2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-6444 | — | — | 45.7% | Jan 16, 2019 | An issue was discovered in NTPsec before 1.1.3. process_control() in ntp_control.c has a stack-based buffer over-read be... |
| CVE-2019-6443 | — | — | 66.9% | Jan 16, 2019 | An issue was discovered in NTPsec before 1.1.3. Because of a bug in ctl_getitem, there is a stack-based buffer over-read... |
| CVE-2019-6442 | — | — | 13.7% | Jan 16, 2019 | An issue was discovered in NTPsec before 1.1.3. An authenticated attacker can write one byte out of bounds in ntpd via a... |
| CVE-2019-6440 | — | — | 3.0% | Jan 16, 2019 | Zemana AntiMalware before 3.0.658 Beta mishandles update logic. |
| CVE-2019-6439 | — | — | 2.6% | Jan 16, 2019 | examples/benchmark/tls_bench.c in a benchmark tool in wolfSSL through 3.15.7 has a heap-based buffer overflow. |
| CVE-2019-3557 | — | — | 1.7% | Jan 15, 2019 | The implementations of streams for bz2 and php://output improperly implemented their readImpl functions, returning -1 co... |
| CVE-2019-3554 | — | — | 1.1% | Jan 15, 2019 | Wangle's AcceptRoutingHandler incorrectly casts a socket when accepting a TLS 1.3 connection, leading to a potential den... |
| CVE-2019-0030 | HIGH | 7.2 | 0.5% | Jan 15, 2019 | Juniper ATP uses DES and a hardcoded salt for password hashing, allowing for trivial de-hashing of the password file con... |
| CVE-2019-0029 | HIGH | 8.8 | 0.3% | Jan 15, 2019 | Juniper ATP Series Splunk credentials are logged in a file readable by authenticated local users. Using these credential... |
| CVE-2019-0027 | MEDIUM | 5.4 | 0.6% | Jan 15, 2019 | A persistent cross-site scripting (XSS) vulnerability in the Snort Rules configuration of Juniper ATP may allow authenti... |
| CVE-2019-0026 | MEDIUM | 5.4 | 0.6% | Jan 15, 2019 | A persistent cross-site scripting (XSS) vulnerability in the Zone configuration of Juniper ATP may allow authenticated u... |
| CVE-2019-0025 | MEDIUM | 5.4 | 0.6% | Jan 15, 2019 | A persistent cross-site scripting (XSS) vulnerability in RADIUS configuration menu of Juniper ATP may allow authenticate... |
| CVE-2019-0024 | MEDIUM | 5.4 | 0.6% | Jan 15, 2019 | A persistent cross-site scripting (XSS) vulnerability in the Email Collectors menu of Juniper ATP may allow authenticate... |
| CVE-2019-0023 | MEDIUM | 5.4 | 0.5% | Jan 15, 2019 | A persistent cross-site scripting (XSS) vulnerability in the Golden VM menu of Juniper ATP may allow authenticated user ... |
| CVE-2019-0022 | CRITICAL | 10 | 1.1% | Jan 15, 2019 | Juniper ATP ships with hard coded credentials in the Cyphort Core instance which gives an attacker the ability to take f... |
| CVE-2019-0021 | HIGH | 7.1 | 0.3% | Jan 15, 2019 | On Juniper ATP, secret passphrase CLI inputs, such as "set mcm", are logged to /var/log/syslog in clear text, allowing a... |
| CVE-2019-0020 | CRITICAL | 10 | 1.6% | Jan 15, 2019 | Juniper ATP ships with hard coded credentials in the Web Collector instance which gives an attacker the ability to take ... |
| CVE-2019-0018 | MEDIUM | 5.4 | 0.5% | Jan 15, 2019 | A persistent cross-site scripting (XSS) vulnerability in the file upload menu of Juniper ATP may allow an authenticated ... |
| CVE-2019-0017 | MEDIUM | 6.5 | 1.1% | Jan 15, 2019 | The Junos Space application, which allows Device Image files to be uploaded, has insufficient validity checking which ma... |
| CVE-2019-0016 | MEDIUM | 6.5 | 0.9% | Jan 15, 2019 | A malicious authenticated user may be able to delete a device from the Junos Space database without the necessary privil... |
| CVE-2019-0015 | MEDIUM | 5.4 | 0.8% | Jan 15, 2019 | A vulnerability in the SRX Series Service Gateway allows deleted dynamic VPN users to establish dynamic VPN connections ... |
| CVE-2019-0014 | HIGH | 7.5 | 1.7% | Jan 15, 2019 | On QFX and PTX Series, receipt of a malformed packet for J-Flow sampling might crash the FPC (Flexible PIC Concentrator)... |
| CVE-2019-0013 | MEDIUM | 6.5 | 1.7% | Jan 15, 2019 | The routing protocol daemon (RPD) process will crash and restart when a specific invalid IPv4 PIM Join packet is receive... |
| CVE-2019-0012 | HIGH | 7.5 | 1.7% | Jan 15, 2019 | A Denial of Service (DoS) vulnerability in BGP in Juniper Networks Junos OS configured as a VPLS PE allows an attacker t... |
| CVE-2019-0011 | MEDIUM | 6.5 | 0.6% | Jan 15, 2019 | The Junos OS kernel crashes after processing a specific incoming packet to the out of band management interface (such as... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now