17,305 vulnerabilities published in 2019
Insufficient access control in subsystem for Intel (R) processor graphics in 6th, 7th, 8th and 9th Generation Intel(R) C
Insufficient access control in protected memory subsystem for SMM for 6th, 7th, 8th and 9th Generation Intel(R) Core(TM)
Insufficient access control in protected memory subsystem for Intel(R) TXT for 6th, 7th, 8th and 9th Generation Intel(R)
Insufficient input validation in Kernel Mode module for Intel(R) Graphics Driver before version 25.20.100.6519 may allow
Out of bounds read in a subsystem for Intel(R) Graphics Driver versions before 26.20.100.7209 may allow an authenticated
Improper access control in the API for the Intel(R) Graphics Driver versions before 26.20.100.7209 may allow an authenti
Improper input validation in the API for Intel(R) Graphics Driver versions before 26.20.100.7209 may allow an authentica
qtnx 0.9 stores non-custom SSH keys in a world-readable configuration file. If a user has a world-readable or world-exec
The BIG-IP 15.0.0-15.0.1, 14.0.0-14.1.2.2, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.1-11.6.5.1, BIG-IQ 7.0.0, 6.0.0-6.1.
jhead 3.03 is affected by: heap-based buffer over-read. The impact is: Denial of service. The component is: ReadJpegSect
A memory leak in the i40e_setup_macvlans() function in drivers/net/ethernet/intel/i40e/i40e_main.c in the Linux kernel t
A memory leak in the mlx5_fw_fatal_reporter_dump() function in drivers/net/ethernet/mellanox/mlx5/core/health.c in the L
A memory leak in the i2400m_op_rfkill_sw_toggle() function in drivers/net/wimax/i2400m/op-rfkill.c in the Linux kernel b
A memory leak in the nl80211_get_ftm_responder_stats() function in net/wireless/nl80211.c in the Linux kernel through 5.
A memory leak in the bnxt_re_create_srq() function in drivers/infiniband/hw/bnxt_re/ib_verbs.c in the Linux kernel throu
Trusted Boot (tboot) before 1.8.2 has a 'loader.c' Security Bypass Vulnerability
surf: cookie jar has read access from other local user
uzbl: Information disclosure via world-readable cookies storage file
foomatic-rip filter, all versions, used insecurely creates temporary files for storage of PostScript data by rendering t
foomatic-rip filter v4.0.12 and prior used insecurely creates temporary files for storage of PostScript data by renderin
tuned 2.10.0 creates its PID file with insecure permissions which allows local users to kill arbitrary processes.
The keyring DB in GnuPG before 2.1.2 does not properly handle invalid packets, which allows remote attackers to cause a
kbx/keybox-search.c in GnuPG before 1.4.19, 2.0.x before 2.0.27, and 2.1.x before 2.1.2 does not properly handle bitwise
Pidgin 2.10.0 uses DBUS for certain cleartext communication, which allows local users to obtain sensitive information vi
btrfs_root_node in fs/btrfs/ctree.c in the Linux kernel through 5.3.12 allows a NULL pointer dereference because rcu_der
__btrfs_free_extent in fs/btrfs/extent-tree.c in the Linux kernel through 5.3.12 calls btrfs_print_leaf in a certain ENO
ext4_empty_dir in fs/ext4/namei.c in the Linux kernel through 5.3.12 allows a NULL pointer dereference because ext4_read
The Ruby net-ldap gem before 0.11 uses a weak salt when generating SSHA passwords.
Ruby gem openshift-origin-node before 2014-02-14 does not contain a cronjob timeout which could result in a denial of se
python-rply before 0.7.4 insecurely creates temporary files.
Use after free issue in Xtra daemon shutdown due to static object instance getting freed from a multiple places in Snapd
Improper validation for loop variable received from firmware can lead to out of bound access in WLAN function while iter
A clear text storage of sensitive information vulnerability in FortiClient for Mac may allow a local attacker to read se
Jenkins Spira Importer Plugin 3.2.2 and earlier stores credentials unencrypted in its global configuration file on the J
Information disclosure due to lack of address range check done on the SysDBG buffers in SDI code. in Snapdragon Auto, Sn
Non Secure Kernel can cause Trustzone to do an arbitrary memory read which will result into DOS in Snapdragon Auto, Snap
Subsequent use of the CBO listener may result in further memory corruption due to use after free issue. in Snapdragon Au
In Libarchive 3.4.0, archive_wstring_append_from_mbs in archive_string.c has an out-of-bounds read because of an incorre
In the AppleTalk subsystem in the Linux kernel before 5.1, there is a potential NULL pointer dereference because registe
An issue was discovered in Eracent EDA, EPA, EPM, EUA, FLW, and SUM Agent through 10.2.26. The agent executable, when in
Claws Mail vCalendar plugin: credentials exposed on interface
A flaw was found in the Linux kernel's Bluetooth implementation of UART, all versions kernel 3.x.x before 4.18.0 and ker
thttpd has a local DoS vulnerability via specially-crafted .htpasswd files
libuser has information disclosure when moving user's home directory
Insufficient validation of untrusted input in intents in Google Chrome on Android prior to 78.0.3904.70 allowed a local
Use after free in PDFium in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to potentially exploit heap co
Use after free in PDFium in Google Chrome prior to 76.0.3809.100 allowed a remote attacker to potentially exploit heap c
In text_to_glyphs in sushi-font-widget.c in gnome-font-viewer 3.34.0, there is a NULL pointer dereference while parsing
The BIG-IP APM Edge Client for macOS bundled with BIG-IP APM 15.0.0-15.0.1, 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.1.0-13.
P30, P30 Pro, Mate 20 smartphones with software of versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1), versions ear
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started