2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-20822CRITICAL9.8An issue was discovered in the 3D Plugin Beta for Foxit Reader and PhantomPDF before 9.7.0.29430. It has an out-of-bound...
CVE-2019-20821HIGH7.5An issue was discovered in Foxit PhantomPDF Mac before 3.4. It has a NULL pointer dereference.
CVE-2019-20820HIGH7.5An issue was discovered in Foxit Reader and PhantomPDF before 9.7. It has a NULL pointer dereference during the parsing ...
CVE-2019-20819HIGH7.5An issue was discovered in Foxit Reader and PhantomPDF before 9.7. It allows stack consumption via nested function calls...
CVE-2019-20818HIGH7.5An issue was discovered in Foxit Reader and PhantomPDF before 9.7. It allows memory consumption because data is created ...
CVE-2019-20817HIGH7.5An issue was discovered in Foxit Reader and PhantomPDF before 9.7. It has a NULL pointer dereference.
CVE-2019-20816HIGH7.5An issue was discovered in Foxit PhantomPDF before 8.3.12. It has a NULL pointer dereference during the parsing of file ...
CVE-2019-20815HIGH7.5An issue was discovered in Foxit PhantomPDF before 8.3.12. It allows stack consumption via nested function calls for XML...
CVE-2019-20814HIGH7.5An issue was discovered in Foxit PhantomPDF before 8.3.12. It allows memory consumption because data is created for each...
CVE-2019-20813HIGH7.5An issue was discovered in Foxit PhantomPDF before 8.3.12. It has a NULL pointer dereference.
CVE-2019-16385MEDIUM6.1Cybele Thinfinity VirtualUI 2.5.17.2 allows HTTP response splitting via the mimetype parameter within a PDF viewer reque...
CVE-2019-16384MEDIUM6.5Cybele Thinfinity VirtualUI 2.5.17.2 allows ../ path traversal that can be used for data exfiltration. This enables file...
CVE-2019-16150MEDIUM5.5Use of a hard-coded cryptographic key to encrypt security sensitive data in local storage and configuration in FortiClie...
CVE-2019-20809HIGH7.5The price oracle in PriceOracle.sol in Compound Finance Compound Price Oracle 1.0 through 2.0 allows a price poster to s...
CVE-2019-19214Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2019-19213Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2019-20812MEDIUM5.5An issue was discovered in the Linux kernel before 5.4.7. The prb_calc_retire_blk_tmo() function in net/packet/af_packet...
CVE-2019-20811MEDIUM5.5An issue was discovered in the Linux kernel before 5.0.6. In rx_queue_add_kobject() and netdev_queue_add_kobject() in ne...
CVE-2019-20810MEDIUM5.5go7007_snd_init in drivers/media/usb/go7007/snd-go7007.c in the Linux kernel before 5.6 does not call snd_card_free for ...
CVE-2019-11843MEDIUM6.1The MailPoet plugin before 3.23.2 for WordPress allows remote attackers to inject arbitrary web script or HTML using ext...
CVE-2019-17603HIGH7.8Ene.sys in Asus Aura Sync through 1.07.71 does not properly validate input to IOCTL 0x80102044, 0x80102050, and 0x801020...
CVE-2019-14087HIGH7.8Failure in buffer management while accessing handle for HDR blit when color modes not supported by display in Snapdragon...
CVE-2019-14078HIGH7.8Out of bound memory access while processing qpay due to not validating length of the response buffer provided by User. i...
CVE-2019-14077HIGH7.8Out of bound memory access while processing ese transmit command due to passing Response buffer received from user in Sn...
CVE-2019-14067MEDIUM5.5Using non-time-constant functions like memcmp to compare sensitive data can lead to information leakage through timing s...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now