Skip to main content

Year archive

CVEs published in 2019

Archive summary

17,305 CVEs published in 2019 — 2,593 Critical, 7,142 High, 7,228 Medium, 342 Low, 0 Unrated.

CVE-2018-16072

Published Jan 9, 2019

A missing origin check related to HLS manifests in Blink in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to bypass same origin policy via a crafted HTML page.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-15428

Published Jan 9, 2019

Insufficient data validation in V8 builtins string generator could lead to out of bounds read and write access in V8 in Google Chrome prior to 62.0.3202.94 and allowed a remote at…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-15405

Published Jan 9, 2019

Inappropriate symlink handling and a race condition in the stateful recovery feature implementation could lead to a persistance established by a malicious code running with root p…

CVSS 7.0 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2017-15404

Published Jan 9, 2019

An ability to process crash dumps under root privileges and inappropriate symlinks handling could lead to a local privilege escalation in Crash Reporting in Google Chrome on Chrom…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2017-15403

Published Jan 9, 2019

Insufficient data validation in crosh could lead to a command injection under chronos privileges in Networking in Google Chrome on Chrome OS prior to 61.0.3163.113 allowed a local…

CVSS 7.3 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2017-15402

Published Jan 9, 2019

Using an ID that can be controlled by a compromised renderer which allows any frame to overwrite the page_state of any other frame in the same process in Navigation in Google Chro…

CVSS 9.6 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2017-15401

Published Jan 9, 2019

A memory corruption bug in WebAssembly could lead to out of bounds read and write through V8 in WebAssembly in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to exe…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-10403

Published Jan 9, 2019

Insufficient data validation on image data in PDFium in Google Chrome prior to 51.0.2704.63 allowed a remote attacker to perform an out of bounds memory read via a crafted PDF fil…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-5748

Published Jan 9, 2019

In Traccar Server version 4.2, protocol/SpotProtocolDecoder.java might allow XXE attacks.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-5747

Published Jan 9, 2019

An issue was discovered in BusyBox through 1.30.0. An out of bounds read in udhcp components (consumed by the DHCP client, server, and/or relay) might allow a remote attacker to l…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-20679

Published Jan 9, 2019

An issue was discovered in BusyBox before 1.30.0. An out of bounds read in udhcp components (consumed by the DHCP server, client, and relay) allows a remote attacker to leak sensi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-3581

Published Jan 9, 2019

Improper input validation in the proxy component of McAfee Web Gateway 7.8.2.0 and later allows remote attackers to cause a denial of service via a crafted HTTP request parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-10735

Published Jan 9, 2019

In Bootstrap 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute, a different vulnerability than CVE-2018-14041.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 17,101-17,125 of 17,305 CVEsPage 685 of 693