2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2019-20055MEDIUM6.5LuquidPixels LiquiFire OS 4.8.0 allows SSRF via the call%3Durl substring followed by a URL in square brackets.
CVE-2019-20054MEDIUM5.5In the Linux kernel before 5.0.6, there is a NULL pointer dereference in drop_sysctl_table() in fs/proc/proc_sysctl.c, r...
CVE-2019-20053MEDIUM5.5An invalid memory address dereference was discovered in the canUnpack function in p_mach.cpp in UPX 3.95 via a crafted M...
CVE-2019-20052MEDIUM6.5A memory leak was discovered in Mat_VarCalloc in mat.c in matio 1.5.17 because SafeMulDims does not consider the rank==0...
CVE-2019-20051MEDIUM5.5A floating-point exception was discovered in PackLinuxElf::elf_hash in p_lx_elf.cpp in UPX 3.95. The vulnerability cause...
CVE-2019-20043MEDIUM4.3In in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in WordPress 3.7 to 5.3.0, authenticated users w...
CVE-2019-20042MEDIUM6.1In wp-includes/formatting.php in WordPress 3.7 to 5.3.0, the function wp_targeted_link_rel() can be used in a particular...
CVE-2019-20024MEDIUM6.5A heap-based buffer overflow was discovered in image_buffer_resize in fromsixel.c in libsixel before 1.8.4.
CVE-2019-20023MEDIUM6.5A memory leak was discovered in image_buffer_resize in fromsixel.c in libsixel 1.8.4.
CVE-2019-20022MEDIUM6.5An invalid memory address dereference was discovered in load_pnm in frompnm.c in libsixel before 1.8.3.
CVE-2019-20021MEDIUM5.5A heap-based buffer over-read was discovered in canUnpack in p_mach.cpp in UPX 3.95 via a crafted Mach-O file.
CVE-2019-20020MEDIUM6.5A stack-based buffer over-read was discovered in ReadNextStructField in mat5.c in matio 1.5.17.
CVE-2019-20019MEDIUM6.5An attempted excessive memory allocation was discovered in Mat_VarRead5 in mat5.c in matio 1.5.17.
CVE-2019-20018MEDIUM6.5A stack-based buffer over-read was discovered in ReadNextCell in mat5.c in matio 1.5.17.
CVE-2019-20017MEDIUM6.5A stack-based buffer over-read was discovered in Mat_VarReadNextInfo5 in mat5.c in matio 1.5.17.
CVE-2019-20016MEDIUM6.5libmysofa before 2019-11-24 does not properly restrict recursive function calls, as demonstrated by reports of stack con...
CVE-2019-20015MEDIUM6.5An issue was discovered in GNU LibreDWG 0.92. Crafted input will lead to an attempted excessive memory allocation in dwg...
CVE-2019-20013MEDIUM6.5An issue was discovered in GNU LibreDWG before 0.93. Crafted input will lead to an attempted excessive memory allocation...
CVE-2019-20012MEDIUM6.5An issue was discovered in GNU LibreDWG 0.92. Crafted input will lead to an attempted excessive memory allocation in dwg...
CVE-2019-20009MEDIUM6.5An issue was discovered in GNU LibreDWG before 0.93. Crafted input will lead to an attempted excessive memory allocation...
CVE-2019-20008MEDIUM5.4In Archery before 1.3, inserting an XSS payload into a project name (either by creating a new project or editing an exis...
CVE-2019-20007MEDIUM6.5An issue was discovered in ezXML 0.8.2 through 0.8.6. The function ezxml_str2utf8, while parsing a crafted XML file, per...
CVE-2019-20005MEDIUM6.5An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxml_decode, while parsing a crafted XML file, perfo...
CVE-2019-19389MEDIUM5.4JetBrains Ktor framework before version 1.2.6 was vulnerable to HTTP Response Splitting.
CVE-2019-5272MEDIUM4.9USG9500 with versions of V500R001C30;V500R001C60 have a missing integrity checking vulnerability. The software of the af...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now