2019 CVE Vulnerabilities
17,621 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-10617 | HIGH | 7.8 | 0.2% | Nov 21, 2019 | Low privilege users can access service configuration which contains registry data that admins uses to create or delete e... |
| CVE-2019-10566 | HIGH | 7.8 | 0.2% | Nov 21, 2019 | Buffer overflow can occur in wlan module if supported rates or extended rates element length is greater than max rate se... |
| CVE-2019-10563 | HIGH | 7.8 | 0.2% | Nov 21, 2019 | Buffer over-read can occur in fast message handler due to improper input validation while processing a message from firm... |
| CVE-2019-10535 | MEDIUM | 5.5 | 0.2% | Nov 21, 2019 | Improper validation for loop variable received from firmware can lead to out of bound access in WLAN function while iter... |
| CVE-2019-10503 | HIGH | 7.8 | 0.2% | Nov 21, 2019 | Out-of-bounds access can occur in camera driver due to improper validation of array index in Snapdragon Auto, Snapdragon... |
| CVE-2019-10490 | MEDIUM | 5.5 | 0.2% | Nov 21, 2019 | Use after free issue in Xtra daemon shutdown due to static object instance getting freed from a multiple places in Snapd... |
| CVE-2019-10486 | HIGH | 7 | 0.1% | Nov 21, 2019 | Race condition due to the lack of resource lock which will be concurrently modified in the memcpy statement leads to out... |
| CVE-2019-19037 | MEDIUM | 5.5 | 1.9% | Nov 21, 2019 | ext4_empty_dir in fs/ext4/namei.c in the Linux kernel through 5.3.12 allows a NULL pointer dereference because ext4_read... |
| CVE-2019-19039 | MEDIUM | 5.5 | 0.7% | Nov 21, 2019 | __btrfs_free_extent in fs/btrfs/extent-tree.c in the Linux kernel through 5.3.12 calls btrfs_print_leaf in a certain ENO... |
| CVE-2019-19036 | MEDIUM | 5.5 | 1.8% | Nov 21, 2019 | btrfs_root_node in fs/btrfs/ctree.c in the Linux kernel through 5.3.12 allows a NULL pointer dereference because rcu_der... |
| CVE-2019-6853 | MEDIUM | 6.1 | 0.6% | Nov 20, 2019 | A CWE-79: Failure to Preserve Web Page Structure vulnerability exists in Andover Continuum (models 9680, 5740 and 5720, ... |
| CVE-2019-6852 | HIGH | 7.5 | 1.4% | Nov 20, 2019 | A CWE-200: Information Exposure vulnerability exists in Modicon Controllers (M340 CPUs, M340 communication modules, Prem... |
| CVE-2019-3466 | HIGH | 7.8 | 0.5% | Nov 20, 2019 | The pg_ctlcluster script in postgresql-common in versions prior to 210 didn't drop privileges when creating socket/stati... |
| CVE-2019-18858 | CRITICAL | 9.8 | 2.0% | Nov 20, 2019 | CODESYS 3 web server before 3.5.15.20, as distributed with CODESYS Control runtime systems, has a Buffer Overflow. |
| CVE-2019-4561 | HIGH | 8.8 | 3.5% | Nov 20, 2019 | IBM Security Identity Manager 6.0.0 could allow a remote attacker to execute arbitrary code on the system, caused by the... |
| CVE-2019-4530 | MEDIUM | 6.5 | 0.7% | Nov 20, 2019 | IBM Maximo Asset Management 7.6, 7.6.1, and 7.6.1.1 could allow an authenticated user to delete a record that they shoul... |
| CVE-2019-5542 | HIGH | 7.7 | 0.9% | Nov 20, 2019 | VMware Workstation (15.x before 15.5.1) and Fusion (11.x before 11.5.1) contain a denial-of-service vulnerability in the... |
| CVE-2019-5541 | CRITICAL | 9.1 | 1.4% | Nov 20, 2019 | VMware Workstation (15.x before 15.5.1) and Fusion (11.x before 11.5.1) contain an out-of-bounds write vulnerability in ... |
| CVE-2019-5540 | HIGH | 7.7 | 1.2% | Nov 20, 2019 | VMware Workstation (15.x before 15.5.1) and Fusion (11.x before 11.5.1) contain an information disclosure vulnerability ... |
| CVE-2019-10765 | CRITICAL | 9.8 | 1.7% | Nov 20, 2019 | iobroker.admin before 3.6.12 allows attacker to include file contents from outside the `/log/file1/` directory. |
| CVE-2019-16200 | HIGH | 7.5 | 1.5% | Nov 20, 2019 | GNU Serveez through 0.2.2 has an Information Leak. An attacker may send an HTTP POST request to the /cgi-bin/reader URI.... |
| CVE-2019-15073 | MEDIUM | 6.1 | 1.1% | Nov 20, 2019 | An Open Redirect vulnerability for all browsers in MAIL2000 through version 6.0 and 7.0, which will redirect to a malici... |
| CVE-2019-15072 | MEDIUM | 6.1 | 1.5% | Nov 20, 2019 | The login feature in "/cgi-bin/portal" in MAIL2000 through version 6.0 and 7.0 has a cross-site scripting (XSS) vulnerab... |
| CVE-2019-15071 | MEDIUM | 6.1 | 1.6% | Nov 20, 2019 | The "/cgi-bin/go" page in MAIL2000 through version 6.0 and 7.0 has a cross-site scripting (XSS) vulnerability, allowing ... |
| CVE-2019-6191 | HIGH | 7.8 | 0.3% | Nov 20, 2019 | A potential vulnerability in the discontinued LenovoPaper software version 1.0.0.22 may allow local privilege escalation... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now