17,305 vulnerabilities published in 2019
While deserializing any key blob during key operations, buffer overflow could occur exposing partial key information if
MySQL-GUI-tools (mysql-administrator) leaks passwords into process list after with launch of mysql text console
A memory leak in the ql_alloc_large_buffers() function in drivers/net/ethernet/qlogic/qla3xxx.c in the Linux kernel befo
A memory leak in the ccp_run_sha_cmd() function in drivers/crypto/ccp/ccp-ops.c in the Linux kernel through 5.3.9 allows
A memory leak in the sof_set_get_large_ctrl_data() function in sound/soc/sof/ipc.c in the Linux kernel through 5.3.9 all
ldap-git-backup before 1.0.4 exposes password hashes due to incorrect directory permissions.
Eximious Logo Designer 3.82 has a User Mode Write AV starting at ExiVectorRender!StrokeText_Blend+0x00000000000003a7.
Eximious Logo Designer 3.82 has Heap Corruption starting at ntdll!RtlpNtMakeTemporaryKey+0x0000000000001a78.
Eximious Logo Designer 3.82 has a User Mode Write AV starting at ExiCustomPathLib!ExiCustomPathLib::CGradientColorsProfi
In Linux 2.6 before 2.6.23, the TRACE_IRQS_ON function in iret_exc calls a C function without ensuring that the segments
tuned before 2.x allows local users to kill running processes due to insecure permissions with tuned's ktune service.
An information-exposure vulnerability was discovered where openstack-mistral's undercloud log files containing clear-tex
The authentication mechanism, in Brocade SANnav versions before v2.0, logs plaintext account credentials at the ‘trace’
Brocade SANnav versions before v2.0, logs plain text database connection password while triggering support save.
NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) in whi
NVIDIA Virtual GPU Manager, all versions, contains a vulnerability in which the provision of an incorrectly sized buffer
alsa-utils 1.0.19 and later versions allows local users to overwrite arbitrary files via a symlink attack via the /usr/b
In tnef before 1.4.18, an attacker may be able to write to the victim's .ssh/authorized_keys file via an e-mail message
Pacemaker before 1.1.6 configure script creates temporary files insecurely
An information disclosure vulnerability exists when affected Open Enclave SDK versions improperly handle objects in memo
An information disclosure vulnerability exists in the way Windows Error Reporting (WER) handles objects in memory, aka '
An information disclosure vulnerability exists when the Windows Servicing Stack allows access to unprivileged file locat
An elevation of privilege vulnerability exists when ActiveX Installer service may allow access to files without proper a
A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Servi
An information disclosure vulnerability exists in Microsoft Office software when the software fails to properly handle o
An information disclosure vulnerability exists when the Windows Remote Procedure Call (RPC) runtime improperly initializ
An information disclosure vulnerability exists in Windows Adobe Type Manager Font Driver (ATMFD.dll) when it fails to pr
An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Wi
An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Wi
A security feature bypass vulnerability exists when Microsoft Office does not validate URLs.An attacker could send a vic
An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka
The update{_bad,}_phishing_sites scripts in mailscanner 4.79.11-2 downloads files and trusts them without using encrypti
babiloo 2.0.9 before 2.0.11 creates temporary files with predictable names when downloading and unpacking dictionary fil
mysql-gui-tools (mysql-query-browser and mysql-admin) before 5.0r14+openSUSE-2.3 exposes the password of a user connecte
P20 Pro, P20, Mate RS smartphones with versions earlier than Charlotte-AL00A 9.1.0.321(C00E320R1P1T8), versions earlier
Huawei smart phones Emily-L29C with Versions earlier than 9.1.0.311(C10E2R1P13T8), Versions earlier than 9.1.0.311(C461E
In Download Provider, there is possible SQL injection. This could lead to local information disclosure with no additiona
In processPhonebookAccess of CachedBluetoothDevice.java, there is a possible permission bypass due to an insecure defaul
In Download Provider, there is a possible SQL injection vulnerability. This could lead to local information disclosure w
In BTA_DmPinReply of bta_dm_api.cc, there is a possible out of bounds read due to an incorrect bounds check. This could
In poisson_distribution of random, there is an out of bounds read. This could lead to local information disclosure with
pithos before 0.3.5 allows overwrite of arbitrary files via symlinks.
A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages are logged when $RepeatedMsgRed
A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages were logged when multiple rules
A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages are logged when multiple rulese
fs/btrfs/volumes.c in the Linux kernel before 5.1 allows a btrfs_verify_dev_extents NULL pointer dereference via a craft
The Coolpad 1851 Android device with a build fingerprint of Coolpad/android/android:8.1.0/O11019/1534834761:userdebug/re
The Coolpad N3C Android device with a build fingerprint of Coolpad/N3C/N3C:8.1.0/O11019/1538236809:user/release-keys con
The Ulefone Armor 5 Android device with a build fingerprint of Ulefone/Ulefone_Armor_5/Ulefone_Armor_5:8.1.0/O11019/1528
The Tecno Camon iClick Android device with a build fingerprint of TECNO/H633/TECNO-IN6:8.1.0/O11019/A-180409V96:user/rel
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started