2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2019-20094HIGH8.8An issue was discovered in libsixel 1.8.4. There is a heap-based buffer overflow in the function gif_init_frame at fromg...
CVE-2019-20090HIGH7.8An issue was discovered in Bento4 1.5.1.0. There is a use-after-free in AP4_Sample::GetOffset in Core/Ap4Sample.h when c...
CVE-2019-20089HIGH7.8GoPro GPMF-parser 1.2.3 has an heap-based buffer over-read in GPMF_SeekToSamples in GPMF_parse.c for the size calculatio...
CVE-2019-20088HIGH7.8GoPro GPMF-parser 1.2.3 has a heap-based buffer over-read in GetPayload in GPMF_mp4reader.c.
CVE-2019-20087HIGH8.8GoPro GPMF-parser 1.2.3 has a heap-based buffer over-read in GPMF_seekToSamples in GPMF-parse.c for the "matching tags" ...
CVE-2019-20086HIGH8.8GoPro GPMF-parser 1.2.3 has a heap-based buffer over-read in GPMF_Next in GPMF_parser.c.
CVE-2019-20085HIGH7.5TVT NVMS-1000 devices allow GET /.. Directory Traversal
CVE-2019-20079HIGH7.8The autocmd feature in window.c in Vim before 8.1.2136 accesses freed memory.
CVE-2019-20074HIGH8.8On Netis DL4323 devices, any user role can view sensitive information, such as a user password or the FTP password, via ...
CVE-2019-20063HIGH8.8hdf/dataobject.c in libmysofa before 0.8 has an uninitialized use of memory, as demonstrated by mysofa2json.
CVE-2019-20048HIGH7.2An issue was discovered on Alcatel-Lucent OmniVista 8770 devices before 4.1.2. An authenticated remote attacker, with el...
CVE-2019-20047HIGH7.5An issue was discovered on Alcatel-Lucent OmniVista 4760 devices, and 8770 devices before 4.1.2. An incorrect web server...
CVE-2019-16896HIGH7.8In K7 Ultimate Security 16.0.0117, the module K7BKCExt.dll (aka the backup module) improperly validates the administrati...
CVE-2019-20014HIGH8.8An issue was discovered in GNU LibreDWG before 0.93. There is a double-free in dwg_free in free.c.
CVE-2019-20011HIGH8.8An issue was discovered in GNU LibreDWG 0.92. There is a heap-based buffer over-read in decode_R13_R2000 in decode.c.
CVE-2019-20010HIGH8.8An issue was discovered in GNU LibreDWG 0.92. There is a use-after-free in resolve_objectref_vector in decode.c.
CVE-2019-20006HIGH7.5An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxml_char_content puts a pointer to the internal add...
CVE-2019-5275HIGH7.5USG9500 with versions of V500R001C30;V500R001C60 have a denial of service vulnerability. Due to a flaw in the X.509 impl...
CVE-2019-5274HIGH7.5USG9500 with versions of V500R001C30;V500R001C60 have a denial of service vulnerability. Due to a flaw in the X.509 impl...
CVE-2019-5273HIGH7.5USG9500 with versions of V500R001C30;V500R001C60 have a denial of service vulnerability. Due to a flaw in the X.509 impl...
CVE-2019-19996HIGH7.5An issue was discovered on Intelbras IWR 3000N 1.8.7 devices. A malformed login request allows remote attackers to cause...
CVE-2019-19995HIGH8.8A CSRF issue was discovered on Intelbras IWR 3000N 1.8.7 devices, leading to complete control of the router, as demonstr...
CVE-2019-16326HIGH8.8D-Link DIR-601 B1 2.00NA devices have CSRF because no anti-CSRF token is implemented. A remote attacker could exploit th...
CVE-2019-16789HIGH8.2In Waitress through version 1.4.0, if a proxy server is used in front of waitress, an invalid request may be sent by an ...
CVE-2019-6032HIGH7.4The NTV News24 prior to Ver.3.0.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle at...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now