2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-17563 | HIGH | 7.5 | 10.7% | Dec 23, 2019 | When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a na... |
| CVE-2019-18391 | MEDIUM | 5.5 | 0.4% | Dec 23, 2019 | A heap-based buffer overflow in the vrend_renderer_transfer_write_iov function in vrend_renderer.c in virglrenderer thro... |
| CVE-2019-18390 | HIGH | 7.1 | 0.3% | Dec 23, 2019 | An out-of-bounds read in the vrend_blit_need_swizzle function in vrend_renderer.c in virglrenderer through 0.8.0 allows ... |
| CVE-2019-18389 | HIGH | 7.8 | 0.4% | Dec 23, 2019 | A heap-based buffer overflow in the vrend_renderer_transfer_write_iov function in vrend_renderer.c in virglrenderer thro... |
| CVE-2019-18388 | MEDIUM | 5.5 | 0.3% | Dec 23, 2019 | A NULL pointer dereference in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of... |
| CVE-2019-19931 | HIGH | 8.8 | 1.3% | Dec 23, 2019 | In libIEC61850 1.4.0, MmsValue_decodeMmsData in mms/iso_mms/server/mms_access_result.c has a heap-based buffer overflow. |
| CVE-2019-19930 | MEDIUM | 6.5 | 1.1% | Dec 23, 2019 | In libIEC61850 1.4.0, MmsValue_newOctetString in mms/iso_mms/common/mms_value.c has an integer signedness error that can... |
| CVE-2019-11050 | MEDIUM | 6.5 | 7.4% | Dec 23, 2019 | When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7... |
| CVE-2019-11049 | CRITICAL | 9.8 | 4.1% | Dec 23, 2019 | In PHP versions 7.3.x below 7.3.13 and 7.4.0 on Windows, when supplying custom headers to mail() function, due to mistak... |
| CVE-2019-11047 | MEDIUM | 6.5 | 7.3% | Dec 23, 2019 | When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7... |
| CVE-2019-11046 | MEDIUM | 5.3 | 4.1% | Dec 23, 2019 | In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP bcmath extension functions on some systems, includ... |
| CVE-2019-11045 | MEDIUM | 5.9 | 8.8% | Dec 23, 2019 | In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP DirectoryIterator class accepts filenames with emb... |
| CVE-2019-11044 | HIGH | 7.5 | 5.1% | Dec 23, 2019 | In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 on Windows, PHP link() function accepts filenames with ... |
| CVE-2019-19929 | HIGH | 7.8 | 0.8% | Dec 23, 2019 | An Untrusted Search Path vulnerability in Malwarebytes AdwCleaner before 8.0.1 could cause arbitrary code execution with... |
| CVE-2019-19926 | HIGH | 7.5 | 7.0% | Dec 23, 2019 | multiSelect in select.c in SQLite 3.30.1 mishandles certain errors during parsing, as demonstrated by errors from sqlite... |
| CVE-2019-19922 | MEDIUM | 5.5 | 0.9% | Dec 22, 2019 | kernel/sched/fair.c in the Linux kernel before 5.3.9, when cpu.cfs_quota_us is used (e.g., with Kubernetes), allows atta... |
| CVE-2019-19920 | HIGH | 8.8 | 3.2% | Dec 22, 2019 | sa-exim 4.2.1 allows attackers to execute arbitrary code if they can write a .cf file or a rule. This occurs because Gre... |
| CVE-2019-19919 | CRITICAL | 9.8 | 7.1% | Dec 20, 2019 | Versions of handlebars prior to 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution. Templates ... |
| CVE-2019-16787 | — | — | — | Dec 20, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-19905. Reason: This candidate is a duplicate of ... |
| CVE-2019-16786 | HIGH | 7.5 | 2.5% | Dec 20, 2019 | Waitress through version 1.3.1 would parse the Transfer-Encoding header and only look for a single string value, if that... |
| CVE-2019-16785 | HIGH | 7.5 | 2.7% | Dec 20, 2019 | Waitress through version 1.3.1 implemented a "MAY" part of the RFC7230 which states: "Although the line terminator for t... |
| CVE-2019-19231 | HIGH | 7.8 | 0.6% | Dec 20, 2019 | An insecure file access vulnerability exists in CA Client Automation 14.0, 14.1, 14.2, and 14.3 Agent for Windows that c... |
| CVE-2019-15584 | MEDIUM | 6.5 | 1.2% | Dec 20, 2019 | A denial of service exists in gitlab <v12.3.2, <v12.2.6, and <v12.1.10 that would let an attacker bypass input validatio... |
| CVE-2019-19918 | HIGH | 7.8 | 1.6% | Dec 20, 2019 | Lout 3.40 has a heap-based buffer overflow in the srcnext() function in z02.c. |
| CVE-2019-19917 | HIGH | 7.8 | 1.5% | Dec 20, 2019 | Lout 3.40 has a buffer overflow in the StringQuotedWord() function in z39.c. |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now