Skip to main content

Year archive

CVEs published in 2019

Archive summary

17,305 CVEs published in 2019 — 2,593 Critical, 7,142 High, 7,228 Medium, 342 Low, 0 Unrated.

CVE-2019-5725

Published Jan 8, 2019

qibosoft through V7 allows remote attackers to read arbitrary files via the member/index.php main parameter, as demonstrated by SSRF to a URL on the same web site to read a .sql f…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-5721

Published Jan 8, 2019

In Wireshark 2.4.0 to 2.4.11, the ENIP dissector could crash. This was addressed in epan/dissectors/packet-enip.c by changing the memory-management approach so that a use-after-fr…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-5719

Published Jan 8, 2019

In Wireshark 2.6.0 to 2.6.5 and 2.4.0 to 2.4.11, the ISAKMP dissector could crash. This was addressed in epan/dissectors/packet-isakmp.c by properly handling the case of a missing…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-5718

Published Jan 8, 2019

In Wireshark 2.6.0 to 2.6.5 and 2.4.0 to 2.4.11, the RTSE dissector and other ASN.1 dissectors could crash. This was addressed in epan/charsets.c by adding a get_t61_string length…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-5717

Published Jan 8, 2019

In Wireshark 2.6.0 to 2.6.5 and 2.4.0 to 2.4.11, the P_MUL dissector could crash. This was addressed in epan/dissectors/packet-p_mul.c by rejecting the invalid sequence number of…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-0622

Published Jan 8, 2019

An elevation of privilege vulnerability exists when Skype for Andriod fails to properly handle specific authentication requests, aka "Skype for Android Elevation of Privilege Vuln…

CVSS 4.6 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2019-0588

Published Jan 8, 2019

An information disclosure vulnerability exists when the Microsoft Exchange PowerShell API grants calendar contributors more view permissions than intended, aka "Microsoft Exchange…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2019-0586

Published Jan 8, 2019

A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka "Microsoft Exchange Memory Corruption…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2019-0585

Published Jan 8, 2019

A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka "Microsoft Word Remote Code Execution Vulnerability…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2019-0584

Published Jan 8, 2019

A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka "Jet Database Engine Remote Code Execution Vulnerabilit…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2019-0583

Published Jan 8, 2019

A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka "Jet Database Engine Remote Code Execution Vulnerabilit…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2019-0582

Published Jan 8, 2019

A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka "Jet Database Engine Remote Code Execution Vulnerabilit…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2019-0581

Published Jan 8, 2019

A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka "Jet Database Engine Remote Code Execution Vulnerabilit…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2019-0580

Published Jan 8, 2019

A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka "Jet Database Engine Remote Code Execution Vulnerabilit…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2019-0579

Published Jan 8, 2019

A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka "Jet Database Engine Remote Code Execution Vulnerabilit…

CVSS 7.8 · High
evidence mentions
3
Buzz score
21.9

CVE-2019-0578

Published Jan 8, 2019

A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka "Jet Database Engine Remote Code Execution Vulnerabilit…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2019-0577

Published Jan 8, 2019

A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka "Jet Database Engine Remote Code Execution Vulnerabilit…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2019-0576

Published Jan 8, 2019

A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka "Jet Database Engine Remote Code Execution Vulnerabilit…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2019-0575

Published Jan 8, 2019

A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka "Jet Database Engine Remote Code Execution Vulnerabilit…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Showing 17,126-17,150 of 17,305 CVEsPage 686 of 693