CVE Vulnerabilities in 2019

54 documented vulnerabilities published in 2019.

Other years: 2026 2025 2024 2023 2022 2021 2020

Top Affected Vendors in 2019

All CVEs from 2019

CVE-2019-1010293
9.8 critical

Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Boundary crossing. The impact is: Memory corruption of the TEE itself. The component is: optee_os. The fixed version is: 3.4.0 and later.

Trustedfirmware Op-Tee Jul 15, 2019
CVE-2019-13118
5.3 medium

In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was too narrow and an invalid character/length combination could be passed to xsltNumberFormatDecimal, leading to a read of uninitialized stack data.

Xmlsoft Libxslt Jul 1, 2019
CVE-2019-13117
5.3 medium

In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could lead to a uninitialized read in xsltNumberFormatInsertNumbers. This could allow an attacker to discern whether a byte on the stack contains the characters A, a, I, i, or 0, or any other character.

Xmlsoft Libxslt Jul 1, 2019
CVE-2017-14854
9.1 critical

A stack buffer overflow exists in one of the Orpak SiteOmat CGI components, allowing for remote code execution. The vulnerability affects all versions prior to 2017-09-25.

Orpak Siteomat Jun 3, 2019
CVE-2017-14853
8.6 high

The Orpak SiteOmat OrCU component is vulnerable to code injection, for all versions prior to 2017-09-25, due to a search query that uses a direct shell command. By tampering with the request, an attacker is able to run shell commands and receive valid output from the device.

Orpak Siteomat Jun 3, 2019
CVE-2017-14852
8.6 high

An insecure communication was found between a user and the Orpak SiteOmat management console for all known versions, due to an invalid SSL certificate. The attack allows for an eavesdropper to capture the communication and decrypt the data.

Orpak Siteomat Jun 3, 2019
CVE-2017-14851
9.8 critical

A SQL injection vulnerability exists in all Orpak SiteOmat versions prior to 2017-09-25. The vulnerability is in the login page, where the authentication validation process contains an insecure SELECT query. The attack allows for authentication bypass.

Orpak Siteomat Jun 3, 2019
CVE-2017-14850
6.1 medium

All known versions of the Orpak SiteOmat web management console is vulnerable to multiple instances of Stored Cross-site Scripting due to improper external user-input validation. An attacker with access to the web interface is able to hijack sessions or navigate victims outside of SiteOmat, to a mal

Orpak Siteomat Jun 3, 2019
CVE-2017-14728
9.8 critical

An authentication bypass was found in an unknown area of the SiteOmat source code. All SiteOmat BOS versions are affected, prior to the submission of this exploit. Also, the SiteOmat does not force administrators to switch passwords, leaving SSH and HTTP remote authentication open to public.

Orpak Siteomat Jun 3, 2019
CVE-2019-11091
5.6 medium

Microarchitectural Data Sampling Uncacheable Memory (MDSUM): Uncacheable memory on some microprocessors utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. A list of impacted products can be found here: ht

Intel Microarchitectural Data Sampling Uncacheable Memory Firmware May 30, 2019
CVE-2018-12130
5.9 medium

Microarchitectural Fill Buffer Data Sampling (MFBDS): Fill buffers on some microprocessors utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. A list of impacted products can be found here: https://www.int

Intel Microarchitectural Fill Buffer Data Sampling Firmware May 30, 2019
CVE-2018-12127
5.6 medium

Microarchitectural Load Port Data Sampling (MLPDS): Load ports on some microprocessors utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. A list of impacted products can be found here: https://www.intel.c

Intel Microarchitectural Load Port Data Sampling Firmware May 30, 2019
CVE-2018-12126
5.6 medium

Microarchitectural Store Buffer Data Sampling (MSBDS): Store buffers on some microprocessors utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. A list of impacted products can be found here: https://www.i

Intel Microarchitectural Store Buffer Data Sampling Firmware May 30, 2019
CVE-2019-6819
7.5 high

