17,305 vulnerabilities published in 2019
OpenOffice.org v3.3 allows execution of arbitrary code with the privileges of the user running the OpenOffice.org suite
xscreensaver before 5.14 crashes during activation and leaves the screen unlocked when in Blank Only Mode and when DPMS
An issue was discovered in disable_priv_mode in shell.c in GNU Bash through 5.0 patch 11. By default, if Bash is run wit
In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image, performing some operations, and unmounting can le
In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image can lead to slab-out-of-bounds write access in ind
Nova 5i pro and Nova 5 smartphones with versions earlier than 9.1.1.190(C00E190R6P2)and Versions earlier than 9.1.1.175(
P30, Mate 20, P30 Pro smartphones with software of versions earlier than ELLE-AL00B 9.1.0.193(C00E190R1P21), versions ea
Some Huawei home routers have an improper authorization vulnerability. Due to improper authorization of certain programs
Free Photo Viewer 1.3 allows remote attackers to execute arbitrary code via a crafted BMP and/or TIFF file that triggers
Trend Micro Security (Consumer) 2020 (v16.0.1221 and below) is affected by a DLL hijacking vulnerability that could allo
An issue was discovered in TitanHQ WebTitan before 5.18. It has a sudoers file that enables low-privilege users to execu
mom creates world-writable pid files in /var/run
FreeBSD: Input Validation Flaw allows local users to gain elevated privileges
DLL preloading vulnerability in Autodesk Desktop Application versions 7.0.16.29 and earlier. An attacker may trick a use
Buffer overflow vulnerability in Autodesk FBX Software Development Kit version 2019.5. A user may be tricked into openin
Max Secure Anti Virus Plus 19.0.4.020 has Insecure Permissions on the installation directory. Local attackers can replac
In the Linux kernel before 5.1.6, there is a use-after-free in serial_ir_init_module() in drivers/media/rc/serial_ir.c.
An exploitable code execution vulnerability exists in the ss-manager binary of Shadowsocks-libev 3.3.2. Specially crafte
COPA-DATA zenone32 zenon Editor through 8.10 has an Uncontrolled Search Path Element.
An unquoted service path vulnerability is reported to affect the service QVssService in QNAP NetBak Replicator. This vul
A weak malicious user can escalate its privilege whenever CatalystProductionSuite.2019.1.exe (version 1.1.0.21) and Cata
In OpenBSD 6.6, local users can use the su -L option to achieve any login class (often excluding root) because there is
xlock in OpenBSD 6.6 allows local users to gain the privileges of the auth group by providing a LIBGL_DRIVERS_PATH envir
OpenBSD 6.6, in a non-default configuration where S/Key or YubiKey authentication is enabled, allows local users to beco
In radare2 through 4.0, there is an integer overflow for the variable new_token_size in the function r_asm_massemble at
OpenDetex 2.8.5 has a Buffer Overflow in TexOpen in detex.l because of an incorrect sprintf.
An improper authentication check in Palo Alto Networks PAN-OS may allow an authenticated low privileged non-superuser cu
An authentication flaw in the AVPNC_RP service in Aviatrix VPN Client through 2.2.10 allows an attacker to gain elevated
Weak file permissions applied to the Aviatrix VPN Client through 2.2.10 installation directory on Windows and Linux allo
A Privilege Escalation vulnerability exits in Fedoraproject Sectool due to an incorrect DBus file.
In setCpuVulkanInUse of GpuStats.cpp, there is possible memory corruption due to a use after free. This could lead to lo
In createSessionInternal of PackageInstallerService.java, there is a possible improper permission grant due to a missing
In hasActivityInVisibleTask of WindowProcessController.java there’s a possible bypass of user interaction requirements d
n ihevcd_parse_slice_data of ihevcd_parse_slice.c, there is a possible out of bounds write due to a missing bounds check
In ihevcd_ref_list of ihevcd_ref_list.c, there is a possible out of bounds write due to a missing bounds check. This cou
In the Linux kernel 5.0.21, mounting a crafted ext4 filesystem image, performing some operations, and unmounting can lea
In the Linux kernel 5.0.21 and 5.3.11, mounting a crafted btrfs filesystem image, performing some operations, and then m
In the Linux kernel 5.0.21, mounting a crafted f2fs filesystem image can lead to slab-out-of-bounds read access in f2fs_
HTMLDOC 1.9.7 allows a stack-based buffer overflow in the hd_strlcpy() function in string.c (when called from render_con
radare2 through 4.0.0 lacks validation of the content variable in the function r_asm_pseudo_incbin at libr/asm/asm.c, ul
In the macho_parse_file functionality in macho/macho.c of YARA 3.11.0, command_size may be inconsistent with the real si
Stack-based buffer overflow in the m2m1shot_compat_ioctl32 function in the Samsung m2m1shot driver framework, as used in
oVirt Node: Lock screen accepts F2 to drop to shell causing privilege escalation
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly handle
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard li
An elevation of privilege vulnerability exists when the Windows Printer Service improperly validates file paths while lo
An elevation of privilege vulnerability exists when Windows improperly handles COM object creation, aka 'Windows COM Ser
An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To e
A remote code execution vulnerability exists when Microsoft Windows OLE fails to properly validate user input, aka 'Wind
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started