2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-4385 | MEDIUM | 6.5 | 0.3% | Jun 19, 2019 | IBM Spectrum Protect Plus 10.1.2 may display the vSnap CIFS password in the IBM Spectrum Protect Plus Joblog. This can r... |
| CVE-2019-4384 | MEDIUM | 4.3 | 2.3% | Jun 19, 2019 | IBM Campaign 9.1.2 and 10.1 could allow a remote attacker to traverse directories on the system. An attacker could send ... |
| CVE-2019-4364 | HIGH | 8 | 2.6% | Jun 19, 2019 | IBM Maximo Asset Management 7.6 is vulnerable to CSV injection, which could allow a remote authenticated attacker to exe... |
| CVE-2019-4303 | MEDIUM | 5.4 | 1.0% | Jun 19, 2019 | IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrar... |
| CVE-2019-12814 | MEDIUM | 5.9 | 11.0% | Jun 19, 2019 | A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x through 2.9.9. When Default Typing is enable... |
| CVE-2019-10257 | — | — | 2.4% | Jun 19, 2019 | Zucchetti HR Portal through 2019-03-15 allows Directory Traversal. Unauthenticated users can escape outside of the restr... |
| CVE-2019-12436 | — | — | 2.8% | Jun 19, 2019 | Samba 4.10.x before 4.10.5 has a NULL pointer dereference, leading to an AD DC LDAP server Denial of Service. This is re... |
| CVE-2019-12435 | — | — | 2.2% | Jun 19, 2019 | Samba 4.9.x before 4.9.9 and 4.10.x before 4.10.5 has a NULL pointer dereference, leading to Denial of Service. This is ... |
| CVE-2019-3954 | — | — | 3.9% | Jun 19, 2019 | Stack-based buffer overflow in Advantech WebAccess/SCADA 8.4.0 allows a remote, unauthenticated attacker to execute arbi... |
| CVE-2019-3896 | HIGH | 7 | 0.4% | Jun 19, 2019 | A double-free can happen in idr_remove_all() in lib/idr.c in the Linux kernel 2.6 branch. An unprivileged local attacker... |
| CVE-2019-11479 | HIGH | 7.5 | 91.7% | Jun 19, 2019 | Jonathan Looney discovered that the Linux kernel default MSS is hard-coded to 48 bytes. This allows a remote peer to fra... |
| CVE-2019-11478 | MEDIUM | 5.3 | 94.7% | Jun 19, 2019 | Jonathan Looney discovered that the TCP retransmission queue implementation in tcp_fragment in the Linux kernel could be... |
| CVE-2019-11477 | HIGH | 7.5 | 98.7% | Jun 19, 2019 | Jonathan Looney discovered that the TCP_SKB_CB(skb)->tcp_gso_segs value was subject to an integer overflow in the Linux ... |
| CVE-2019-11271 | HIGH | 7.8 | 0.3% | Jun 19, 2019 | Cloud Foundry BOSH 270.x versions prior to v270.1.1, contain a BOSH Director that does not properly redact credentials w... |
| CVE-2019-11040 | CRITICAL | 9.1 | 4.0% | Jun 19, 2019 | When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7... |
| CVE-2019-11039 | CRITICAL | 9.1 | 3.0% | Jun 19, 2019 | Function iconv_mime_decode_headers() in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3.6 may pe... |
| CVE-2019-11038 | MEDIUM | 5.3 | 4.3% | Jun 19, 2019 | When using the gdImageCreateFromXbm() function in the GD Graphics Library (aka LibGD) 2.2.5, as used in the PHP GD exten... |
| CVE-2019-10085 | — | — | 5.1% | Jun 19, 2019 | In Apache Allura prior to 1.11.0, a vulnerability exists for stored XSS on the user dropdown selector when creating or e... |
| CVE-2019-3953 | — | — | 4.0% | Jun 18, 2019 | Stack-based buffer overflow in Advantech WebAccess/SCADA 8.4.0 allows a remote, unauthenticated attacker to execute arbi... |
| CVE-2019-12881 | HIGH | 7.8 | 0.8% | Jun 18, 2019 | i915_gem_userptr_get_pages in drivers/gpu/drm/i915/i915_gem_userptr.c in the Linux kernel 4.15.0 on Ubuntu 18.04.2 allow... |
| CVE-2019-12133 | — | — | 1.8% | Jun 18, 2019 | Multiple Zoho ManageEngine products suffer from local privilege escalation due to improper permissions for the %SYSTEMDR... |
| CVE-2019-12592 | — | — | 1.1% | Jun 18, 2019 | A universal Cross-site scripting (UXSS) vulnerability in the Evernote Web Clipper extension before 7.11.1 for Chrome all... |
| CVE-2019-12875 | — | — | 1.3% | Jun 18, 2019 | Alpine Linux abuild through 3.4.0 allows an unprivileged member of the abuild group to add an untrusted package via a --... |
| CVE-2019-12874 | — | — | 2.4% | Jun 18, 2019 | An issue was discovered in zlib_decompress_extra in modules/demux/mkv/util.cpp in VideoLAN VLC media player 3.x through ... |
| CVE-2019-4142 | HIGH | 8.8 | 0.5% | Jun 18, 2019 | IBM Cloud Private 2.1.0, 3.1.0, 3.1.1, and 3.1.2 is vulnerable to cross-site request forgery which could allow an attack... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now