CVE Vulnerabilities in 2019

54 documented vulnerabilities published in 2019.

Other years: 2026 2025 2024 2023 2022 2021 2020

Top Affected Vendors in 2019

All CVEs from 2019

CVE-2019-7386
6.5 medium

A Denial of Service issue has been discovered in the Gecko component of KaiOS 2.5 10.05 (platform 48.0.a2) on Nokia 8810 4G devices. When a crafted web page is visited with the internal browser, the Gecko process crashes with a segfault. Successful exploitation could lead to the remote code executio

Kaiostech Kaios Mar 21, 2019
CVE-2019-9201
9.8 critical

Multiple Phoenix Contact devices allow remote attackers to establish TCP sessions to port 1962 and obtain sensitive information or make changes, as demonstrated by using the Create Backup feature to traverse all directories.

Phoenixcontact Ilc 131 Eth Firmware Feb 26, 2019
CVE-2019-7317
5.3 medium

png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called under png_safe_execute.

Libpng Libpng Feb 4, 2019
CVE-2019-6109
6.8 medium

An issue was discovered in OpenSSH 7.9. Due to missing character encoding in the progress display, a malicious server (or Man-in-The-Middle attacker) can employ crafted object names to manipulate the client output, e.g., by using ANSI control codes to hide additional files being transferred. This af

Openbsd Openssh Jan 31, 2019
CVE-2018-19440
5.3 medium

ARM Trusted Firmware-A allows information disclosure.

Trustedfirmware Trusted Firmware-A Jan 30, 2019
CVE-2019-6129
6.5 medium

png_create_info_struct in png.c in libpng 1.6.36 has a memory leak, as demonstrated by pngcp. NOTE: a third party has stated "I don't think it is libpng's job to free this buffer.

Libpng Libpng Jan 11, 2019