2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-17533HIGH8.2Mat_VarReadNextInfo4 in mat4.c in MATIO 1.5.17 omits a certain '\0' character, leading to a heap-based buffer over-read ...
CVE-2019-17532HIGH7.5An issue was discovered on Belkin Wemo Switch 28B WW_2.00.11057.PVT-OWRT-SNS devices. They allow remote attackers to cau...
CVE-2019-17531CRITICAL9.8A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is ena...
CVE-2019-17530HIGH7.8An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer over-read in AP4_PrintInspector::AddField in Cor...
CVE-2019-17529HIGH7.8An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer over-read in AP4_CencSampleEncryption::DoInspect...
CVE-2019-17528HIGH7.5An issue was discovered in Bento4 1.5.1.0. There is a SEGV in the function AP4_TfhdAtom::SetDefaultSampleSize at Core/Ap...
CVE-2019-17502HIGH7.5Hydra through 0.1.8 has a NULL pointer dereference and daemon crash when processing POST requests that lack a Content-Le...
CVE-2019-17522MEDIUM4.8A stored XSS vulnerability was discovered in Hotaru CMS v1.7.2 via the admin_index.php?page=settings SITE NAME field (ak...
CVE-2019-17521MEDIUM6.5An issue was discovered in Landing-CMS 0.0.6. There is a CSRF vulnerability that can change the admin's password via the...
CVE-2019-17514HIGH7.5library/glob.html in the Python 2 and 3 documentation before 2016 has potentially misleading information about whether s...
CVE-2019-17176MEDIUM6.1Genesys PureEngage Digital (eServices) 8.1.x allows XSS via HtmlChatPanel.jsp or HtmlChatFrameSet.jsp (ActionColor, Clie...
CVE-2019-17510CRITICAL9.8D-Link DIR-846 devices with firmware 100A35 allow remote attackers to execute arbitrary OS commands as root by leveragin...
CVE-2019-17509CRITICAL9.8D-Link DIR-846 devices with firmware 100A35 allow remote attackers to execute arbitrary OS commands as root by leveragin...
CVE-2019-17508CRITICAL9.8On D-Link DIR-859 A3-1.06 and DIR-850 A1.13 devices, /etc/services/DEVICE.TIME.php allows command injection via the $SER...
CVE-2019-17507HIGH7.5An issue was discovered on D-Link DIR-816 A1 1.06 devices. An attacker could access management pages of the router via a...
CVE-2019-17506CRITICAL9.8There are some web interfaces without authentication requirements on D-Link DIR-868L B1-2.03 and DIR-817LW A1-1.04 route...
CVE-2019-17505HIGH7.5D-Link DAP-1320 A2-V1.21 routers have some web interfaces without authentication requirements, as demonstrated by uplink...
CVE-2019-2215HIGH7.8A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti...
CVE-2019-2187MEDIUM5.5In nfc_ncif_decode_rf_params of nfc_ncif.cc, there is a possible out of bounds read due to an integer underflow. This co...
CVE-2019-2186HIGH8.8In GetMBheader of combined_decode.cpp, there is a possible out of bounds write due to a missing bounds check. This could...
CVE-2019-2185HIGH8.8In VlcDequantH263IntraBlock_SH of vlc_dequant.cpp, there is a possible out of bounds write due to a missing bounds check...
CVE-2019-2184HIGH8.8In PV_DecodePredictedIntraDC of dec_pred_intra_dc.cpp, there is a possible out of bounds write due to a missing bounds c...
CVE-2019-2183MEDIUM5.5In generateServicesMap of RegisteredServicesCache.java, there is a possible account protection bypass due to a caching o...
CVE-2019-2173HIGH7.8In startActivityMayWait of ActivityStarter.java, there is a possible incorrect Activity launch due to an incorrect permi...
CVE-2019-2114HIGH7.8In the default privileges of NFC, there is a possible local bypass of user interaction requirements on package installat...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now