2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-20094 | HIGH | 8.8 | 1.0% | Dec 30, 2019 | An issue was discovered in libsixel 1.8.4. There is a heap-based buffer overflow in the function gif_init_frame at fromg... |
| CVE-2019-20090 | HIGH | 7.8 | 0.8% | Dec 30, 2019 | An issue was discovered in Bento4 1.5.1.0. There is a use-after-free in AP4_Sample::GetOffset in Core/Ap4Sample.h when c... |
| CVE-2019-20089 | HIGH | 7.8 | 0.8% | Dec 30, 2019 | GoPro GPMF-parser 1.2.3 has an heap-based buffer over-read in GPMF_SeekToSamples in GPMF_parse.c for the size calculatio... |
| CVE-2019-20088 | HIGH | 7.8 | 0.9% | Dec 30, 2019 | GoPro GPMF-parser 1.2.3 has a heap-based buffer over-read in GetPayload in GPMF_mp4reader.c. |
| CVE-2019-20087 | HIGH | 8.8 | 1.0% | Dec 30, 2019 | GoPro GPMF-parser 1.2.3 has a heap-based buffer over-read in GPMF_seekToSamples in GPMF-parse.c for the "matching tags" ... |
| CVE-2019-20086 | HIGH | 8.8 | 1.0% | Dec 30, 2019 | GoPro GPMF-parser 1.2.3 has a heap-based buffer over-read in GPMF_Next in GPMF_parser.c. |
| CVE-2019-20085 | HIGH | 7.5 | 96.1% | Dec 30, 2019 | TVT NVMS-1000 devices allow GET /.. Directory Traversal |
| CVE-2019-20079 | HIGH | 7.8 | 1.9% | Dec 30, 2019 | The autocmd feature in window.c in Vim before 8.1.2136 accesses freed memory. |
| CVE-2019-20074 | HIGH | 8.8 | 1.4% | Dec 30, 2019 | On Netis DL4323 devices, any user role can view sensitive information, such as a user password or the FTP password, via ... |
| CVE-2019-20063 | HIGH | 8.8 | 1.7% | Dec 29, 2019 | hdf/dataobject.c in libmysofa before 0.8 has an uninitialized use of memory, as demonstrated by mysofa2json. |
| CVE-2019-20048 | HIGH | 7.2 | 5.8% | Dec 27, 2019 | An issue was discovered on Alcatel-Lucent OmniVista 8770 devices before 4.1.2. An authenticated remote attacker, with el... |
| CVE-2019-20047 | HIGH | 7.5 | 2.7% | Dec 27, 2019 | An issue was discovered on Alcatel-Lucent OmniVista 4760 devices, and 8770 devices before 4.1.2. An incorrect web server... |
| CVE-2019-16896 | HIGH | 7.8 | 0.4% | Dec 27, 2019 | In K7 Ultimate Security 16.0.0117, the module K7BKCExt.dll (aka the backup module) improperly validates the administrati... |
| CVE-2019-20014 | HIGH | 8.8 | 1.5% | Dec 27, 2019 | An issue was discovered in GNU LibreDWG before 0.93. There is a double-free in dwg_free in free.c. |
| CVE-2019-20011 | HIGH | 8.8 | 1.5% | Dec 27, 2019 | An issue was discovered in GNU LibreDWG 0.92. There is a heap-based buffer over-read in decode_R13_R2000 in decode.c. |
| CVE-2019-20010 | HIGH | 8.8 | 1.4% | Dec 27, 2019 | An issue was discovered in GNU LibreDWG 0.92. There is a use-after-free in resolve_objectref_vector in decode.c. |
| CVE-2019-20006 | HIGH | 7.5 | 1.6% | Dec 26, 2019 | An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxml_char_content puts a pointer to the internal add... |
| CVE-2019-5275 | HIGH | 7.5 | 0.5% | Dec 26, 2019 | USG9500 with versions of V500R001C30;V500R001C60 have a denial of service vulnerability. Due to a flaw in the X.509 impl... |
| CVE-2019-5274 | HIGH | 7.5 | 0.5% | Dec 26, 2019 | USG9500 with versions of V500R001C30;V500R001C60 have a denial of service vulnerability. Due to a flaw in the X.509 impl... |
| CVE-2019-5273 | HIGH | 7.5 | 0.5% | Dec 26, 2019 | USG9500 with versions of V500R001C30;V500R001C60 have a denial of service vulnerability. Due to a flaw in the X.509 impl... |
| CVE-2019-19996 | HIGH | 7.5 | 1.5% | Dec 26, 2019 | An issue was discovered on Intelbras IWR 3000N 1.8.7 devices. A malformed login request allows remote attackers to cause... |
| CVE-2019-19995 | HIGH | 8.8 | 0.7% | Dec 26, 2019 | A CSRF issue was discovered on Intelbras IWR 3000N 1.8.7 devices, leading to complete control of the router, as demonstr... |
| CVE-2019-16326 | HIGH | 8.8 | 0.6% | Dec 26, 2019 | D-Link DIR-601 B1 2.00NA devices have CSRF because no anti-CSRF token is implemented. A remote attacker could exploit th... |
| CVE-2019-16789 | HIGH | 8.2 | 2.6% | Dec 26, 2019 | In Waitress through version 1.4.0, if a proxy server is used in front of waitress, an invalid request may be sent by an ... |
| CVE-2019-6032 | HIGH | 7.4 | 0.5% | Dec 26, 2019 | The NTV News24 prior to Ver.3.0.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle at... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now