVE-2019-25051HIGH7.8objstack in GNU Aspell 0.60.8 has a heap-based buffer overflow in acommon::ObjStack::dup_top (called from acommon::Strin...
CVE-2019-25050HIGH7.8netCDF in GDAL 2.4.2 through 3.0.4 has a stack-based buffer overflow in nc4_get_att (called from nc4_get_att_tc and nc_g...
CVE-2019-3752HIGH8.2Dell EMC Avamar Server versions 7.4.1, 7.5.0, 7.5.1, 18.2 and 19.1 and Dell EMC Integrated Data Protection Appliance (ID...
CVE-2019-25049HIGH7.1LibreSSL 2.9.1 through 3.2.1 has an out-of-bounds read in asn1_item_print_ctx (called from asn1_template_print_ctx).
CVE-2019-25048HIGH7.1LibreSSL 2.9.1 through 3.2.1 has a heap-based buffer over-read in do_print_ex (called from asn1_item_print_ctx and ASN1_...
CVE-2019-25045HIGH7.8An issue was discovered in the Linux kernel before 5.0.19. The XFRM subsystem has a use-after-free, related to an xfrm_s...
CVE-2019-14584HIGH7.8Null pointer dereference in Tianocore EDK2 may allow an authenticated user to potentially enable escalation of privilege...
CVE-2019-4730HIGH7.1IBM Cognos Analytics 11.0 and 11.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML da...
CVE-2019-4724HIGH7.5IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain credentials from a user's browser via incorre...
CVE-2019-4723HIGH7.5IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain credentials from a user's browser via incorre...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now