2019 CVE Vulnerabilities

17,621 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-10617HIGH7.8Low privilege users can access service configuration which contains registry data that admins uses to create or delete e...
CVE-2019-10566HIGH7.8Buffer overflow can occur in wlan module if supported rates or extended rates element length is greater than max rate se...
CVE-2019-10563HIGH7.8Buffer over-read can occur in fast message handler due to improper input validation while processing a message from firm...
CVE-2019-10535MEDIUM5.5Improper validation for loop variable received from firmware can lead to out of bound access in WLAN function while iter...
CVE-2019-10503HIGH7.8Out-of-bounds access can occur in camera driver due to improper validation of array index in Snapdragon Auto, Snapdragon...
CVE-2019-10490MEDIUM5.5Use after free issue in Xtra daemon shutdown due to static object instance getting freed from a multiple places in Snapd...
CVE-2019-10486HIGH7Race condition due to the lack of resource lock which will be concurrently modified in the memcpy statement leads to out...
CVE-2019-19037MEDIUM5.5ext4_empty_dir in fs/ext4/namei.c in the Linux kernel through 5.3.12 allows a NULL pointer dereference because ext4_read...
CVE-2019-19039MEDIUM5.5__btrfs_free_extent in fs/btrfs/extent-tree.c in the Linux kernel through 5.3.12 calls btrfs_print_leaf in a certain ENO...
CVE-2019-19036MEDIUM5.5btrfs_root_node in fs/btrfs/ctree.c in the Linux kernel through 5.3.12 allows a NULL pointer dereference because rcu_der...
CVE-2019-6853MEDIUM6.1A CWE-79: Failure to Preserve Web Page Structure vulnerability exists in Andover Continuum (models 9680, 5740 and 5720, ...
CVE-2019-6852HIGH7.5A CWE-200: Information Exposure vulnerability exists in Modicon Controllers (M340 CPUs, M340 communication modules, Prem...
CVE-2019-3466HIGH7.8The pg_ctlcluster script in postgresql-common in versions prior to 210 didn't drop privileges when creating socket/stati...
CVE-2019-18858CRITICAL9.8CODESYS 3 web server before 3.5.15.20, as distributed with CODESYS Control runtime systems, has a Buffer Overflow.
CVE-2019-4561HIGH8.8IBM Security Identity Manager 6.0.0 could allow a remote attacker to execute arbitrary code on the system, caused by the...
CVE-2019-4530MEDIUM6.5IBM Maximo Asset Management 7.6, 7.6.1, and 7.6.1.1 could allow an authenticated user to delete a record that they shoul...
CVE-2019-5542HIGH7.7VMware Workstation (15.x before 15.5.1) and Fusion (11.x before 11.5.1) contain a denial-of-service vulnerability in the...
CVE-2019-5541CRITICAL9.1VMware Workstation (15.x before 15.5.1) and Fusion (11.x before 11.5.1) contain an out-of-bounds write vulnerability in ...
CVE-2019-5540HIGH7.7VMware Workstation (15.x before 15.5.1) and Fusion (11.x before 11.5.1) contain an information disclosure vulnerability ...
CVE-2019-10765CRITICAL9.8iobroker.admin before 3.6.12 allows attacker to include file contents from outside the `/log/file1/` directory.
CVE-2019-16200HIGH7.5GNU Serveez through 0.2.2 has an Information Leak. An attacker may send an HTTP POST request to the /cgi-bin/reader URI....
CVE-2019-15073MEDIUM6.1An Open Redirect vulnerability for all browsers in MAIL2000 through version 6.0 and 7.0, which will redirect to a malici...
CVE-2019-15072MEDIUM6.1The login feature in "/cgi-bin/portal" in MAIL2000 through version 6.0 and 7.0 has a cross-site scripting (XSS) vulnerab...
CVE-2019-15071MEDIUM6.1The "/cgi-bin/go" page in MAIL2000 through version 6.0 and 7.0 has a cross-site scripting (XSS) vulnerability, allowing ...
CVE-2019-6191HIGH7.8A potential vulnerability in the discontinued LenovoPaper software version 1.0.0.22 may allow local privilege escalation...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now