2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-17563HIGH7.5When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a na...
CVE-2019-18391MEDIUM5.5A heap-based buffer overflow in the vrend_renderer_transfer_write_iov function in vrend_renderer.c in virglrenderer thro...
CVE-2019-18390HIGH7.1An out-of-bounds read in the vrend_blit_need_swizzle function in vrend_renderer.c in virglrenderer through 0.8.0 allows ...
CVE-2019-18389HIGH7.8A heap-based buffer overflow in the vrend_renderer_transfer_write_iov function in vrend_renderer.c in virglrenderer thro...
CVE-2019-18388MEDIUM5.5A NULL pointer dereference in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of...
CVE-2019-19931HIGH8.8In libIEC61850 1.4.0, MmsValue_decodeMmsData in mms/iso_mms/server/mms_access_result.c has a heap-based buffer overflow.
CVE-2019-19930MEDIUM6.5In libIEC61850 1.4.0, MmsValue_newOctetString in mms/iso_mms/common/mms_value.c has an integer signedness error that can...
CVE-2019-11050MEDIUM6.5When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7...
CVE-2019-11049CRITICAL9.8In PHP versions 7.3.x below 7.3.13 and 7.4.0 on Windows, when supplying custom headers to mail() function, due to mistak...
CVE-2019-11047MEDIUM6.5When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7...
CVE-2019-11046MEDIUM5.3In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP bcmath extension functions on some systems, includ...
CVE-2019-11045MEDIUM5.9In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP DirectoryIterator class accepts filenames with emb...
CVE-2019-11044HIGH7.5In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 on Windows, PHP link() function accepts filenames with ...
CVE-2019-19929HIGH7.8An Untrusted Search Path vulnerability in Malwarebytes AdwCleaner before 8.0.1 could cause arbitrary code execution with...
CVE-2019-19926HIGH7.5multiSelect in select.c in SQLite 3.30.1 mishandles certain errors during parsing, as demonstrated by errors from sqlite...
CVE-2019-19922MEDIUM5.5kernel/sched/fair.c in the Linux kernel before 5.3.9, when cpu.cfs_quota_us is used (e.g., with Kubernetes), allows atta...
CVE-2019-19920HIGH8.8sa-exim 4.2.1 allows attackers to execute arbitrary code if they can write a .cf file or a rule. This occurs because Gre...
CVE-2019-19919CRITICAL9.8Versions of handlebars prior to 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution. Templates ...
CVE-2019-16787Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-19905. Reason: This candidate is a duplicate of ...
CVE-2019-16786HIGH7.5Waitress through version 1.3.1 would parse the Transfer-Encoding header and only look for a single string value, if that...
CVE-2019-16785HIGH7.5Waitress through version 1.3.1 implemented a "MAY" part of the RFC7230 which states: "Although the line terminator for t...
CVE-2019-19231HIGH7.8An insecure file access vulnerability exists in CA Client Automation 14.0, 14.1, 14.2, and 14.3 Agent for Windows that c...
CVE-2019-15584MEDIUM6.5A denial of service exists in gitlab <v12.3.2, <v12.2.6, and <v12.1.10 that would let an attacker bypass input validatio...
CVE-2019-19918HIGH7.8Lout 3.40 has a heap-based buffer overflow in the srcnext() function in z02.c.
CVE-2019-19917HIGH7.8Lout 3.40 has a buffer overflow in the StringQuotedWord() function in z39.c.

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now