2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2019-3837MEDIUM6.1It was found that the net_dma code in tcp_recvmsg() in the 2.6.32 kernel as shipped in RHEL6 is thread-unsafe. So an unp...
CVE-2019-1003050MEDIUM5.4The f:validateButton form control for the Jenkins UI did not properly escape job URLs in Jenkins 2.171 and earlier and J...
CVE-2019-3612MEDIUM4.4Information Disclosure vulnerability in McAfee DXL Platform and TIE Server in DXL prior to 5.0.1 HF2 and TIE prior to 2....
CVE-2019-0042MEDIUM4.2Juniper Identity Management Service (JIMS) for Windows versions prior to 1.1.4 may send an incorrect message to associat...
CVE-2019-0038MEDIUM6.5Crafted packets destined to the management interface (fxp0) of an SRX340 or SRX345 services gateway may create a denial ...
CVE-2019-0035MEDIUM6.8When "set system ports console insecure" is enabled, root login is disallowed for Junos OS as expected. However, the roo...
CVE-2019-5426MEDIUM4.8In Ubiquiti Networks EdgeSwitch X v1.1.0 and prior, an unauthenticated user can use the "local port forwarding" and "dyn...
CVE-2019-6154MEDIUM5.3A DLL search path vulnerability was reported in Lenovo Bootable Generator, prior to version Mar-2019, that could allow a...
CVE-2019-11065MEDIUM5.9Gradle versions from 1.4 to 5.3.1 use an insecure HTTP URL to download dependencies when the built-in JavaScript or Coff...
CVE-2019-8456MEDIUM5.9Check Point IKEv2 IPsec VPN up to R80.30, in some less common conditions, may allow an attacker with knowledge of the in...
CVE-2019-0876MEDIUM5.5An information disclosure vulnerability exists when affected Open Enclave SDK versions improperly handle objects in memo...
CVE-2019-0858MEDIUM6.1A spoofing vulnerability exists in Microsoft Exchange Server when Outlook Web Access (OWA) fails to properly handle web ...
CVE-2019-0831MEDIUM5.4A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a speciall...
CVE-2019-0830MEDIUM5.4A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a speciall...
CVE-2019-0817MEDIUM5.4A spoofing vulnerability exists in Microsoft Exchange Server when Outlook Web Access (OWA) fails to properly handle web ...
CVE-2019-9133MEDIUM5.5When processing subtitles format media file, KMPlayer version 2018.12.24.14 or lower doesn't check object size correctly...
CVE-2019-5615MEDIUM6.5Users with Site-level permissions can access files containing the username-encrypted passwords of Security Console Globa...
CVE-2019-3893MEDIUM4.9In Foreman it was discovered that the delete compute resource operation, when executed from the Foreman API, leads to th...
CVE-2019-3887MEDIUM5.6A flaw was found in the way KVM hypervisor handled x2APIC Machine Specific Rregister (MSR) access with nested(=1) virtua...
CVE-2019-3880MEDIUM5.4A flaw was found in the way samba implemented an RPC endpoint emulating the Windows registry service API. An unprivilege...
CVE-2019-3870MEDIUM6.1A vulnerability was found in Samba from version (including) 4.9 to versions before 4.9.6 and 4.10.2. During the creation...
CVE-2019-3795MEDIUM5.3Spring Security versions 4.2.x prior to 4.2.12, 5.0.x prior to 5.0.12, and 5.1.x prior to 5.1.5 contain an insecure rand...
CVE-2019-0757MEDIUM6.5A tampering vulnerability exists in the NuGet Package Manager for Linux and Mac that could allow an authenticated attack...
CVE-2019-0703MEDIUM6.5An information disclosure vulnerability exists in the way that the Windows SMB Server handles certain requests, aka 'Win...
CVE-2019-11026MEDIUM6.5FontInfoScanner::scanFonts in FontInfo.cc in Poppler 0.75.0 has infinite recursion, leading to a call to the error funct...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now