17,305 vulnerabilities published in 2019
OpenStack nova base images permissions are world readable
An Information Disclosure vulnerability exists in the Jasig Project php-pear-CAS 1.2.2 package in the /tmp directory. Th
In checkOperation of AppOpsService.java, there is a possible bypass of user interaction requirements due to mishandling
In device_class_to_int of device_class.cc, there is a possible out of bounds read due to improper casting. This could le
In array_find of array.c, there is a possible out-of-bounds read due to an incorrect bounds check. This could lead to lo
In updateWidget of BaseWidgetProvider.java, there is a possible leak of user data due to a missing permission check. Thi
In various functions of RecentLocationApps.java, DevicePolicyManagerService.java, and RecognitionService.java, there is
alter.c in SQLite through 3.30.1 allows attackers to trigger infinite recursion via certain types of self-referential vi
Perl module Data::UUID from CPAN version 1.219 vulnerable to symlink attacks
An information disclosure vulnerability exists in Microsoft Access software when the software fails to properly handle o
An information disclosure vulnerability exists in Microsoft Access software when the software fails to properly handle o
An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka
An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Wi
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Window
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Window
make_arrow in arrow.c in Xfig fig2dev 3.2.7b allows a segmentation fault and out-of-bounds write because of an integer o
Use after free issue occurs when command destructors access dynamically allocated response buffer which is already deall
An unprivileged application can allocate GPU memory by calling memory allocation ioctl function and can exhaust all the
Null pointer dereference issue in kernel due to missing check related to LLC support in GPU in Snapdragon Auto, Snapdrag
Driver may access an invalid address while processing IO control due to lack of check of address validation in Snapdrago
A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0), Control Center Server (CCS)
The Linux kernel before 5.4.2 mishandles ext4_expand_extra_isize, as demonstrated by use-after-free errors in __ext4_exp
rubygem-hammer_cli_foreman: File /etc/hammer/cli.modules.d/foreman.yml world readable
There is a path traversal vulnerability in several Huawei smartphones. The system does not sufficiently validate certain
Certain Huawei products (AP2000;IPS Module;NGFW Module;NIP6300;NIP6600;NIP6800;S5700;SVN5600;SVN5800;SVN5800-C;SeMG9811;
Certain Huawei products (AP2000;IPS Module;NGFW Module;NIP6300;NIP6600;NIP6800;S5700;SVN5600;SVN5800;SVN5800-C;SeMG9811;
Certain Huawei products (AP2000;IPS Module;NGFW Module;NIP6300;NIP6600;NIP6800;S5700;SVN5600;SVN5800;SVN5800-C;SeMG9811;
Certain Huawei products (AP2000;IPS Module;NGFW Module;NIP6300;NIP6600;NIP6800;S5700;SVN5600;SVN5800;SVN5800-C;SeMG9811;
read_colordef in read.c in Xfig fig2dev 3.2.7b has an out-of-bounds write.
CFME (CloudForms Management Engine) 5: RHN account information is logged to top_output.log during registration
IBM API Connect 2018.1 through 2018.4.1.7 Developer Portal's user registration page does not disable password autocomple
Insufficient memory protection for Intel(R) Ethernet I218 Adapter driver for Windows* 10 before version 24.1 may allow a
Improper conditions check in the Linux kernel driver for the Intel(R) FPGA SDK for OpenCL(TM) Pro Edition before version
Null pointer dereference in the FPGA kernel driver for Intel(R) Quartus(R) Prime Pro Edition before version 19.3 may all
The JBIG2Decode library in npdf.dll in Nitro Free PDF Reader 12.0.0.112 has a CAPPDAnnotHandlerUtils::PDAnnotHandlerDest
In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image, performing some operations, and then making a syn
In the Linux kernel 5.0.21, mounting a crafted f2fs filesystem image can cause a NULL pointer dereference in f2fs_recove
Docker Engine before 1.8.3 and CS Docker Engine before 1.6.2-CS7 do not use a globally unique identifier to store image
Jenkins Weibo Plugin 1.0.1 and earlier stores credentials unencrypted in its global configuration file on the Jenkins ma
Possibility of Null pointer access if the SPDM commands are executed in the non-standard way in Trustzone in Snapdragon
An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in S
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 12.2, macOS Mojave 10.
A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 12.2, macOS Mojave
Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Mojave 10.
An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Mojave 10.14.4. An appli
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Mojave 10.14.4. A malici
This issue was addressed with improved checks. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4. A malicious applic
A logic issue was addressed with improved state management. This issue is fixed in macOS Mojave 10.14.4. An encrypted vo
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started