2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-13450In the Zoom Client through 4.4.4 and RingCentral 7.0.136380.0312 on macOS, remote attackers can force a user to join a v...
CVE-2019-13449In the Zoom Client before 4.4.2 on macOS, remote attackers can cause a denial of service (continual focus grabs) via a s...
CVE-2019-13369Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2019-13368Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2019-13367Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2019-12927MailEnable Enterprise Premium 10.23 was vulnerable to stored and reflected cross-site scripting (XSS) attacks. Because t...
CVE-2019-12926MailEnable Enterprise Premium 10.23 did not use appropriate access control checks in a number of areas. As a result, it ...
CVE-2019-12925MailEnable Enterprise Premium 10.23 was vulnerable to multiple directory traversal issues, with which authenticated user...
CVE-2019-12924MailEnable Enterprise Premium 10.23 was vulnerable to XML External Entity Injection (XXE) attacks that could be exploite...
CVE-2019-12923In MailEnable Enterprise Premium 10.23, the potential cross-site request forgery (CSRF) protection mechanism was not imp...
CVE-2019-12930A cross-site scripting (XSS) vulnerability in noMenu() and noSubMenu() in core/navigation/MENU.php in WIKINDX prior to v...
CVE-2019-9630Sonatype Nexus Repository Manager before 3.17.0 has a weak default of giving any unauthenticated user read permissions o...
CVE-2019-9629Sonatype Nexus Repository Manager before 3.17.0 establishes a default administrator user with weak defaults (fixed crede...
CVE-2019-2119In multiple functions of key_store_service.cpp, there is a possible Information Disclosure due to improper locking. This...
CVE-2019-2118In various functions of Parcel.cpp, there are uninitialized or partially initialized stack variables. These could lead t...
CVE-2019-2117In checkQueryPermission of TelephonyProvider.java, there is a possible disclosure of secure data due to a missing permis...
CVE-2019-2116In save_attr_seq of sdp_discovery.cc, there is a possible out-of-bound read due to a missing bounds check. This could le...
CVE-2019-2113In setup wizard there is a bypass of some checks when wifi connection is skipped. This could lead to factory reset prote...
CVE-2019-2112In several functions of alarm.cc, there is possible memory corruption due to a use after free. This could lead to local ...
CVE-2019-2111In loop of DnsTlsSocket.cpp, there is a possible heap memory corruption due to a use after free. This could lead to remo...
CVE-2019-2109In MakeMPEG4VideoCodecSpecificData of AVIExtractor.cpp, there is a possible out of bounds write due to an incorrect boun...
CVE-2019-2107In ihevcd_parse_pps of ihevcd_parse_headers.c, there is a possible out of bounds write due to a missing bounds check. Th...
CVE-2019-2106In ihevcd_sao_shift_ctb of ihevcd_sao.c, there is a possible out of bounds write due to a missing bounds check. This cou...
CVE-2019-2105In FileInputStream::Read of file_input_stream.cc, there is a possible memory corruption due to uninitialized data. This ...
CVE-2019-2104In HIDL, safe_union, and other C++ structs/unions being sent to application processes, there are uninitialized fields. T...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now