2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-2035In rw_i93_sm_update_ndef of rw_i93.cc, there is a possible out-of-bound write due to a missing bounds check. This could ...
CVE-2019-2034In rw_i93_sm_read_ndef of rw_i93.cc, there is a possible out-of-bounds write due to an integer overflow. This could lead...
CVE-2019-2033In create_hdr of dnssd_clientstub.c, there is a possible use after free. This could lead to local escalation of privileg...
CVE-2019-2032In SetScanResponseData of ble_advertiser_hci_interface.cc, there is a possible out-of-bound write due to a missing bound...
CVE-2019-2031In rw_t3t_act_handle_check_ndef_rsp of rw_t3t.cc, there is a possible out-of-bound write due to a missing bounds check. ...
CVE-2019-2030In removeInterfaceAddress of NetworkController.cpp, there is a possible use after free. This could lead to remote code e...
CVE-2019-2029In btm_proc_smp_cback of tm_ble.cc, there is a possible memory corruption due to a use after free. This could lead to re...
CVE-2019-2028In numerous hand-crafted functions in libmpeg2, NEON registers are not preserved. This could lead to remote code executi...
CVE-2019-2027In floor0_inverse1 of floor0.c, there is a possible out of bounds write due to an incorrect bounds check. This could lea...
CVE-2019-2026In updateAssistMenuItems of Editor.java, there is a possible escape from the Setup Wizard due to a missing permission ch...
CVE-2019-9841Vesta Control Panel 0.9.8-23 allows XSS via a crafted URL.
CVE-2019-5008hw/sparc64/sun4u.c in QEMU 3.1.50 is vulnerable to a NULL pointer dereference, which allows the attacker to cause a deni...
CVE-2019-11344data/inc/files.php in Pluck 4.7.8 allows remote attackers to execute arbitrary code by uploading a .htaccess file that s...
CVE-2019-10886An incorrect access control exists in the Sony Photo Sharing Plus application in the firmware before PKG6.5629 version (...
CVE-2019-4055HIGH7.5IBM MQ 8.0.0.0 through 8.0.0.10, 9.0.0.0 through 9.0.0.5, and 9.1.0.0 through 9.1.1 is vulnerable to a denial of service...
CVE-2019-11340util/emailutils.py in Matrix Sydent before 1.0.2 mishandles registration restrictions that are based on e-mail domain, i...
CVE-2019-10245HIGH7.5In Eclipse OpenJ9 prior to the 0.14.0 release, the Java bytecode verifier incorrectly allows a method to execute past th...
CVE-2019-11339The studio profile decoder in libavcodec/mpeg4videodec.c in FFmpeg 4.0 before 4.0.4 and 4.1 before 4.1.2 allows remote a...
CVE-2019-11338HIGH8.8libavcodec/hevcdec.c in FFmpeg 3.4 and 4.1.2 mishandles detection of duplicate first slices, which allows remote attacke...
CVE-2019-9161WAC on the Sangfor Sundray WLAN Controller version 3.7.4.2 and earlier has a Remote Code Execution issue allowing remote...
CVE-2019-11332MKCMS 5.0 allows remote attackers to take over arbitrary user accounts by posting a username and e-mail address to ucent...
CVE-2019-9160WAC on the Sangfor Sundray WLAN Controller version 3.7.4.2 and earlier has a backdoor account allowing a remote attacker...
CVE-2019-11331Network Time Protocol (NTP), as specified in RFC 5905, uses port 123 even for modes where a fixed port number is not req...
CVE-2019-11015A vulnerability was found in the MIUI OS version 10.1.3.0 that allows a physically proximate attacker to bypass Lockscre...
CVE-2019-11324The urllib3 library before 1.24.2 for Python mishandles certain cases where the desired set of CA certificates is differ...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now