A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists which could cause a possible Denial of Service when specific Modbus frames are sent to the controller in the products: Modicon M340 - firmware versions prior to V3.01, Modicon M580 - firmware versions prior to V2.80

Schneider-Electric Modicon M340 Firmware May 22, 2019
CVE-2019-6820
8.2 high

A CWE-306: Missing Authentication for Critical Function vulnerability exists which could cause a modification of device IP configuration (IP address, network mask and gateway IP address) when a specific Ethernet frame is received in all versions of: Modicon M100, Modicon M200, Modicon M221, ATV IMC

Schneider-Electric Modicon M100 Firmware May 22, 2019
CVE-2018-7852
7.5 high

A CWE-248: Uncaught Exception vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause denial of service when an invalid private command parameter is sent to the controller over Modbus.

Schneider-Electric Modicon M580 Firmware May 22, 2019
CVE-2018-7821
7.5 high

An Environment (CWE-2) vulnerability exists in SoMachine Basic, all versions, and Modicon M221(all references, all versions prior to firmware V1.10.0.0) which could cause cycle time impact when flooding the M221 ethernet interface while the Ethernet/IP adapter is activated.

Schneider-Electric Somachine Basic May 22, 2019
CVE-2019-6576
6.5 medium

A vulnerability has been identified in SIMATIC HMI Comfort Panels 4" - 22" (All versions < V15.1 Update 1), SIMATIC HMI Comfort Outdoor Panels 7" & 15" (All versions < V15.1 Update 1), SIMATIC HMI KTP Mobile Panels KTP400F, KTP700, KTP700F, KTP900 und KTP900F (All versions < V15.1 Update 1), SIMATIC

Siemens Simatic Hmi Comfort Panels Firmware May 14, 2019
CVE-2019-11687
7.8 high

An issue was discovered in the DICOM Part 10 File Format in the NEMA DICOM Standard 1995 through 2019b and continuing in current implementations. The 128-byte preamble of a DICOM file that complies with this specification can contain arbitrary executable headers for multiple operating systems, inclu

Nema Dicom Standard May 2, 2019
CVE-2019-10955
6.1 medium

In Rockwell Automation MicroLogix 1400 Controllers Series A, All Versions Series B, v15.002 and earlier, MicroLogix 1100 Controllers v14.00 and earlier, CompactLogix 5370 L1 controllers v30.014 and earlier, CompactLogix 5370 L2 controllers v30.014 and earlier, CompactLogix 5370 L3 controllers (inclu

Rockwellautomation Micrologix 1400 A Firmware Apr 25, 2019
CVE-2019-10953
7.5 high

ABB, Phoenix Contact, Schneider Electric, Siemens, WAGO - Programmable Logic Controllers, multiple versions. Researchers have found some controllers are susceptible to a denial-of-service attack due to a flood of network packets.

Abb Pm554-Tp-Eth Firmware Apr 17, 2019
CVE-2019-6575
7.5 high

A vulnerability has been identified in SIMATIC CP 443-1 OPC UA (All versions), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) (All versions < V2.7), SIMATIC HMI Comfort Outdoor Panels 7" & 15" (incl. SIPLUS variants) (All versions < V15.1 Upd 4), SIMATIC HMI Comfort Panels 4

Siemens Simatic Cp443-1 Opc Ua Firmware Apr 17, 2019
CVE-2018-16561
7.5 high

A vulnerability has been identified in SIMATIC S7-300 CPUs (All versions < V3.X.16). The affected CPUs improperly validate S7 communication packets which could cause a Denial-of-Service condition of the CPU. The CPU will remain in DEFECT mode until manual restart. Successful exploitation requires an

Siemens Simatic S7-300 Firmware Apr 17, 2019
CVE-2019-11068
9.8 critical

libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code. xsltCheckRead can return -1 for a crafted URL that is not actually invalid and is subsequently loaded.

Xmlsoft Libxslt Apr 10, 2019