2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-7665 | MEDIUM | 5.5 | 1.4% | Feb 9, 2019 | In elfutils 0.175, a heap-based buffer over-read was discovered in the function elf32_xlatetom in elf32_xlatetom.c in li... |
| CVE-2019-7664 | MEDIUM | 5.5 | 1.0% | Feb 9, 2019 | In elfutils 0.175, a negative-sized memcpy is attempted in elf_cvt_note in libelf/note_xlate.h because of an incorrect o... |
| CVE-2019-7663 | — | — | 3.4% | Feb 9, 2019 | An Invalid Address dereference was discovered in TIFFWriteDirectoryTagTransferfunction in libtiff/tif_dirwrite.c in LibT... |
| CVE-2019-7662 | MEDIUM | 6.5 | 1.6% | Feb 9, 2019 | An assertion failure was discovered in wasm::WasmBinaryBuilder::getType() in wasm-binary.cpp in Binaryen 1.38.22. This a... |
| CVE-2019-7659 | — | — | 2.0% | Feb 9, 2019 | Genivia gSOAP 2.7.x and 2.8.x before 2.8.75 allows attackers to cause a denial of service (application abort) or possibl... |
| CVE-2019-7653 | CRITICAL | 9.8 | 2.3% | Feb 9, 2019 | The Debian python-rdflib-tools 4.2.2-1 package for RDFLib 4.2.2 has CLI tools that can load Python modules from the curr... |
| CVE-2019-7651 | — | — | 4.9% | Feb 8, 2019 | EPP.sys in Emsisoft Anti-Malware prior to version 2018.12 allows an attacker to bypass ACLs because Interpreted Device C... |
| CVE-2019-1676 | MEDIUM | 6.8 | 1.8% | Feb 8, 2019 | A vulnerability in the Session Initiation Protocol (SIP) call processing of Cisco Meeting Server (CMS) software could al... |
| CVE-2019-1672 | MEDIUM | 5.8 | 1.6% | Feb 8, 2019 | A vulnerability in the Decryption Policy Default Action functionality of the Cisco Web Security Appliance (WSA) could al... |
| CVE-2019-7648 | — | — | 0.9% | Feb 8, 2019 | controller/fetchpwd.php and controller/doAction.php in Hotels_Server through 2018-11-05 rely on base64 in an attempt to ... |
| CVE-2019-1673 | MEDIUM | 5.4 | 0.8% | Feb 8, 2019 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticat... |
| CVE-2019-7639 | — | — | 1.2% | Feb 8, 2019 | An issue was discovered in gsi-openssh-server 7.9p1 on Fedora 29. If PermitPAMUserChange is set to yes in the /etc/gsiss... |
| CVE-2019-7638 | HIGH | 8.8 | 3.0% | Feb 8, 2019 | SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in Map1toN in vide... |
| CVE-2019-7637 | HIGH | 8.8 | 3.1% | Feb 8, 2019 | SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer overflow in SDL_FillRect in ... |
| CVE-2019-7636 | HIGH | 8.1 | 2.9% | Feb 8, 2019 | SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in SDL_GetRGB in v... |
| CVE-2019-7635 | HIGH | 8.1 | 3.3% | Feb 8, 2019 | SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in Blit1to4 in vid... |
| CVE-2019-7632 | — | — | 6.5% | Feb 8, 2019 | LifeSize Team, Room, Passport, and Networker 220 devices allow Authenticated Remote OS Command Injection, as demonstrate... |
| CVE-2019-6242 | — | — | 1.2% | Feb 8, 2019 | Kentico v10.0.42 allows Global Administrators to read the cleartext SMTP Password by navigating to the SMTP configuratio... |
| CVE-2019-7628 | — | — | 0.9% | Feb 8, 2019 | Pagure 5.2 leaks API keys by e-mailing them to users. Few e-mail servers validate TLS certificates, so it is easy for ma... |
| CVE-2019-7401 | — | — | 2.9% | Feb 8, 2019 | NGINX Unit before 1.7.1 might allow an attacker to cause a heap-based buffer overflow in the router process with a speci... |
| CVE-2019-6139 | CRITICAL | 9.8 | 2.4% | Feb 7, 2019 | Forcepoint User ID (FUID) server versions up to 1.2 have a remote arbitrary file upload vulnerability on TCP port 5001. ... |
| CVE-2019-1671 | MEDIUM | 6.1 | 1.2% | Feb 7, 2019 | A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an unauthen... |
| CVE-2019-1670 | MEDIUM | 6.1 | 1.2% | Feb 7, 2019 | A vulnerability in the web-based management interface of Cisco Unified Intelligence Center Software could allow an unaut... |
| CVE-2019-1661 | MEDIUM | 6.1 | 1.2% | Feb 7, 2019 | A vulnerability in the web-based management interface of Cisco TelePresence Management Suite (TMS) software could allow ... |
| CVE-2019-1680 | MEDIUM | 4.3 | 1.4% | Feb 7, 2019 | A vulnerability in Cisco Webex Business Suite could allow an unauthenticated, remote attacker to inject arbitrary text i... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now