2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-9812 | CRITICAL | 9.3 | 1.3% | Jan 8, 2020 | Given a compromised sandboxed content process due to a separate vulnerability, it is possible to escape that sandbox by ... |
| CVE-2019-17025 | HIGH | 8.8 | 1.3% | Jan 8, 2020 | Mozilla developers reported memory safety bugs present in Firefox 71. Some of these bugs showed evidence of memory corru... |
| CVE-2019-17024 | HIGH | 8.8 | 2.5% | Jan 8, 2020 | Mozilla developers reported memory safety bugs present in Firefox 71 and Firefox ESR 68.3. Some of these bugs showed evi... |
| CVE-2019-17023 | MEDIUM | 6.5 | 1.3% | Jan 8, 2020 | After a HelloRetryRequest has been sent, the client may negotiate a lower protocol that TLS 1.3, resulting in an invalid... |
| CVE-2019-17022 | MEDIUM | 6.1 | 2.0% | Jan 8, 2020 | When pasting a <style> tag from the clipboard into a rich text editor, the CSS sanitizer does not escape < and ... |
| CVE-2019-17021 | MEDIUM | 5.3 | 1.9% | Jan 8, 2020 | During the initialization of a new content process, a race condition occurs that can allow a content process to disclose... |
| CVE-2019-17020 | MEDIUM | 6.5 | 1.1% | Jan 8, 2020 | If an XML file is served with a Content Security Policy and the XML file includes an XSL stylesheet, the Content Securit... |
| CVE-2019-17019 | HIGH | 8.8 | 1.0% | Jan 8, 2020 | When Python was installed on Windows, a python file being served with the MIME type of text/plain could be executed by P... |
| CVE-2019-17018 | MEDIUM | 5.3 | 0.9% | Jan 8, 2020 | When in Private Browsing Mode on Windows 10, the Windows keyboard may retain word suggestions to improve the accuracy of... |
| CVE-2019-17017 | HIGH | 8.8 | 2.5% | Jan 8, 2020 | Due to a missing case handling object types, a type confusion vulnerability could occur, resulting in a crash. We presum... |
| CVE-2019-17016 | MEDIUM | 6.1 | 2.0% | Jan 8, 2020 | When pasting a <style> tag from the clipboard into a rich text editor, the CSS sanitizer incorrectly rewrites a @n... |
| CVE-2019-17015 | HIGH | 8.8 | 1.8% | Jan 8, 2020 | During the initialization of a new content process, a pointer offset can be manipulated leading to memory corruption and... |
| CVE-2019-17014 | HIGH | 7.4 | 1.1% | Jan 8, 2020 | If an image had not loaded correctly (such as when it is not actually an image), it could be dragged and dropped cross-d... |
| CVE-2019-17013 | HIGH | 8.8 | 0.8% | Jan 8, 2020 | Mozilla developers reported memory safety bugs present in Firefox 70. Some of these bugs showed evidence of memory corru... |
| CVE-2019-17012 | HIGH | 8.8 | 2.0% | Jan 8, 2020 | Mozilla developers reported memory safety bugs present in Firefox 70 and Firefox ESR 68.2. Some of these bugs showed evi... |
| CVE-2019-17011 | HIGH | 7.5 | 1.5% | Jan 8, 2020 | Under certain conditions, when retrieving a document from a DocShell in the antitracking code, a race condition could ca... |
| CVE-2019-17010 | HIGH | 7.5 | 1.6% | Jan 8, 2020 | Under certain conditions, when checking the Resist Fingerprinting preference during device orientation checks, a race co... |
| CVE-2019-17009 | HIGH | 7.8 | 0.3% | Jan 8, 2020 | When running, the updater service wrote status and log files to an unrestricted location; potentially allowing an unpriv... |
| CVE-2019-17008 | HIGH | 8.8 | 1.9% | Jan 8, 2020 | When using nested workers, a use-after-free could occur during worker destruction. This resulted in a potentially exploi... |
| CVE-2019-17005 | HIGH | 8.8 | 1.9% | Jan 8, 2020 | The plain text serializer used a fixed-size array for the number of <ol> elements it could process; however it was possi... |
| CVE-2019-17002 | MEDIUM | 4.3 | 0.7% | Jan 8, 2020 | If upgrade-insecure-requests was specified in the Content Security Policy, and a link was dragged and dropped from that ... |
| CVE-2019-17001 | MEDIUM | 6.1 | 0.8% | Jan 8, 2020 | A Content-Security-Policy that blocks in-line scripts could be bypassed using an object tag to execute JavaScript in the... |
| CVE-2019-17000 | MEDIUM | 6.1 | 0.8% | Jan 8, 2020 | An object tag with a data URI did not correctly inherit the document's Content Security Policy. This allowed a CSP bypas... |
| CVE-2019-11765 | MEDIUM | 6.5 | 0.8% | Jan 8, 2020 | A compromised content process could send a message to the parent process that would cause the 'Click to Play' permission... |
| CVE-2019-11764 | HIGH | 8.8 | 1.5% | Jan 8, 2020 | Mozilla developers and community members reported memory safety bugs present in Firefox 69 and Firefox ESR 68.1. Some of... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now