2019 CVE Vulnerabilities

17,624 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-25038CRITICAL9.8Unbound before 1.9.5 allows an integer overflow in a size calculation in dnscrypt/dnscrypt.c. NOTE: The vendor disputes ...
CVE-2019-25037HIGH7.5Unbound before 1.9.5 allows an assertion failure and denial of service in dname_pkt_copy via an invalid packet. NOTE: Th...
CVE-2019-25036HIGH7.5Unbound before 1.9.5 allows an assertion failure and denial of service in synth_cname. NOTE: The vendor disputes that th...
CVE-2019-25035CRITICAL9.8Unbound before 1.9.5 allows an out-of-bounds write in sldns_bget_token_par. NOTE: The vendor disputes that this is a vul...
CVE-2019-25034CRITICAL9.8Unbound before 1.9.5 allows an integer overflow in sldns_str2wire_dname_buf_origin, leading to an out-of-bounds write. N...
CVE-2019-25033CRITICAL9.8Unbound before 1.9.5 allows an integer overflow in the regional allocator via the ALIGN_UP macro. NOTE: The vendor dispu...
CVE-2019-25032CRITICAL9.8Unbound before 1.9.5 allows an integer overflow in the regional allocator via regional_alloc. NOTE: The vendor disputes ...
CVE-2019-25031MEDIUM5.9Unbound before 1.9.5 allows configuration injection in create_unbound_ad_servers.sh upon a successful man-in-the-middle ...
CVE-2019-25028MEDIUM6.1Missing variable sanitization in Grid component in com.vaadin:vaadin-server versions 7.4.0 through 7.7.19 (Vaadin 7.4.0 ...
CVE-2019-25027MEDIUM6.1Missing output sanitization in default RouteNotFoundError view in com.vaadin:flow-server versions 1.0.0 through 1.0.10 (...
CVE-2019-10881CRITICAL9.8Xerox AltaLink B8045/B8055/B8065/B8075/B8090, AltaLink C8030/C8035/C8045/C8055/C8070 with software releases before 103.x...
CVE-2019-15059HIGH7.5In Liberty lisPBX 2.0-4, configuration backup files can be retrieved remotely from /backup/lispbx-CONF-YYYY-MM-DD.tar or...
CVE-2019-17656MEDIUM6.5A Stack-based Buffer Overflow vulnerability in the HTTPD daemon of FortiOS 6.0.10 and below, 6.2.2 and below and FortiPr...
CVE-2019-25026MEDIUM5.3Redmine before 3.4.13 and 4.x before 4.0.6 mishandles markup data during Textile formatting.
CVE-2019-20466HIGH7.8An issue was discovered on Sannce Smart HD Wifi Security Camera EAN 2 950004 595317 devices. A local attacker with the "...
CVE-2019-20465HIGH7.5An issue was discovered on Sannce Smart HD Wifi Security Camera EAN 2 950004 595317 devices. It is possible (using TELNE...
CVE-2019-20464HIGH7.5An issue was discovered on Sannce Smart HD Wifi Security Camera EAN 2 950004 595317 devices. By default, a mobile applic...
CVE-2019-20463HIGH7.5An issue was discovered on Sannce Smart HD Wifi Security Camera EAN 2 950004 595317 devices. A crash and reboot can be t...
CVE-2019-5319CRITICAL9.8A remote buffer overflow vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): A...
CVE-2019-5317MEDIUM6.8A local authentication bypass vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(...
CVE-2019-19354HIGH7.8An insecure modification vulnerability in the /etc/passwd file was found in the operator-framework/hadoop as shipped in ...
CVE-2019-19353HIGH7An insecure modification vulnerability in the /etc/passwd file was found in the operator-framework/hive as shipped in Re...
CVE-2019-19352HIGH7An insecure modification vulnerability in the /etc/passwd file was found in the operator-framework/presto as shipped in ...
CVE-2019-19350HIGH7.8An insecure modification vulnerability in the /etc/passwd file was found in the openshift/ansible-service-broker as ship...
CVE-2019-19349HIGH7.8An insecure modification vulnerability in the /etc/passwd file was found in the container operator-framework/operator-me...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now