17,305 vulnerabilities published in 2019
Vulnerability in the Data Store component of Oracle Berkeley DB. Supported versions that are affected are 12.1.6.1.23, 1
Possible race condition that will cause a use-after-free when writing to two sysfs entries at nearly the same time in Sn
Race condition while accessing DMA buffer in jpeg driver in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consume
An elevation of privilege vulnerability exists in the way that the PsmServiceExtHost.dll handles objects in memory. An a
An elevation of privilege vulnerability exists in the way that the PsmServiceExtHost.dll handles objects in memory. An a
An elevation of privilege vulnerability exists in the way that the psmsrv.dll handles objects in memory. An attacker who
An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory. An attacker who succes
An elevation of privilege vulnerability exists in the way that the rpcss.dll handles objects in memory. An attacker who
An elevation of privilege vulnerability exists in the way that the ssdpsrv.dll handles objects in memory. An attacker wh
An elevation of privilege vulnerability exists in the way that the unistore.dll handles objects in memory. An attacker w
An elevation of privilege vulnerability exists in the way that the wcmsvc.dll handles objects in memory. An attacker who
An elevation of privilege vulnerability exists in the way that the wcmsvc.dll handles objects in memory. An attacker who
An issue was discovered in drivers/net/ethernet/arc/emac_main.c in the Linux kernel before 4.5. A use-after-free is caus
An unauthenticated privilege escalation exists in SailPoint Desktop Password Reset 7.2. A user with local access to only
In ActivityManagerService.attachApplication of ActivityManagerService, there is a possible race condition. This could le
Valve Steam Client for Windows through 2019-08-20 has weak folder permissions, leading to privilege escalation (to NT AU
Apport before versions 2.14.1-0ubuntu3.29+esm1, 2.20.1-0ubuntu2.19, 2.20.9-0ubuntu7.7, 2.20.10-0ubuntu27.1, 2.20.11-0ubu
An issue was discovered in the Linux kernel before 5.0.5. There is a use-after-free issue when hci_uart_register_dev() f
In the Android kernel in the video driver there is a use after free due to a race condition. This could lead to local es
An issue was discovered in GitLab Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. The
The Mozilla Maintenance Service does not guard against files being hardlinked to another file in the updates directory,
Possible use-after-free issue due to a race condition while calling camera ioctl concurrently in Snapdragon Compute, Sna
The command-line argument parser in tcpdump before 4.9.3 has a buffer overflow in tcpdump.c:get_next_file().
An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privil
Postgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via superuser writing pas
An issue was discovered in drivers/media/platform/vivid in the Linux kernel through 5.3.8. It is exploitable for privile
Sudo through 1.8.29 allows local users to escalate to root if they have write access to file descriptor 3 of the sudo pr
Medtronic Valleylab Exchange Client version 3.4 and below, Valleylab FT10 Energy Platform (VLFT10GEN) software version 4
An elevation of privilege vulnerability exists due to a race condition in Windows Subsystem for Linux, aka 'Windows Subs
Race condition due to the lack of resource lock which will be concurrently modified in the memcpy statement leads to out
xcfa before 5.0.1 creates temporary files insecurely which could allow local users to launch a symlink attack and overwr
AsLdrSrv.exe in ASUS ATK Package before V1.0.0061 (for Windows 10 notebook PCs) could lead to unsigned code execution wi
A race condition was addressed with additional validation. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4. A mali
A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. T
When Apache Tomcat 9.0.0.M1 to 9.0.28, 8.5.0 to 8.5.47, 7.0.0 and 7.0.97 is configured with the JMX Remote Lifecycle Lis
Vulnerability in the Oracle Web Cache component of Oracle Fusion Middleware (subcomponent: ESI/Partial Page Caching). Th
DLL Search Order Hijacking vulnerability in Microsoft Windows client in McAfee Total Protection (MTP) Free Antivirus Tri
Yamaha routers RT57i Rev.8.00.95 and earlier, RT58i Rev.9.01.51 and earlier, NVR500 Rev.11.00.36 and earlier, RTX810 Rev
Yamaha routers RT57i Rev.8.00.95 and earlier, RT58i Rev.9.01.51 and earlier, NVR500 Rev.11.00.36 and earlier, RTX810 Rev
BN-SDWBP3 firmware version 1.0.9 and earlier allows attacker with administrator rights on the same network segment to ex
Buffer overflow in BN-SDWBP3 firmware version 1.0.9 and earlier allows an attacker on the same network segment to execut
A vulnerability in the TCP socket code of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker
An improper authorization flaw was found in the Smart Class feature of Foreman. An attacker can use it to change configu
A vulnerability in the one-x Portal component of IP Office could allow an authenticated user to perform stored cross sit
An issue was discovered in OpenSSH 7.9. Due to missing character encoding in the progress display, a malicious server (o
In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-T
IBM Tivoli Application Dependency Discovery Manager 7.2.2 and 7.3 could expose password hashes in stored in system memor
BD FACSLyric Research Use Only, Windows 10 Professional Operating System, U.S. and Malaysian Releases, between November
A vulnerability in the Session Initiation Protocol (SIP) call processing of Cisco Meeting Server (CMS) software could al
The British Airways Entertainment System, as installed on Boeing 777-36N(ER) and possibly other aircraft, does not preve
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started