2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-9810HIGH8.8Incorrect alias information in IonMonkey JIT compiler for Array.prototype.slice method may lead to missing bounds check ...
CVE-2019-9809If the source for resources on a page is through an FTP connection, it is possible to trigger a series of modal alert me...
CVE-2019-9808If WebRTC permission is requested from documents with data: or blob: URLs, the permission notifications do not properly ...
CVE-2019-9807When arbitrary text is sent over an FTP connection and a page reload is initiated, it is possible to create a modal aler...
CVE-2019-9806A vulnerability exists during authorization prompting for FTP transaction where successive modal prompts are displayed a...
CVE-2019-9805CRITICAL9.8A latent vulnerability exists in the Prio library where data may be read from uninitialized memory for some functions, l...
CVE-2019-9804In Firefox Developer Tools it is possible that pasting the result of the 'Copy as cURL' command into a command shell on ...
CVE-2019-9803The Upgrade-Insecure-Requests (UIR) specification states that if UIR is enabled through Content Security Policy (CSP), n...
CVE-2019-9802If a Sandbox content process is compromised, it can initiate an FTP download which will then use a child process to rend...
CVE-2019-9801Firefox will accept any registered Program ID as an external protocol handler and offer to launch this local application...
CVE-2019-9799Insufficient bounds checking of data during inter-process communication might allow a compromised content process to be ...
CVE-2019-9798On Android systems, Firefox can load a library from APITRACE_LIB, which is writable by all users and applications. This ...
CVE-2019-9797Cross-origin images can be read in violation of the same-origin policy by exporting an image after using createImageBitm...
CVE-2019-9796A use-after-free vulnerability can occur when the SMIL animation controller incorrectly registers with the refresh drive...
CVE-2019-9795A vulnerability where type-confusion in the IonMonkey just-in-time (JIT) compiler could potentially be used by malicious...
CVE-2019-9794A vulnerability was discovered where specific command line arguments are not properly discarded during Firefox invocatio...
CVE-2019-9793A mechanism was discovered that removes some bounds checking for string, array, or typed array accesses if Spectre mitig...
CVE-2019-9792CRITICAL9.8The IonMonkey just-in-time (JIT) compiler can leak an internal JS_OPTIMIZED_OUT magic value to the running script during...
CVE-2019-9791CRITICAL9.8The type inference system allows the compilation of functions that can cause type confusions between arbitrary objects w...
CVE-2019-9790A use-after-free vulnerability can occur when a raw pointer to a DOM element on a page is obtained using JavaScript and ...
CVE-2019-9789Mozilla developers and community members reported memory safety bugs present in Firefox 65. Some of these bugs showed ev...
CVE-2019-9788CRITICAL9.8Mozilla developers and community members reported memory safety bugs present in Firefox 65, Firefox ESR 60.5, and Thunde...
CVE-2019-0186The input fields of the Apache Pluto "Chat Room" demo portlet 3.0.0 and 3.0.1 are vulnerable to Cross-Site Scripting (XS...
CVE-2019-11493VeryPDF 4.1 has a Memory Overflow leading to Code Execution because pdfocx!CxImageTIF::operator in pdfocx.ocx (used by p...
CVE-2019-11543MEDIUM6.1XSS exists in the admin web console in Pulse Secure Pulse Connect Secure (PCS) 9.0RX before 9.0R3.4, 8.3RX before 8.3R7....

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now