17,305 vulnerabilities published in 2019
Trusted Boot (tboot) before 1.8.2 has a 'loader.c' Security Bypass Vulnerability
surf: cookie jar has read access from other local user
uzbl: Information disclosure via world-readable cookies storage file
foomatic-rip filter, all versions, used insecurely creates temporary files for storage of PostScript data by rendering t
foomatic-rip filter v4.0.12 and prior used insecurely creates temporary files for storage of PostScript data by renderin
tuned 2.10.0 creates its PID file with insecure permissions which allows local users to kill arbitrary processes.
The keyring DB in GnuPG before 2.1.2 does not properly handle invalid packets, which allows remote attackers to cause a
kbx/keybox-search.c in GnuPG before 1.4.19, 2.0.x before 2.0.27, and 2.1.x before 2.1.2 does not properly handle bitwise
Pidgin 2.10.0 uses DBUS for certain cleartext communication, which allows local users to obtain sensitive information vi
btrfs_root_node in fs/btrfs/ctree.c in the Linux kernel through 5.3.12 allows a NULL pointer dereference because rcu_der
__btrfs_free_extent in fs/btrfs/extent-tree.c in the Linux kernel through 5.3.12 calls btrfs_print_leaf in a certain ENO
ext4_empty_dir in fs/ext4/namei.c in the Linux kernel through 5.3.12 allows a NULL pointer dereference because ext4_read
The Ruby net-ldap gem before 0.11 uses a weak salt when generating SSHA passwords.
Ruby gem openshift-origin-node before 2014-02-14 does not contain a cronjob timeout which could result in a denial of se
python-rply before 0.7.4 insecurely creates temporary files.
Use after free issue in Xtra daemon shutdown due to static object instance getting freed from a multiple places in Snapd
Improper validation for loop variable received from firmware can lead to out of bound access in WLAN function while iter
A clear text storage of sensitive information vulnerability in FortiClient for Mac may allow a local attacker to read se
Jenkins Spira Importer Plugin 3.2.2 and earlier stores credentials unencrypted in its global configuration file on the J
Information disclosure due to lack of address range check done on the SysDBG buffers in SDI code. in Snapdragon Auto, Sn
Non Secure Kernel can cause Trustzone to do an arbitrary memory read which will result into DOS in Snapdragon Auto, Snap
Subsequent use of the CBO listener may result in further memory corruption due to use after free issue. in Snapdragon Au
In Libarchive 3.4.0, archive_wstring_append_from_mbs in archive_string.c has an out-of-bounds read because of an incorre
In the AppleTalk subsystem in the Linux kernel before 5.1, there is a potential NULL pointer dereference because registe
An issue was discovered in Eracent EDA, EPA, EPM, EUA, FLW, and SUM Agent through 10.2.26. The agent executable, when in
Claws Mail vCalendar plugin: credentials exposed on interface
A flaw was found in the Linux kernel's Bluetooth implementation of UART, all versions kernel 3.x.x before 4.18.0 and ker
thttpd has a local DoS vulnerability via specially-crafted .htpasswd files
libuser has information disclosure when moving user's home directory
Insufficient validation of untrusted input in intents in Google Chrome on Android prior to 78.0.3904.70 allowed a local
Use after free in PDFium in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to potentially exploit heap co
Use after free in PDFium in Google Chrome prior to 76.0.3809.100 allowed a remote attacker to potentially exploit heap c
In text_to_glyphs in sushi-font-widget.c in gnome-font-viewer 3.34.0, there is a NULL pointer dereference while parsing
The BIG-IP APM Edge Client for macOS bundled with BIG-IP APM 15.0.0-15.0.1, 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.1.0-13.
P30, P30 Pro, Mate 20 smartphones with software of versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1), versions ear
There is an improper access control vulnerability in Huawei Share. The software does not properly restrict access to cer
P30 smartphones with versions earlier than ELLE-AL00B 9.1.0.193(C00E190R1P21) have an out of bounds read vulnerability.
P30, P30 Pro, Mate 20 smartphones with software of versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1), versions ear
HiSuite with 9.1.0.305 and earlier versions and 9.1.0.305(MAC) and earlier versions and HwBackup with earlier versions b
Huawei Atlas 300, Atlas 500 have a buffer overflow vulnerability. A local, authenticated attacker may craft specific par
When GNOME Dia before 2019-11-27 is launched with a filename argument that is not a valid codepoint in the current encod
relay_open in kernel/relay.c in the Linux kernel through 5.4.1 allows local users to cause a denial of service (such as
An issue was discovered in OpenSC through 0.19.0 and 0.20.x through 0.20.0-rc3. libopensc/card-setcos.c has an incorrect
SMPlayer 19.5.0 has a buffer overflow via a long .m3u file.
An issue was discovered in SALTO ProAccess SPACE 5.4.3.0. The product's webserver runs as a Windows service with local S
Dell Command Update versions prior to 3.1 contain an Arbitrary File Deletion Vulnerability. A local authenticated malici
Dell Command Update versions prior to 3.1 contain an Arbitrary File Deletion Vulnerability. A local authenticated malici
The XML content type entity deserializer in Apache Olingo versions 4.0.0 to 4.6.0 is not configured to deny the resoluti
read_textobject in read.c in Xfig fig2dev 3.2.7b has a stack-based buffer overflow because of an incorrect sscanf.
OpenShift haproxy cartridge: predictable /tmp in set-proxy connection hook which could facilitate DoS
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started