2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-13242IrfanView 4.52 has a User Mode Write AV starting at image00400000+0x0000000000013a98.
CVE-2019-13241HIGH7.8FlightCrew v0.9.2 and older are vulnerable to a directory traversal, allowing attackers to write arbitrary files via a ....
CVE-2019-13239inc/user.class.php in GLPI before 9.4.3 allows XSS via a user picture.
CVE-2019-13238An issue was discovered in Bento4 1.5.1.0. A memory allocation failure is unhandled in Core/Ap4SdpAtom.cpp and leads to ...
CVE-2019-13233In arch/x86/lib/insn-eval.c in the Linux kernel before 5.1.9, there is a use-after-free for access to an LDT entry becau...
CVE-2019-13232LOW3.3Info-ZIP UnZip 6.0 mishandles the overlapping of files inside a ZIP container, leading to denial of service (resource co...
CVE-2019-13229deepin-clone before 1.1.3 uses a fixed path /tmp/partclone.log in the Helper::getPartitionSizeInfo() function to write a...
CVE-2019-13228deepin-clone before 1.1.3 uses a fixed path /tmp/repo.iso in the BootDoctor::fix() function to download an ISO file, and...
CVE-2019-13227In GUI mode, deepin-clone before 1.1.3 creates a log file at the fixed path /tmp/.deepin-clone.log as root, and follows ...
CVE-2019-13226HIGH7deepin-clone before 1.1.3 uses a predictable path /tmp/.deepin-clone/mount/<block-dev-basename> in the Helper::temporary...
CVE-2019-13208WavesSysSvc in Waves MAXX Audio allows privilege escalation because the General registry key has Full Control access for...
CVE-2019-9827Hawt Hawtio through 2.5.0 is vulnerable to SSRF, allowing a remote attacker to trigger an HTTP request from an affected ...
CVE-2019-13074A vulnerability in the FTP daemon on MikroTik routers through 6.44.3 could allow remote attackers to exhaust all availab...
CVE-2019-13207nsd-checkzone in NLnet Labs NSD 4.2.0 has a Stack-based Buffer Overflow in the dname_concatenate() function in dname.c.
CVE-2019-12852An SSRF attack was possible on a JetBrains YouTrack server. The issue (1 of 2) was fixed in JetBrains YouTrack 2018.4.49...
CVE-2019-12846A user without the required permissions could gain access to some JetBrains TeamCity settings. The issue was fixed in Te...
CVE-2019-12845The generated Kotlin DSL settings allowed usage of an unencrypted connection for resolving artifacts. The issue was fixe...
CVE-2019-12844A possible stored JavaScript injection was detected on one of the JetBrains TeamCity pages. The issue was fixed in TeamC...
CVE-2019-12843A possible stored JavaScript injection requiring a deliberate server administrator action was detected. The issue was fi...
CVE-2019-12842A reflected XSS on a user page was detected on one of the JetBrains TeamCity pages. The issue was fixed in TeamCity 2018...
CVE-2019-12841Incorrect handling of user input in ZIP extraction was detected in JetBrains TeamCity. The issue was fixed in TeamCity 2...
CVE-2019-10103JetBrains IntelliJ IDEA projects created using the Kotlin (JS Client/JVM Server) IDE Template were resolving Gradle arti...
CVE-2019-10102JetBrains Ktor framework (created using the Kotlin IDE template) versions before 1.1.0 were resolving artifacts using an...
CVE-2019-10101HIGH8.1JetBrains Kotlin versions before 1.3.30 were resolving artifacts using an http connection during the build process, pote...
CVE-2019-9873In several versions of JetBrains IntelliJ IDEA Ultimate, creating Task Servers configurations leads to saving a cleartex...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now