2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-20021MEDIUM5.5A heap-based buffer over-read was discovered in canUnpack in p_mach.cpp in UPX 3.95 via a crafted Mach-O file.
CVE-2019-20020MEDIUM6.5A stack-based buffer over-read was discovered in ReadNextStructField in mat5.c in matio 1.5.17.
CVE-2019-20019MEDIUM6.5An attempted excessive memory allocation was discovered in Mat_VarRead5 in mat5.c in matio 1.5.17.
CVE-2019-20018MEDIUM6.5A stack-based buffer over-read was discovered in ReadNextCell in mat5.c in matio 1.5.17.
CVE-2019-20017MEDIUM6.5A stack-based buffer over-read was discovered in Mat_VarReadNextInfo5 in mat5.c in matio 1.5.17.
CVE-2019-20016MEDIUM6.5libmysofa before 2019-11-24 does not properly restrict recursive function calls, as demonstrated by reports of stack con...
CVE-2019-20015MEDIUM6.5An issue was discovered in GNU LibreDWG 0.92. Crafted input will lead to an attempted excessive memory allocation in dwg...
CVE-2019-20014HIGH8.8An issue was discovered in GNU LibreDWG before 0.93. There is a double-free in dwg_free in free.c.
CVE-2019-20013MEDIUM6.5An issue was discovered in GNU LibreDWG before 0.93. Crafted input will lead to an attempted excessive memory allocation...
CVE-2019-20012MEDIUM6.5An issue was discovered in GNU LibreDWG 0.92. Crafted input will lead to an attempted excessive memory allocation in dwg...
CVE-2019-20011HIGH8.8An issue was discovered in GNU LibreDWG 0.92. There is a heap-based buffer over-read in decode_R13_R2000 in decode.c.
CVE-2019-20010HIGH8.8An issue was discovered in GNU LibreDWG 0.92. There is a use-after-free in resolve_objectref_vector in decode.c.
CVE-2019-20009MEDIUM6.5An issue was discovered in GNU LibreDWG before 0.93. Crafted input will lead to an attempted excessive memory allocation...
CVE-2019-20008MEDIUM5.4In Archery before 1.3, inserting an XSS payload into a project name (either by creating a new project or editing an exis...
CVE-2019-20007MEDIUM6.5An issue was discovered in ezXML 0.8.2 through 0.8.6. The function ezxml_str2utf8, while parsing a crafted XML file, per...
CVE-2019-20006HIGH7.5An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxml_char_content puts a pointer to the internal add...
CVE-2019-20005MEDIUM6.5An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxml_decode, while parsing a crafted XML file, perfo...
CVE-2019-19389MEDIUM5.4JetBrains Ktor framework before version 1.2.6 was vulnerable to HTTP Response Splitting.
CVE-2019-5275HIGH7.5USG9500 with versions of V500R001C30;V500R001C60 have a denial of service vulnerability. Due to a flaw in the X.509 impl...
CVE-2019-5274HIGH7.5USG9500 with versions of V500R001C30;V500R001C60 have a denial of service vulnerability. Due to a flaw in the X.509 impl...
CVE-2019-5273HIGH7.5USG9500 with versions of V500R001C30;V500R001C60 have a denial of service vulnerability. Due to a flaw in the X.509 impl...
CVE-2019-5272MEDIUM4.9USG9500 with versions of V500R001C30;V500R001C60 have a missing integrity checking vulnerability. The software of the af...
CVE-2019-19398CRITICAL9.8M5 lite 10 with versions of 8.0.0.182(C00) have an insufficient input validation vulnerability. Due to the input validat...
CVE-2019-19996HIGH7.5An issue was discovered on Intelbras IWR 3000N 1.8.7 devices. A malformed login request allows remote attackers to cause...
CVE-2019-19995HIGH8.8A CSRF issue was discovered on Intelbras IWR 3000N 1.8.7 devices, leading to complete control of the router, as demonstr...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now