2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-13960 | — | — | 1.0% | Jul 18, 2019 | In libjpeg-turbo 2.0.2, a large amount of memory can be used during processing of an invalid progressive JPEG image cont... |
| CVE-2019-13959 | — | — | 1.2% | Jul 18, 2019 | In Bento4 1.5.1-627, AP4_DataBuffer::SetDataSize does not handle reallocation failures, leading to a memory copy into a ... |
| CVE-2019-1010279 | — | — | 1.5% | Jul 18, 2019 | Open Information Security Foundation Suricata prior to version 4.1.3 is affected by: Denial of Service - TCP/HTTP detect... |
| CVE-2019-1010246 | — | — | 1.4% | Jul 18, 2019 | MailCleaner before c888fbb6aaa7c5f8400f637bcf1cbb844de46cd9 is affected by: Unauthenticated MySQL database password info... |
| CVE-2019-1010112 | — | — | 0.7% | Jul 18, 2019 | OECMS v4.3.R60321 and v4.3 later is affected by: Cross Site Request Forgery (CSRF). The impact is: The victim clicks on ... |
| CVE-2019-3592 | HIGH | 7.2 | 0.3% | Jul 18, 2019 | Privilege escalation vulnerability in McAfee Agent (MA) before 5.6.1 HF3, allows local administrator users to potentiall... |
| CVE-2019-13956 | — | — | 4.6% | Jul 18, 2019 | Discuz!ML 3.2 through 3.4 allows remote attackers to execute arbitrary PHP code via a modified language cookie, as demon... |
| CVE-2019-1010252 | — | — | 1.1% | Jul 18, 2019 | The Linux Foundation ONOS 2.0.0 and earlier is affected by: Poor Input-validation. The impact is: A network administrato... |
| CVE-2019-1010251 | — | — | 2.1% | Jul 18, 2019 | Open Information Security Foundation Suricata prior to version 4.1.2 is affected by: Denial of Service - DNS detection b... |
| CVE-2019-1010250 | — | — | 1.1% | Jul 18, 2019 | The Linux Foundation ONOS 2.0.0 and earlier is affected by: Poor Input-validation. The impact is: A network administrato... |
| CVE-2019-1010249 | — | — | 1.1% | Jul 18, 2019 | The Linux Foundation ONOS 2.0.0 and earlier is affected by: Integer Overflow. The impact is: A network administrator (or... |
| CVE-2019-1010248 | — | — | 1.4% | Jul 18, 2019 | Synetics GmbH I-doit 1.12 and earlier is affected by: SQL Injection. The impact is: Unauthenticated mysql database acces... |
| CVE-2019-13952 | CRITICAL | 9.8 | 1.6% | Jul 18, 2019 | The set_ipv6() function in zscan_rfc1035.rl in gdnsd before 2.4.3 and 3.x before 3.2.1 has a stack-based buffer overflow... |
| CVE-2019-13951 | — | — | 1.7% | Jul 18, 2019 | The set_ipv4() function in zscan_rfc1035.rl in gdnsd 3.x before 3.2.1 has a stack-based buffer overflow via a long and m... |
| CVE-2019-11230 | — | — | 0.5% | Jul 18, 2019 | In Avast Antivirus before 19.4, a local administrator can trick the product into renaming arbitrary files by replacing t... |
| CVE-2019-1010268 | — | — | 5.7% | Jul 18, 2019 | Ladon since 0.6.1 (since ebef0aae48af78c159b6fce81bc6f5e7e0ddb059) is affected by: XML External Entity (XXE). The impact... |
| CVE-2019-1010262 | — | — | — | Jul 18, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-1010142. Reason: This candidate is a reservation... |
| CVE-2019-1010261 | — | — | 0.8% | Jul 18, 2019 | Gitea 1.7.0 and earlier is affected by: Cross Site Scripting (XSS). The impact is: Attacker is able to have victim execu... |
| CVE-2019-1010259 | — | — | 1.9% | Jul 18, 2019 | SaltStack Salt 2018.3, 2019.2 is affected by: SQL Injection. The impact is: An attacker could escalate privileges on MyS... |
| CVE-2019-1010065 | MEDIUM | 6.5 | 1.4% | Jul 18, 2019 | The Sleuth Kit 4.6.0 and earlier is affected by: Integer Overflow. The impact is: Opening crafted disk image triggers cr... |
| CVE-2019-9231 | — | — | 0.7% | Jul 18, 2019 | An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versio... |
| CVE-2019-3794 | MEDIUM | 5.4 | 1.1% | Jul 18, 2019 | Cloud Foundry UAA, versions prior to v73.4.0, does not set an X-FRAME-OPTIONS header on various endpoints. A remote user... |
| CVE-2019-3741 | HIGH | 7.8 | 0.3% | Jul 18, 2019 | Dell EMC Unity and UnityVSA versions prior to 5.0.0.0.5.116 contain a plain-text password storage vulnerability. A Unisp... |
| CVE-2019-3734 | MEDIUM | 5.4 | 1.1% | Jul 18, 2019 | Dell EMC Unity and UnityVSA versions prior to 5.0.0.0.5.116 contain an improper authorization vulnerability in NAS Serve... |
| CVE-2019-3570 | CRITICAL | 9.8 | 1.7% | Jul 18, 2019 | Call to the scrypt_enc() function in HHVM can lead to heap corruption by using specifically crafted parameters (N, r and... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now