2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-12977 | — | — | 1.9% | Jun 26, 2019 | ImageMagick 7.0.8-34 has a "use of uninitialized value" vulnerability in the WriteJP2Image function in coders/jp2.c. |
| CVE-2019-12976 | MEDIUM | 5.5 | 2.4% | Jun 26, 2019 | ImageMagick 7.0.8-34 has a memory leak in the ReadPCLImage function in coders/pcl.c. |
| CVE-2019-12975 | MEDIUM | 5.5 | 2.3% | Jun 26, 2019 | ImageMagick 7.0.8-34 has a memory leak vulnerability in the WriteDPXImage function in coders/dpx.c. |
| CVE-2019-12974 | — | — | 2.3% | Jun 26, 2019 | A NULL pointer dereference in the function ReadPANGOImage in coders/pango.c and the function ReadVIDImage in coders/vid.... |
| CVE-2019-12973 | MEDIUM | 5.5 | 2.6% | Jun 26, 2019 | In OpenJPEG 2.3.1, there is excessive iteration in the opj_t1_encode_cblks function of openjp2/t1.c. Remote attackers co... |
| CVE-2019-11583 | — | — | 1.5% | Jun 26, 2019 | The issue searching component in Jira before version 8.1.0 allows remote attackers to deny access to Jira service via de... |
| CVE-2019-10164 | HIGH | 8.8 | 3.7% | Jun 26, 2019 | PostgreSQL versions 10.x before 10.9 and versions 11.x before 11.4 are vulnerable to a stack-based buffer overflow. Any ... |
| CVE-2019-4241 | HIGH | 7.8 | 0.4% | Jun 26, 2019 | IBM PureApplication System 2.2.3.0 through 2.2.5.3 could allow an authenticated user with local access to bypass authent... |
| CVE-2019-4235 | HIGH | 7.5 | 1.5% | Jun 26, 2019 | IBM PureApplication System 2.2.3.0 through 2.2.5.3 does not require that users should have strong passwords by default, ... |
| CVE-2019-4234 | MEDIUM | 4.3 | 0.9% | Jun 26, 2019 | IBM PureApplication System 2.2.3.0 through 2.2.5.3 weakness in the implementation of locking feature in pattern editor. ... |
| CVE-2019-4225 | MEDIUM | 4.4 | 0.4% | Jun 26, 2019 | IBM PureApplication System 2.2.3.0 through 2.2.5.3 stores potentially sensitive information in log files that could be r... |
| CVE-2019-4224 | HIGH | 8.8 | 1.4% | Jun 26, 2019 | IBM PureApplication System 2.2.3.0 through 2.2.5.3 is vulnerable to SQL injection. A remote attacker could send speciall... |
| CVE-2019-3569 | HIGH | 7.5 | 1.5% | Jun 26, 2019 | HHVM, when used with FastCGI, would bind by default to all available interfaces. This behavior could allow a malicious i... |
| CVE-2019-6169 | HIGH | 7.5 | 0.8% | Jun 26, 2019 | A vulnerability reported in Lenovo Service Bridge before version 4.1.0.1 could allow unencrypted downloads over FTP. |
| CVE-2019-6168 | CRITICAL | 9.8 | 2.5% | Jun 26, 2019 | A vulnerability reported in Lenovo Service Bridge before version 4.1.0.1 could allow remote code execution. |
| CVE-2019-6167 | CRITICAL | 9.8 | 2.5% | Jun 26, 2019 | A vulnerability reported in Lenovo Service Bridge before version 4.1.0.1 could allow remote code execution. |
| CVE-2019-6166 | HIGH | 8.8 | 0.5% | Jun 26, 2019 | A vulnerability reported in Lenovo Service Bridge before version 4.1.0.1 could allow cross-site request forgery. |
| CVE-2019-6163 | MEDIUM | 5.5 | 0.8% | Jun 26, 2019 | A denial of service vulnerability was reported in Lenovo System Update before version 5.07.0084 that could allow service... |
| CVE-2019-12972 | MEDIUM | 5.5 | 1.8% | Jun 26, 2019 | An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. T... |
| CVE-2019-11272 | HIGH | 7.3 | 1.4% | Jun 26, 2019 | Spring Security, versions 4.2.x up to 4.2.12, and older unsupported versions support plain text passwords using Plaintex... |
| CVE-2019-12968 | — | — | 2.6% | Jun 26, 2019 | A vulnerability was found in the Sonic Robo Blast 2 (SRB2) plugin (EP_Versions 9 to 11 inclusive) distributed with Dooms... |
| CVE-2019-12966 | — | — | 2.4% | Jun 26, 2019 | FeHelper through 2019-06-19 allows arbitrary code execution during a JSON format operation, as demonstrated by the {"a":... |
| CVE-2019-12888 | — | — | — | Jun 26, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-12887. Reason: This candidate is a reservation d... |
| CVE-2019-9836 | MEDIUM | 5.3 | 1.6% | Jun 25, 2019 | Secure Encrypted Virtualization (SEV) on Advanced Micro Devices (AMD) Platform Security Processor (PSP; aka AMD Secure P... |
| CVE-2019-3961 | — | — | 1.5% | Jun 25, 2019 | Nessus versions 8.4.0 and earlier were found to contain a reflected XSS vulnerability due to improper validation of user... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now