2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-12977ImageMagick 7.0.8-34 has a "use of uninitialized value" vulnerability in the WriteJP2Image function in coders/jp2.c.
CVE-2019-12976MEDIUM5.5ImageMagick 7.0.8-34 has a memory leak in the ReadPCLImage function in coders/pcl.c.
CVE-2019-12975MEDIUM5.5ImageMagick 7.0.8-34 has a memory leak vulnerability in the WriteDPXImage function in coders/dpx.c.
CVE-2019-12974A NULL pointer dereference in the function ReadPANGOImage in coders/pango.c and the function ReadVIDImage in coders/vid....
CVE-2019-12973MEDIUM5.5In OpenJPEG 2.3.1, there is excessive iteration in the opj_t1_encode_cblks function of openjp2/t1.c. Remote attackers co...
CVE-2019-11583The issue searching component in Jira before version 8.1.0 allows remote attackers to deny access to Jira service via de...
CVE-2019-10164HIGH8.8PostgreSQL versions 10.x before 10.9 and versions 11.x before 11.4 are vulnerable to a stack-based buffer overflow. Any ...
CVE-2019-4241HIGH7.8IBM PureApplication System 2.2.3.0 through 2.2.5.3 could allow an authenticated user with local access to bypass authent...
CVE-2019-4235HIGH7.5IBM PureApplication System 2.2.3.0 through 2.2.5.3 does not require that users should have strong passwords by default, ...
CVE-2019-4234MEDIUM4.3IBM PureApplication System 2.2.3.0 through 2.2.5.3 weakness in the implementation of locking feature in pattern editor. ...
CVE-2019-4225MEDIUM4.4IBM PureApplication System 2.2.3.0 through 2.2.5.3 stores potentially sensitive information in log files that could be r...
CVE-2019-4224HIGH8.8IBM PureApplication System 2.2.3.0 through 2.2.5.3 is vulnerable to SQL injection. A remote attacker could send speciall...
CVE-2019-3569HIGH7.5HHVM, when used with FastCGI, would bind by default to all available interfaces. This behavior could allow a malicious i...
CVE-2019-6169HIGH7.5A vulnerability reported in Lenovo Service Bridge before version 4.1.0.1 could allow unencrypted downloads over FTP.
CVE-2019-6168CRITICAL9.8A vulnerability reported in Lenovo Service Bridge before version 4.1.0.1 could allow remote code execution.
CVE-2019-6167CRITICAL9.8A vulnerability reported in Lenovo Service Bridge before version 4.1.0.1 could allow remote code execution.
CVE-2019-6166HIGH8.8A vulnerability reported in Lenovo Service Bridge before version 4.1.0.1 could allow cross-site request forgery.
CVE-2019-6163MEDIUM5.5A denial of service vulnerability was reported in Lenovo System Update before version 5.07.0084 that could allow service...
CVE-2019-12972MEDIUM5.5An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. T...
CVE-2019-11272HIGH7.3Spring Security, versions 4.2.x up to 4.2.12, and older unsupported versions support plain text passwords using Plaintex...
CVE-2019-12968A vulnerability was found in the Sonic Robo Blast 2 (SRB2) plugin (EP_Versions 9 to 11 inclusive) distributed with Dooms...
CVE-2019-12966FeHelper through 2019-06-19 allows arbitrary code execution during a JSON format operation, as demonstrated by the {"a":...
CVE-2019-12888Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-12887. Reason: This candidate is a reservation d...
CVE-2019-9836MEDIUM5.3Secure Encrypted Virtualization (SEV) on Advanced Micro Devices (AMD) Platform Security Processor (PSP; aka AMD Secure P...
CVE-2019-3961Nessus versions 8.4.0 and earlier were found to contain a reflected XSS vulnerability due to improper validation of user...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now