2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2019-13147MEDIUM6.5In Audio File Library (aka audiofile) 0.3.6, there exists one NULL pointer dereference bug in ulaw2linear_buf in G711.cp...
CVE-2019-7272MEDIUM5.3Optergy Proton/Enterprise devices allow Username Disclosure.
CVE-2019-7275MEDIUM6.1Optergy Proton/Enterprise devices allow Open Redirect.
CVE-2019-13137MEDIUM6.5ImageMagick before 7.0.8-50 has a memory leak vulnerability in the function ReadPSImage in coders/ps.c.
CVE-2019-13134MEDIUM5.5ImageMagick before 7.0.8-50 has a memory leak vulnerability in the function ReadVIFFImage in coders/viff.c.
CVE-2019-13133MEDIUM5.5ImageMagick before 7.0.8-50 has a memory leak vulnerability in the function ReadBMPImage in coders/bmp.c.
CVE-2019-4410MEDIUM5.4IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, 18.0.0.2, and 19.0.0.1 is vulnerable to cross-site scripting. This ...
CVE-2019-4386MEDIUM6.5IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1 could allow an authenticated user to execute a fu...
CVE-2019-4383MEDIUM6.7When using IBM Spectrum Protect Plus 10.1.0, 10.1.2, and 10.1.3 to protect Oracle or MongoDB databases, a redirected res...
CVE-2019-4357MEDIUM6.7When using IBM Spectrum Protect Plus 10.1.0, 10.1.2, and 10.1.3 to protect Oracle, DB2 or MongoDB databases, a redirecte...
CVE-2019-4337MEDIUM5.3IBM Robotic Process Automation with Automation Anywhere 11 could allow an attacker to obtain sensitive information due t...
CVE-2019-4299MEDIUM5.5IBM Robotic Process Automation with Automation Anywhere 11 could allow a local user to obtain highly sensitive informati...
CVE-2019-4297MEDIUM5.4IBM Robotic Process Automation with Automation Anywhere 11 could allow a remote authenticated attacker to conduct an LDA...
CVE-2019-4295MEDIUM4.9IBM Robotic Process Automation with Automation Anywhere 11 could allow an attacker with specialized access to obtain hig...
CVE-2019-4237MEDIUM5.4A Cross-Frame Scripting vulnerability in IBM InfoSphere Information Server 11.3, 11.5, and 11.7 can allow an attacker to...
CVE-2019-4102MEDIUM5.9IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.0 uses weaker than expected cr...
CVE-2019-4101MEDIUM5.5IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.1, 10.5, and 11.1 is vulnerable to a denial of serv...
CVE-2019-4057MEDIUM6.7IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow malicious user w...
CVE-2019-13118MEDIUM5.3In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was too narrow and an in...
CVE-2019-13117MEDIUM5.3In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could lead to a uninitialized read in xsltNumb...
CVE-2019-13114MEDIUM6.5http.c in Exiv2 through 0.27.1 allows a malicious http server to cause a denial of service (crash due to a NULL pointer ...
CVE-2019-13113MEDIUM6.5Exiv2 through 0.27.1 allows an attacker to cause a denial of service (crash due to assertion failure) via an invalid dat...
CVE-2019-13112MEDIUM6.5A PngChunk::parseChunkContent uncontrolled memory allocation in Exiv2 through 0.27.1 allows an attacker to cause a denia...
CVE-2019-13111MEDIUM5.5A WebPImage::decodeChunks integer overflow in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (larg...
CVE-2019-13110MEDIUM6.5A CiffDirectory::readDirectory integer overflow and out-of-bounds read in Exiv2 through 0.27.1 allows an attacker to cau...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now