Skip to main content

Year archive

CVEs published in 2019

Archive summary

17,305 CVEs published in 2019 — 2,593 Critical, 7,142 High, 7,228 Medium, 342 Low, 0 Unrated.

CVE-2019-19963

Published Dec 25, 2019

An issue was discovered in wolfSSL before 4.3.0 in a non-default configuration where DSA is enabled. DSA signing uses the BEEA algorithm during modular inversion of the nonce, lea…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-19962

Published Dec 25, 2019

wolfSSL before 4.3.0 mishandles calls to wc_SignatureGenerateHash, leading to fault injection in RSA cryptography.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-19960

Published Dec 25, 2019

In wolfSSL before 4.3.0, wc_ecc_mulmod_ex does not properly resist side-channel attacks.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-5702

Published Dec 24, 2019

NVIDIA GeForce Experience, all versions prior to 3.20.2, contains a vulnerability when GameStream is enabled in which an attacker with local system access can corrupt a system fil…

CVSS 7.8 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2019-19958

Published Dec 24, 2019

In libIEC61850 1.4.0, StringUtils_createStringFromBuffer in common/string_utilities.c has an integer signedness issue that could lead to an attempted excessive memory allocation a…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-19957

Published Dec 24, 2019

In libIEC61850 1.4.0, getNumberOfElements in mms/iso_mms/server/mms_access_result.c has an out-of-bounds read vulnerability, related to bufPos and elementLength.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-10758

Published Dec 24, 2019

mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. A misuse of the `vm` dependency to perform `exec` commands in a non…

CVSS 9.9 · Critical
evidence mentions
2
Buzz score
42.5
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2019-19925

Published Dec 24, 2019

zipfileUpdate in ext/misc/zipfile.c in SQLite 3.30.1 mishandles a NULL pathname during an update of a ZIP archive.

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2019-19923

Published Dec 24, 2019

flattenSubquery in select.c in SQLite 3.30.1 mishandles certain uses of SELECT DISTINCT involving a LEFT JOIN in which the right-hand side is a view. This can cause a NULL pointer…

CVSS 7.5 · High

CVE-2019-19695

Published Dec 24, 2019

A privilege escalation vulnerability in Trend Micro Antivirus for Mac 2019 (v9.0.1379 and below) could potentially allow an attacker to create a symbolic link to a target file and…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-19952

Published Dec 24, 2019

In ImageMagick 7.0.9-7 Q16, there is a use-after-free in the function MngInfoDiscardObject of coders/png.c, related to ReadOneMNGImage.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-18211

Published Dec 23, 2019

An issue was discovered in Orckestra C1 CMS through 6.6. The EntityTokenSerializer class in Composite.dll is prone to unvalidated deserialization of wrapped BinaryFormatter payloa…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 276-300 of 17,305 CVEsPage 12 of 693