2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-9811 | HIGH | 8.3 | 2.6% | Jul 23, 2019 | As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack a... |
| CVE-2019-9800 | — | — | 1.8% | Jul 23, 2019 | Mozilla developers and community members reported memory safety bugs present in Firefox 66, Firefox ESR 60.6, and Thunde... |
| CVE-2019-11730 | MEDIUM | 6.5 | 20.3% | Jul 23, 2019 | A vulnerability exists where if a user opens a locally saved HTML file, this file can use file: URIs to access other fil... |
| CVE-2019-11729 | — | — | 2.8% | Jul 23, 2019 | Empty or malformed p256-ECDH public keys may trigger a segmentation fault due values being improperly sanitized before b... |
| CVE-2019-11728 | MEDIUM | 4.7 | 1.1% | Jul 23, 2019 | The HTTP Alternative Services header, Alt-Svc, can be used by a malicious site to scan all TCP ports of any host that th... |
| CVE-2019-11727 | — | — | 1.7% | Jul 23, 2019 | A vulnerability exists where it possible to force Network Security Services (NSS) to sign CertificateVerify with PKCS#1 ... |
| CVE-2019-11725 | MEDIUM | 6.5 | 1.1% | Jul 23, 2019 | When a user navigates to site marked as unsafe by the Safebrowsing API, warning messages are displayed and navigation is... |
| CVE-2019-11724 | MEDIUM | 6.1 | 1.1% | Jul 23, 2019 | Application permissions give additional remote troubleshooting permission to the site input.mozilla.org, which has been ... |
| CVE-2019-11723 | HIGH | 7.5 | 0.8% | Jul 23, 2019 | A vulnerability exists during the installation of add-ons where the initial fetch ignored the origin attributes of the b... |
| CVE-2019-11721 | MEDIUM | 6.5 | 1.4% | Jul 23, 2019 | The unicode latin 'kra' character can be used to spoof a standard 'k' character in the addressbar. This allows for domai... |
| CVE-2019-11720 | MEDIUM | 6.1 | 1.1% | Jul 23, 2019 | Some unicode characters are incorrectly treated as whitespace during the parsing of web content instead of triggering pa... |
| CVE-2019-11719 | — | — | 2.2% | Jul 23, 2019 | When importing a curve25519 private key in PKCS#8format with leading 0x00 bytes, it is possible to trigger an out-of-bou... |
| CVE-2019-11718 | MEDIUM | 5.3 | 1.2% | Jul 23, 2019 | Activity Stream can display content from sent from the Snippet Service website. This content is written to innerHTML on ... |
| CVE-2019-11717 | MEDIUM | 5.3 | 2.1% | Jul 23, 2019 | A vulnerability exists where the caret ("^") character is improperly escaped constructing some URIs due to it being used... |
| CVE-2019-11716 | — | — | 1.4% | Jul 23, 2019 | Until explicitly accessed by script, window.globalThis is not enumerable and, as a result, is not visible to code such a... |
| CVE-2019-11715 | — | — | 1.5% | Jul 23, 2019 | Due to an error while parsing page content, it is possible for properly sanitized user input to be misinterpreted and le... |
| CVE-2019-11714 | — | — | 1.7% | Jul 23, 2019 | Necko can access a child on the wrong thread during UDP connections, resulting in a potentially exploitable crash in som... |
| CVE-2019-11713 | — | — | 2.1% | Jul 23, 2019 | A use-after-free vulnerability can occur in HTTP/2 when a cached HTTP/2 stream is closed while still in use, resulting i... |
| CVE-2019-11712 | — | — | 1.0% | Jul 23, 2019 | POST requests made by NPAPI plugins, such as Flash, that receive a status 308 redirect response can bypass CORS requirem... |
| CVE-2019-11711 | HIGH | 8.8 | 1.6% | Jul 23, 2019 | When an inner window is reused, it does not consider the use of document.domain for cross-origin protections. If pages o... |
| CVE-2019-11710 | CRITICAL | 9.8 | 1.7% | Jul 23, 2019 | Mozilla developers and community members reported memory safety bugs present in Firefox 67. Some of these bugs showed ev... |
| CVE-2019-11709 | CRITICAL | 9.8 | 2.3% | Jul 23, 2019 | Mozilla developers and community members reported memory safety bugs present in Firefox 67 and Firefox ESR 60.7. Some of... |
| CVE-2019-11708 | CRITICAL | 10 | 55.9% | Jul 23, 2019 | Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result... |
| CVE-2019-11707 | HIGH | 8.8 | 38.0% | Jul 23, 2019 | A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow... |
| CVE-2019-11706 | HIGH | 7.5 | 9.7% | Jul 23, 2019 | A flaw in Thunderbird's implementation of iCal causes a type confusion in icaltimezone_get_vtimezone_properties when pro... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now