2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2019-9536MEDIUM6.8Apple iPhone 3GS bootrom malloc implementation returns a non-NULL pointer when unable to allocate memory, aka 'alloc8'. ...
CVE-2019-17445MEDIUM5.5An issue was discovered in Eracent EDA, EPA, EPM, EUA, FLW, and SUM Agent through 10.2.26. The agent executable, when in...
CVE-2019-15652MEDIUM6.1The web interface for NSSLGlobal SatLink VSAT Modem Unit (VMU) devices before 18.1.0 doesn't properly sanitize input for...
CVE-2019-18790MEDIUM6.5An issue was discovered in channels/chan_sip.c in Sangoma Asterisk 13.x before 13.29.2, 16.x before 16.6.2, and 17.x bef...
CVE-2019-4570MEDIUM5.3IBM Tivoli Netcool Impact 7.1.0 through 7.1.0.16 generates an error message that includes sensitive information about it...
CVE-2019-4569MEDIUM5.4IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.16 is vulnerable to cross-site scripting. This vulnerability allows user...
CVE-2019-4243MEDIUM4.4IBM SmartCloud Analytics 1.3.1 through 1.3.5 allows unauthorized disclosure of information like accessing solrconfig.xml...
CVE-2019-4216MEDIUM4.6IBM SmartCloud Analytics 1.3.1 through 1.3.5 is vulnerable to possible host header injection attack that could lead to H...
CVE-2019-4215MEDIUM6.1IBM SmartCloud Analytics 1.3.1 through 1.3.5 could allow a remote attacker to hijack the clicking action of the victim. ...
CVE-2019-3428MEDIUM6.5The version V6.01.03.01 of ZTE ZXCDN IAMWEB product is impacted by a configuration error vulnerability. An attacker coul...
CVE-2019-19227MEDIUM5.5In the AppleTalk subsystem in the Linux kernel before 5.1, there is a potential NULL pointer dereference because registe...
CVE-2019-10206MEDIUM6.5ansible-playbook -k and ansible cli tools, all versions 2.8.x before 2.8.4, all 2.7.x before 2.7.13 and all 2.6.x before...
CVE-2019-10203MEDIUM4.3PowerDNS Authoritative daemon , pdns versions 4.0.x before 4.0.9, 4.1.x before 4.1.11, exiting when encountering a seria...
CVE-2019-19221MEDIUM5.5In Libarchive 3.4.0, archive_wstring_append_from_mbs in archive_string.c has an out-of-bounds read because of an incorre...
CVE-2019-18890MEDIUM6.5A SQL injection vulnerability in Redmine through 3.2.9 and 3.3.x before 3.3.10 allows Redmine users to access protected ...
CVE-2019-18886MEDIUM5.3An issue was discovered in Symfony 4.2.0 to 4.2.11 and 4.3.0 to 4.3.7. The ability to enumerate users was possible due t...
CVE-2019-6693MEDIUM6.5Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacke...
CVE-2019-2336MEDIUM5.5Subsequent use of the CBO listener may result in further memory corruption due to use after free issue. in Snapdragon Au...
CVE-2019-2318MEDIUM5.5Non Secure Kernel can cause Trustzone to do an arbitrary memory read which will result into DOS in Snapdragon Auto, Snap...
CVE-2019-2295MEDIUM5.5Information disclosure due to lack of address range check done on the SysDBG buffers in SDI code. in Snapdragon Auto, Sn...
CVE-2019-16547MEDIUM4.3Missing permission checks in various API endpoints in Jenkins Google Compute Engine Plugin 4.1.1 and earlier allow attac...
CVE-2019-16546MEDIUM5.9Jenkins Google Compute Engine Plugin 4.1.1 and earlier does not verify SSH host keys when connecting agents created by t...
CVE-2019-16545MEDIUM6.5Jenkins QMetry for JIRA - Test Management Plugin transmits credentials in its configuration in plain text as part of job...
CVE-2019-16543MEDIUM5.5Jenkins Spira Importer Plugin 3.2.2 and earlier stores credentials unencrypted in its global configuration file on the J...
CVE-2019-16542MEDIUM6.5Jenkins Anchore Container Image Scanner Plugin 1.0.19 and earlier stores credentials unencrypted in job config.xml files...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now