2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-7577 | HIGH | 8.8 | 3.0% | Feb 7, 2019 | SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a buffer over-read in SDL_LoadWAV_RW in audio/SD... |
| CVE-2019-7576 | HIGH | 8.8 | 2.9% | Feb 7, 2019 | SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in InitMS_ADPCM in... |
| CVE-2019-7575 | HIGH | 8.8 | 3.0% | Feb 7, 2019 | SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer overflow in MS_ADPCM_decode ... |
| CVE-2019-7574 | HIGH | 8.8 | 2.8% | Feb 7, 2019 | SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in IMA_ADPCM_decod... |
| CVE-2019-7573 | HIGH | 8.8 | 3.0% | Feb 7, 2019 | SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in InitMS_ADPCM in... |
| CVE-2019-7572 | HIGH | 8.8 | 2.8% | Feb 7, 2019 | SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a buffer over-read in IMA_ADPCM_nibble in audio/... |
| CVE-2019-7548 | HIGH | 7.8 | 1.8% | Feb 6, 2019 | SQLAlchemy 1.2.17 has SQL Injection when the group_by parameter can be controlled. |
| CVE-2019-1003011 | HIGH | 8.1 | 2.0% | Feb 6, 2019 | An information exposure and denial of service vulnerability exists in Jenkins Token Macro Plugin 2.5 and earlier in src/... |
| CVE-2019-1003006 | HIGH | 8.8 | 1.6% | Feb 6, 2019 | A sandbox bypass vulnerability exists in Jenkins Groovy Plugin 2.0 and earlier in src/main/java/hudson/plugins/groovy/St... |
| CVE-2019-1003005 | HIGH | 8.8 | 19.0% | Feb 6, 2019 | A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.50 and earlier in src/main/java/org/jenkinsci/... |
| CVE-2019-6535 | HIGH | 7.5 | 4.3% | Feb 5, 2019 | Mitsubishi Electric Q03/04/06/13/26UDVCPU: serial number 20081 and prior, Q04/06/13/26UDPVCPU: serial number 20081 and p... |
| CVE-2019-3818 | HIGH | 7.5 | 0.7% | Feb 5, 2019 | The kube-rbac-proxy container before version 0.4.1 as used in Red Hat OpenShift Container Platform does not honor TLS co... |
| CVE-2019-7398 | HIGH | 7.5 | 3.7% | Feb 5, 2019 | In ImageMagick before 7.0.8-25, a memory leak exists in WriteDIBImage in coders/dib.c. |
| CVE-2019-7397 | HIGH | 7.5 | 3.8% | Feb 5, 2019 | In ImageMagick before 7.0.8-25 and GraphicsMagick through 1.3.31, several memory leaks exist in WritePDFImage in coders/... |
| CVE-2019-7396 | HIGH | 7.5 | 3.4% | Feb 5, 2019 | In ImageMagick before 7.0.8-25, a memory leak exists in ReadSIXELImage in coders/sixel.c. |
| CVE-2019-7395 | HIGH | 7.5 | 3.4% | Feb 5, 2019 | In ImageMagick before 7.0.8-25, a memory leak exists in WritePSDChannel in coders/psd.c. |
| CVE-2019-1000018 | HIGH | 7.8 | 1.9% | Feb 4, 2019 | rssh version 2.3.4 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection'... |
| CVE-2019-3813 | HIGH | 7.5 | 1.2% | Feb 4, 2019 | Spice, versions 0.5.2 through 0.14.1, are vulnerable to an out-of-bounds read due to an off-by-one error in memslot_get_... |
| CVE-2019-7310 | HIGH | 7.8 | 2.2% | Feb 3, 2019 | In Poppler 0.73.0, a heap-based buffer over-read (due to an integer signedness error in the XRef::getEntry function in X... |
| CVE-2019-7283 | HIGH | 7.4 | 2.0% | Jan 31, 2019 | An issue was discovered in rcp in NetKit through 0.17. For an rcp operation, the server chooses which files/directories ... |
| CVE-2019-0190 | HIGH | 7.5 | 59.9% | Jan 30, 2019 | A bug exists in the way mod_ssl handled client renegotiations. A remote attacker could send a carefully crafted request ... |
| CVE-2019-3806 | HIGH | 8.1 | 1.5% | Jan 29, 2019 | An issue has been found in PowerDNS Recursor versions after 4.1.3 before 4.1.9 where Lua hooks are not properly applied ... |
| CVE-2019-3462 | HIGH | 8.1 | 14.6% | Jan 28, 2019 | Incorrect sanitation of the 302 redirect field in HTTP transport method of apt versions 1.4.8 and earlier can lead to co... |
| CVE-2019-3593 | HIGH | 7.5 | 0.3% | Jan 28, 2019 | Exploitation of Privilege/Trust vulnerability in Microsoft Windows client in McAfee Total Protection (MTP) Prior to 16.0... |
| CVE-2019-6956 | HIGH | 7.1 | 1.2% | Jan 25, 2019 | An issue was discovered in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. It is a buffer over-read in ps_mix_phase in ... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now