2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-7665MEDIUM5.5In elfutils 0.175, a heap-based buffer over-read was discovered in the function elf32_xlatetom in elf32_xlatetom.c in li...
CVE-2019-7664MEDIUM5.5In elfutils 0.175, a negative-sized memcpy is attempted in elf_cvt_note in libelf/note_xlate.h because of an incorrect o...
CVE-2019-7663An Invalid Address dereference was discovered in TIFFWriteDirectoryTagTransferfunction in libtiff/tif_dirwrite.c in LibT...
CVE-2019-7662MEDIUM6.5An assertion failure was discovered in wasm::WasmBinaryBuilder::getType() in wasm-binary.cpp in Binaryen 1.38.22. This a...
CVE-2019-7659Genivia gSOAP 2.7.x and 2.8.x before 2.8.75 allows attackers to cause a denial of service (application abort) or possibl...
CVE-2019-7653CRITICAL9.8The Debian python-rdflib-tools 4.2.2-1 package for RDFLib 4.2.2 has CLI tools that can load Python modules from the curr...
CVE-2019-7651EPP.sys in Emsisoft Anti-Malware prior to version 2018.12 allows an attacker to bypass ACLs because Interpreted Device C...
CVE-2019-1676MEDIUM6.8A vulnerability in the Session Initiation Protocol (SIP) call processing of Cisco Meeting Server (CMS) software could al...
CVE-2019-1672MEDIUM5.8A vulnerability in the Decryption Policy Default Action functionality of the Cisco Web Security Appliance (WSA) could al...
CVE-2019-7648controller/fetchpwd.php and controller/doAction.php in Hotels_Server through 2018-11-05 rely on base64 in an attempt to ...
CVE-2019-1673MEDIUM5.4A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticat...
CVE-2019-7639An issue was discovered in gsi-openssh-server 7.9p1 on Fedora 29. If PermitPAMUserChange is set to yes in the /etc/gsiss...
CVE-2019-7638HIGH8.8SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in Map1toN in vide...
CVE-2019-7637HIGH8.8SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer overflow in SDL_FillRect in ...
CVE-2019-7636HIGH8.1SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in SDL_GetRGB in v...
CVE-2019-7635HIGH8.1SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in Blit1to4 in vid...
CVE-2019-7632LifeSize Team, Room, Passport, and Networker 220 devices allow Authenticated Remote OS Command Injection, as demonstrate...
CVE-2019-6242Kentico v10.0.42 allows Global Administrators to read the cleartext SMTP Password by navigating to the SMTP configuratio...
CVE-2019-7628Pagure 5.2 leaks API keys by e-mailing them to users. Few e-mail servers validate TLS certificates, so it is easy for ma...
CVE-2019-7401NGINX Unit before 1.7.1 might allow an attacker to cause a heap-based buffer overflow in the router process with a speci...
CVE-2019-6139CRITICAL9.8Forcepoint User ID (FUID) server versions up to 1.2 have a remote arbitrary file upload vulnerability on TCP port 5001. ...
CVE-2019-1671MEDIUM6.1A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an unauthen...
CVE-2019-1670MEDIUM6.1A vulnerability in the web-based management interface of Cisco Unified Intelligence Center Software could allow an unaut...
CVE-2019-1661MEDIUM6.1A vulnerability in the web-based management interface of Cisco TelePresence Management Suite (TMS) software could allow ...
CVE-2019-1680MEDIUM4.3A vulnerability in Cisco Webex Business Suite could allow an unauthenticated, remote attacker to inject arbitrary text i...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now