2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-9811HIGH8.3As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack a...
CVE-2019-9800Mozilla developers and community members reported memory safety bugs present in Firefox 66, Firefox ESR 60.6, and Thunde...
CVE-2019-11730MEDIUM6.5A vulnerability exists where if a user opens a locally saved HTML file, this file can use file: URIs to access other fil...
CVE-2019-11729Empty or malformed p256-ECDH public keys may trigger a segmentation fault due values being improperly sanitized before b...
CVE-2019-11728MEDIUM4.7The HTTP Alternative Services header, Alt-Svc, can be used by a malicious site to scan all TCP ports of any host that th...
CVE-2019-11727A vulnerability exists where it possible to force Network Security Services (NSS) to sign CertificateVerify with PKCS#1 ...
CVE-2019-11725MEDIUM6.5When a user navigates to site marked as unsafe by the Safebrowsing API, warning messages are displayed and navigation is...
CVE-2019-11724MEDIUM6.1Application permissions give additional remote troubleshooting permission to the site input.mozilla.org, which has been ...
CVE-2019-11723HIGH7.5A vulnerability exists during the installation of add-ons where the initial fetch ignored the origin attributes of the b...
CVE-2019-11721MEDIUM6.5The unicode latin 'kra' character can be used to spoof a standard 'k' character in the addressbar. This allows for domai...
CVE-2019-11720MEDIUM6.1Some unicode characters are incorrectly treated as whitespace during the parsing of web content instead of triggering pa...
CVE-2019-11719When importing a curve25519 private key in PKCS#8format with leading 0x00 bytes, it is possible to trigger an out-of-bou...
CVE-2019-11718MEDIUM5.3Activity Stream can display content from sent from the Snippet Service website. This content is written to innerHTML on ...
CVE-2019-11717MEDIUM5.3A vulnerability exists where the caret ("^") character is improperly escaped constructing some URIs due to it being used...
CVE-2019-11716Until explicitly accessed by script, window.globalThis is not enumerable and, as a result, is not visible to code such a...
CVE-2019-11715Due to an error while parsing page content, it is possible for properly sanitized user input to be misinterpreted and le...
CVE-2019-11714Necko can access a child on the wrong thread during UDP connections, resulting in a potentially exploitable crash in som...
CVE-2019-11713A use-after-free vulnerability can occur in HTTP/2 when a cached HTTP/2 stream is closed while still in use, resulting i...
CVE-2019-11712POST requests made by NPAPI plugins, such as Flash, that receive a status 308 redirect response can bypass CORS requirem...
CVE-2019-11711HIGH8.8When an inner window is reused, it does not consider the use of document.domain for cross-origin protections. If pages o...
CVE-2019-11710CRITICAL9.8Mozilla developers and community members reported memory safety bugs present in Firefox 67. Some of these bugs showed ev...
CVE-2019-11709CRITICAL9.8Mozilla developers and community members reported memory safety bugs present in Firefox 67 and Firefox ESR 60.7. Some of...
CVE-2019-11708CRITICAL10Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result...
CVE-2019-11707HIGH8.8A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow...
CVE-2019-11706HIGH7.5A flaw in Thunderbird's implementation of iCal causes a type confusion in icaltimezone_get_vtimezone_properties when pro...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now