2019 CVE Vulnerabilities

17,624 CVEs published in 2019.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2019-19449HIGH7.8In the Linux kernel 5.0.21, mounting a crafted f2fs filesystem image can lead to slab-out-of-bounds read access in f2fs_...
CVE-2019-19448HIGH7.8In the Linux kernel 5.0.21 and 5.3.11, mounting a crafted btrfs filesystem image, performing some operations, and then m...
CVE-2019-19447HIGH7.8In the Linux kernel 5.0.21, mounting a crafted ext4 filesystem image, performing some operations, and unmounting can lea...
CVE-2019-2232HIGH7.5In handleRun of TextLine.java, there is a possible application crash due to improper input validation. This could lead t...
CVE-2019-2230HIGH7.5In nfcManager_routeAid and nfcManager_unrouteAid of NativeNfcManager.cpp, there is possible memory reuse due to a use af...
CVE-2019-2225HIGH8.8When pairing with a Bluetooth device, it may be possible to pair a malicious device without any confirmation from the us...
CVE-2019-2223HIGH7.8In ihevcd_ref_list of ihevcd_ref_list.c, there is a possible out of bounds write due to a missing bounds check. This cou...
CVE-2019-2222HIGH7.8n ihevcd_parse_slice_data of ihevcd_parse_slice.c, there is a possible out of bounds write due to a missing bounds check...
CVE-2019-2221HIGH7.8In hasActivityInVisibleTask of WindowProcessController.java there’s a possible bypass of user interaction requirements d...
CVE-2019-2218HIGH7.8In createSessionInternal of PackageInstallerService.java, there is a possible improper permission grant due to a missing...
CVE-2019-2217HIGH7.8In setCpuVulkanInUse of GpuStats.cpp, there is possible memory corruption due to a use after free. This could lead to lo...
CVE-2019-18575HIGH7.1Dell Command Configure versions prior to 4.2.1 contain an uncontrolled search path vulnerability. A locally authenticate...
CVE-2019-18672HIGH7.5Insufficient checks in the finite state machine of the ShapeShift KeepKey hardware wallet before firmware 6.2.2 allow a ...
CVE-2019-12734HIGH8.8SiteVision 4 has Incorrect Access Control.
CVE-2019-12733HIGH8.8SiteVision 4 allows Remote Code Execution.
CVE-2019-19609HIGH7.2The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin c...
CVE-2019-16770HIGH7.5In Puma before versions 3.12.2 and 4.3.1, a poorly-behaved client could use keepalive requests to monopolize Puma's reac...
CVE-2019-5098HIGH8.6An exploitable out-of-bounds read vulnerability exists in AMD ATIDXX64.DLL driver, version 26.20.13001.29010. A speciall...
CVE-2019-17388HIGH7.8Weak file permissions applied to the Aviatrix VPN Client through 2.2.10 installation directory on Windows and Linux allo...
CVE-2019-17387HIGH7.8An authentication flaw in the AVPNC_RP service in Aviatrix VPN Client through 2.2.10 allows an attacker to gain elevated...
CVE-2019-3690HIGH7.8The chkstat tool in the permissions package followed symlinks before commit a9e1d26cd49ef9ee0c2060c859321128a6dd4230 (pl...
CVE-2019-19007HIGH7.2Intelbras IWR 3000N 1.8.7 devices allow disclosure of the administrator login name and password because v1/system/user i...
CVE-2019-18180HIGH7.5Improper Check for filenames with overly long extensions in PostMaster (sending in email) or uploading files (e.g. attac...
CVE-2019-17437HIGH7.8An improper authentication check in Palo Alto Networks PAN-OS may allow an authenticated low privileged non-superuser cu...
CVE-2019-19601HIGH7.8OpenDetex 2.8.5 has a Buffer Overflow in TexOpen in detex.l because of an incorrect sprintf.

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now