2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-9812CRITICAL9.3Given a compromised sandboxed content process due to a separate vulnerability, it is possible to escape that sandbox by ...
CVE-2019-17025HIGH8.8Mozilla developers reported memory safety bugs present in Firefox 71. Some of these bugs showed evidence of memory corru...
CVE-2019-17024HIGH8.8Mozilla developers reported memory safety bugs present in Firefox 71 and Firefox ESR 68.3. Some of these bugs showed evi...
CVE-2019-17023MEDIUM6.5After a HelloRetryRequest has been sent, the client may negotiate a lower protocol that TLS 1.3, resulting in an invalid...
CVE-2019-17022MEDIUM6.1When pasting a <style> tag from the clipboard into a rich text editor, the CSS sanitizer does not escape < and ...
CVE-2019-17021MEDIUM5.3During the initialization of a new content process, a race condition occurs that can allow a content process to disclose...
CVE-2019-17020MEDIUM6.5If an XML file is served with a Content Security Policy and the XML file includes an XSL stylesheet, the Content Securit...
CVE-2019-17019HIGH8.8When Python was installed on Windows, a python file being served with the MIME type of text/plain could be executed by P...
CVE-2019-17018MEDIUM5.3When in Private Browsing Mode on Windows 10, the Windows keyboard may retain word suggestions to improve the accuracy of...
CVE-2019-17017HIGH8.8Due to a missing case handling object types, a type confusion vulnerability could occur, resulting in a crash. We presum...
CVE-2019-17016MEDIUM6.1When pasting a <style> tag from the clipboard into a rich text editor, the CSS sanitizer incorrectly rewrites a @n...
CVE-2019-17015HIGH8.8During the initialization of a new content process, a pointer offset can be manipulated leading to memory corruption and...
CVE-2019-17014HIGH7.4If an image had not loaded correctly (such as when it is not actually an image), it could be dragged and dropped cross-d...
CVE-2019-17013HIGH8.8Mozilla developers reported memory safety bugs present in Firefox 70. Some of these bugs showed evidence of memory corru...
CVE-2019-17012HIGH8.8Mozilla developers reported memory safety bugs present in Firefox 70 and Firefox ESR 68.2. Some of these bugs showed evi...
CVE-2019-17011HIGH7.5Under certain conditions, when retrieving a document from a DocShell in the antitracking code, a race condition could ca...
CVE-2019-17010HIGH7.5Under certain conditions, when checking the Resist Fingerprinting preference during device orientation checks, a race co...
CVE-2019-17009HIGH7.8When running, the updater service wrote status and log files to an unrestricted location; potentially allowing an unpriv...
CVE-2019-17008HIGH8.8When using nested workers, a use-after-free could occur during worker destruction. This resulted in a potentially exploi...
CVE-2019-17005HIGH8.8The plain text serializer used a fixed-size array for the number of <ol> elements it could process; however it was possi...
CVE-2019-17002MEDIUM4.3If upgrade-insecure-requests was specified in the Content Security Policy, and a link was dragged and dropped from that ...
CVE-2019-17001MEDIUM6.1A Content-Security-Policy that blocks in-line scripts could be bypassed using an object tag to execute JavaScript in the...
CVE-2019-17000MEDIUM6.1An object tag with a data URI did not correctly inherit the document's Content Security Policy. This allowed a CSP bypas...
CVE-2019-11765MEDIUM6.5A compromised content process could send a message to the parent process that would cause the 'Click to Play' permission...
CVE-2019-11764HIGH8.8Mozilla developers and community members reported memory safety bugs present in Firefox 69 and Firefox ESR 68.1. Some of...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now