2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-19966 | MEDIUM | 4.6 | 0.6% | Dec 25, 2019 | In the Linux kernel before 5.1.6, there is a use-after-free in cpia2_exit() in drivers/media/usb/cpia2/cpia2_v4l.c that ... |
| CVE-2019-19965 | MEDIUM | 4.7 | 0.7% | Dec 25, 2019 | In the Linux kernel through 5.4.6, there is a NULL pointer dereference in drivers/scsi/libsas/sas_discover.c because of ... |
| CVE-2019-19963 | MEDIUM | 5.3 | 1.0% | Dec 25, 2019 | An issue was discovered in wolfSSL before 4.3.0 in a non-default configuration where DSA is enabled. DSA signing uses th... |
| CVE-2019-19962 | HIGH | 7.5 | 0.9% | Dec 25, 2019 | wolfSSL before 4.3.0 mishandles calls to wc_SignatureGenerateHash, leading to fault injection in RSA cryptography. |
| CVE-2019-19960 | MEDIUM | 5.3 | 1.0% | Dec 25, 2019 | In wolfSSL before 4.3.0, wc_ecc_mulmod_ex does not properly resist side-channel attacks. |
| CVE-2019-5702 | HIGH | 7.8 | 0.4% | Dec 24, 2019 | NVIDIA GeForce Experience, all versions prior to 3.20.2, contains a vulnerability when GameStream is enabled in which an... |
| CVE-2019-19958 | MEDIUM | 6.5 | 0.9% | Dec 24, 2019 | In libIEC61850 1.4.0, StringUtils_createStringFromBuffer in common/string_utilities.c has an integer signedness issue th... |
| CVE-2019-19957 | MEDIUM | 6.5 | 0.9% | Dec 24, 2019 | In libIEC61850 1.4.0, getNumberOfElements in mms/iso_mms/server/mms_access_result.c has an out-of-bounds read vulnerabil... |
| CVE-2019-10758 | CRITICAL | 9.9 | 84.8% | Dec 24, 2019 | mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. A misuse... |
| CVE-2019-19925 | HIGH | 7.5 | 6.8% | Dec 24, 2019 | zipfileUpdate in ext/misc/zipfile.c in SQLite 3.30.1 mishandles a NULL pathname during an update of a ZIP archive. |
| CVE-2019-19956 | HIGH | 7.5 | 5.5% | Dec 24, 2019 | xmlParseBalancedChunkMemoryRecover in parser.c in libxml2 before 2.9.10 has a memory leak related to newDoc->oldNs. |
| CVE-2019-19924 | MEDIUM | 5.3 | 7.9% | Dec 24, 2019 | SQLite 3.30.1 mishandles certain parser-tree rewriting, related to expr.c, vdbeaux.c, and window.c. This is caused by in... |
| CVE-2019-19923 | HIGH | 7.5 | 6.8% | Dec 24, 2019 | flattenSubquery in select.c in SQLite 3.30.1 mishandles certain uses of SELECT DISTINCT involving a LEFT JOIN in which t... |
| CVE-2019-19954 | HIGH | 7.3 | 0.5% | Dec 24, 2019 | Signal Desktop before 1.29.1 on Windows allows local users to gain privileges by creating a Trojan horse %SYSTEMDRIVE%\n... |
| CVE-2019-18249 | MEDIUM | 6.1 | 0.8% | Dec 24, 2019 | Reliable Controls MACH-ProWebCom/Sys, all versions prior to 2.15 (Firmware versions prior to 8.26.4), may allow attacker... |
| CVE-2019-19695 | HIGH | 7.5 | 3.2% | Dec 24, 2019 | A privilege escalation vulnerability in Trend Micro Antivirus for Mac 2019 (v9.0.1379 and below) could potentially allow... |
| CVE-2019-19953 | CRITICAL | 9.1 | 2.8% | Dec 24, 2019 | In GraphicsMagick 1.4 snapshot-20191208 Q8, there is a heap-based buffer over-read in the function EncodeImage of coders... |
| CVE-2019-19952 | CRITICAL | 9.8 | 2.2% | Dec 24, 2019 | In ImageMagick 7.0.9-7 Q16, there is a use-after-free in the function MngInfoDiscardObject of coders/png.c, related to R... |
| CVE-2019-19951 | CRITICAL | 9.8 | 2.5% | Dec 24, 2019 | In GraphicsMagick 1.4 snapshot-20190423 Q8, there is a heap-based buffer overflow in the function ImportRLEPixels of cod... |
| CVE-2019-19950 | CRITICAL | 9.8 | 2.7% | Dec 24, 2019 | In GraphicsMagick 1.4 snapshot-20190403 Q8, there is a use-after-free in ThrowException and ThrowLoggedException of magi... |
| CVE-2019-19949 | CRITICAL | 9.1 | 2.9% | Dec 24, 2019 | In ImageMagick 7.0.8-43 Q16, there is a heap-based buffer over-read in the function WritePNGImage of coders/png.c, relat... |
| CVE-2019-19948 | CRITICAL | 9.8 | 3.7% | Dec 24, 2019 | In ImageMagick 7.0.8-43 Q16, there is a heap-based buffer overflow in the function WriteSGIImage of coders/sgi.c. |
| CVE-2019-19947 | MEDIUM | 4.6 | 0.5% | Dec 24, 2019 | In the Linux kernel through 5.4.6, there are information leaks of uninitialized memory to a USB device in the drivers/ne... |
| CVE-2019-18211 | HIGH | 8.8 | 2.9% | Dec 23, 2019 | An issue was discovered in Orckestra C1 CMS through 6.6. The EntityTokenSerializer class in Composite.dll is prone to un... |
| CVE-2019-12568 | CRITICAL | 9.8 | 2.3% | Dec 23, 2019 | Stack-based overflow vulnerability in the logMess function in Open TFTP Server SP 1.66 and earlier allows remote attacke... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now