2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-6444An issue was discovered in NTPsec before 1.1.3. process_control() in ntp_control.c has a stack-based buffer over-read be...
CVE-2019-6443An issue was discovered in NTPsec before 1.1.3. Because of a bug in ctl_getitem, there is a stack-based buffer over-read...
CVE-2019-6442An issue was discovered in NTPsec before 1.1.3. An authenticated attacker can write one byte out of bounds in ntpd via a...
CVE-2019-6440Zemana AntiMalware before 3.0.658 Beta mishandles update logic.
CVE-2019-6439examples/benchmark/tls_bench.c in a benchmark tool in wolfSSL through 3.15.7 has a heap-based buffer overflow.
CVE-2019-3557The implementations of streams for bz2 and php://output improperly implemented their readImpl functions, returning -1 co...
CVE-2019-3554Wangle's AcceptRoutingHandler incorrectly casts a socket when accepting a TLS 1.3 connection, leading to a potential den...
CVE-2019-0030HIGH7.2Juniper ATP uses DES and a hardcoded salt for password hashing, allowing for trivial de-hashing of the password file con...
CVE-2019-0029HIGH8.8Juniper ATP Series Splunk credentials are logged in a file readable by authenticated local users. Using these credential...
CVE-2019-0027MEDIUM5.4A persistent cross-site scripting (XSS) vulnerability in the Snort Rules configuration of Juniper ATP may allow authenti...
CVE-2019-0026MEDIUM5.4A persistent cross-site scripting (XSS) vulnerability in the Zone configuration of Juniper ATP may allow authenticated u...
CVE-2019-0025MEDIUM5.4A persistent cross-site scripting (XSS) vulnerability in RADIUS configuration menu of Juniper ATP may allow authenticate...
CVE-2019-0024MEDIUM5.4A persistent cross-site scripting (XSS) vulnerability in the Email Collectors menu of Juniper ATP may allow authenticate...
CVE-2019-0023MEDIUM5.4A persistent cross-site scripting (XSS) vulnerability in the Golden VM menu of Juniper ATP may allow authenticated user ...
CVE-2019-0022CRITICAL10Juniper ATP ships with hard coded credentials in the Cyphort Core instance which gives an attacker the ability to take f...
CVE-2019-0021HIGH7.1On Juniper ATP, secret passphrase CLI inputs, such as "set mcm", are logged to /var/log/syslog in clear text, allowing a...
CVE-2019-0020CRITICAL10Juniper ATP ships with hard coded credentials in the Web Collector instance which gives an attacker the ability to take ...
CVE-2019-0018MEDIUM5.4A persistent cross-site scripting (XSS) vulnerability in the file upload menu of Juniper ATP may allow an authenticated ...
CVE-2019-0017MEDIUM6.5The Junos Space application, which allows Device Image files to be uploaded, has insufficient validity checking which ma...
CVE-2019-0016MEDIUM6.5A malicious authenticated user may be able to delete a device from the Junos Space database without the necessary privil...
CVE-2019-0015MEDIUM5.4A vulnerability in the SRX Series Service Gateway allows deleted dynamic VPN users to establish dynamic VPN connections ...
CVE-2019-0014HIGH7.5On QFX and PTX Series, receipt of a malformed packet for J-Flow sampling might crash the FPC (Flexible PIC Concentrator)...
CVE-2019-0013MEDIUM6.5The routing protocol daemon (RPD) process will crash and restart when a specific invalid IPv4 PIM Join packet is receive...
CVE-2019-0012HIGH7.5A Denial of Service (DoS) vulnerability in BGP in Juniper Networks Junos OS configured as a VPLS PE allows an attacker t...
CVE-2019-0011MEDIUM6.5The Junos OS kernel crashes after processing a specific incoming packet to the out of band management interface (such as...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now