2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-15805CommScope ARRIS TR4400 devices with firmware through A1.00.004-180301 are vulnerable to an authentication bypass to the ...
CVE-2019-14535A divide-by-zero error exists in the SeekIndex function of demux/asf/asf.c in VideoLAN VLC media player 3.0.7.1. As a re...
CVE-2019-14498A divide-by-zero error exists in the Control function of demux/caf.c in VideoLAN VLC media player 3.0.7.1. As a result, ...
CVE-2019-14438A heap-based buffer over-read in xiph_PackHeaders() in modules/demux/xiph.h in VideoLAN VLC media player 3.0.7.1 allows ...
CVE-2019-14437The xiph_SplitHeaders function in modules/demux/xiph.h in VideoLAN VLC media player 3.0.7.1 does not check array bounds ...
CVE-2019-15717Irssi 1.2.x before 1.2.2 has a use-after-free if the IRC server sends a double CAP.
CVE-2019-15502The TeamSpeak client before 3.3.2 allows remote servers to trigger a crash via the 0xe2 0x81 0xa8 0xe2 0x81 0xa7 byte se...
CVE-2019-7307HIGH7Apport before versions 2.14.1-0ubuntu3.29+esm1, 2.20.1-0ubuntu2.19, 2.20.9-0ubuntu7.7, 2.20.10-0ubuntu27.1, 2.20.11-0ubu...
CVE-2019-4536MEDIUM6.3IBM i 7.4 users who have done a Restore User Profile (RSTUSRPRF) on a system which has been configured with Db2 Mirror f...
CVE-2019-4133MEDIUM5.2IBM Cloud Automation Manager 3.1.2 could allow a malicious user on the client side (with access to client computer) to r...
CVE-2019-4132LOW3.3IBM Cloud Automation Manager 3.1.2 could allow a user to be impropertly redirected and obtain sensitive information rath...
CVE-2019-3394There was a local file disclosure vulnerability in Confluence Server and Confluence Data Center via page exporting. An a...
CVE-2019-11476MEDIUM6.5An integer overflow in whoopsie before versions 0.2.52.5ubuntu0.1, 0.2.62ubuntu0.1, 0.2.64ubuntu0.1, 0.2.66, results in ...
CVE-2019-11500In Dovecot before 2.2.36.4 and 2.3.x before 2.3.7.2 (and Pigeonhole before 0.5.7.2), protocol processing can fail for qu...
CVE-2019-15788Clara Genomics Analysis before 0.2.0 has an integer overflow for cudapoa memory management in allocate_block.cpp.
CVE-2019-15786ROBOTIS Dynamixel SDK through 3.7.11 has a buffer overflow via a large rxpacket.
CVE-2019-15785FontForge 20190813 through 20190820 has a buffer overflow in PrefsUI_LoadPrefs in prefs.c.
CVE-2019-15784Secure Reliable Transport (SRT) through 1.3.4 has a CSndUList array overflow if there are many SRT connections.
CVE-2019-15781The facebook-by-weblizar plugin before 2.8.5 for WordPress has CSRF.
CVE-2019-15779The insta-gallery plugin before 2.4.8 for WordPress has no nonce validation for qligg_dismiss_notice or qligg_form_item_...
CVE-2019-15778The woo-variation-gallery plugin before 1.1.29 for WordPress has XSS.
CVE-2019-15771The nd-shortcodes plugin before 6.0 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl sett...
CVE-2019-15745The Eques elf smart plug and the mobile app use a hardcoded AES 256 bit key to encrypt the commands and responses betwee...
CVE-2019-15787libZetta.rs through 0.1.2 has an integer overflow in the zpool parser (for error stats) that leads to a panic.
CVE-2019-15783Lute-Tab before 2019-08-23 has a buffer overflow in pdf_print.cc.

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now