2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-8358In Hiawatha before 10.8.4, a remote attacker is able to do directory traversal if AllowDotFiles is enabled.
CVE-2019-8357An issue was discovered in SoX 14.4.2. lsx_make_lpf in effect_i_dsp.c allows a NULL pointer dereference.
CVE-2019-8356An issue was discovered in SoX 14.4.2. One of the arguments to bitrv2 in fft4g.c is not guarded, such that it can lead t...
CVE-2019-8355An issue was discovered in SoX 14.4.2. In xmalloc.h, there is an integer overflow on the result of multiplication fed in...
CVE-2019-8354MEDIUM5An issue was discovered in SoX 14.4.2. lsx_make_lpf in effect_i_dsp.c has an integer overflow on the result of multiplic...
CVE-2019-4059CRITICAL9.8IBM Rational ClearCase 1.0.0.0 GIT connector does not sufficiently protect the document database password. An attacker c...
CVE-2019-0267SAP Manufacturing Integration and Intelligence, versions 15.0, 15.1 and 15.2, (Illuminator Servlet) currently does not p...
CVE-2019-0266Under certain conditions SAP HANA Extended Application Services, version 1.0, advanced model (XS advanced) writes creden...
CVE-2019-0265SLD Registration of ABAP Platform allows an attacker to prevent legitimate users from accessing a service, either by cra...
CVE-2019-0262SAP WebIntelligence BILaunchPad, versions 4.10, 4.20, does not sufficiently encode user-controlled inputs in generated H...
CVE-2019-0261Under certain circumstances, SAP HANA Extended Application Services, advanced model (XS advanced) does not perform authe...
CVE-2019-0259SAP BusinessObjects, versions 4.2 and 4.3, (Visual Difference) allows an attacker to upload any file (including script f...
CVE-2019-0258SAP Disclosure Management, version 10.01, does not perform necessary authorization checks for an authenticated user, res...
CVE-2019-0257HIGH8.8Customizing functionality of SAP NetWeaver AS ABAP Platform (fixed in versions from 7.0 to 7.02, from 7.10 to 7.11, 7.30...
CVE-2019-0256Under certain conditions SAP Business One Mobile Android App, version 1.2.12, allows an attacker to access information w...
CVE-2019-0255SAP NetWeaver AS ABAP Platform, Krnl64nuc 7.74, krnl64UC 7.73, 7.74, Kernel 7.73, 7.74, 7.75, fails to validate type of ...
CVE-2019-0254SAP Disclosure Management (before version 10.1 Stack 1301) does not sufficiently encode user-controlled inputs, resultin...
CVE-2019-0251The Fiori Launchpad of SAP BusinessObjects, before versions 4.2 and 4.3, does not sufficiently encode user-controlled in...
CVE-2019-8347BEESCMS 4.0 has a CSRF vulnerability to add arbitrary VIP accounts via the admin/admin_member.php?action=add&nav=add_web...
CVE-2019-6974HIGH8.1In the Linux kernel before 4.20.8, kvm_ioctl_create_device in virt/kvm/kvm_main.c mishandles reference counting because ...
CVE-2019-8345The Help feature in the ES File Explorer File Manager application 4.1.9.7.4 for Android allows session hijacking by a Ma...
CVE-2019-8343In Netwide Assembler (NASM) 2.14.02, there is a use-after-free in paste_tokens in asm/preproc.c.
CVE-2019-8341CRITICAL9.8An issue was discovered in Jinja2 2.10. The from_string function is prone to Server Side Template Injection (SSTI) where...
CVE-2019-6589On BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.1.3, 12.1.0-12.1.3.7, and 11.6.0-11.6.3.2, a reflected Cross Site Scripting (XSS)...
CVE-2019-8337In msmtp 1.8.2 and mpop 1.4.3, when tls_trust_file has its default configuration, certificate-verification results are n...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now