CVE Vulnerabilities in 2019

54 documented vulnerabilities published in 2019.

Other years: 2026 2025 2024 2023 2022 2021 2020

Top Affected Vendors in 2019

All CVEs from 2019

CVE-2019-17571
9.8 critical

Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for log data. This affects Log4j versions up to 1.2

Apache Log4J Dec 20, 2019
CVE-2019-18269
9.8 critical

Omron’s CS and CJ series PLCs have an unrestricted externally accessible lock vulnerability.

Omron Plc Cj Firmware Dec 16, 2019
CVE-2019-13533
8.1 high

In Omron PLC CJ series, all versions, and Omron PLC CS series, all versions, an attacker could monitor traffic between the PLC and the controller and replay requests that could result in the opening and closing of industrial valves.

Omron Plc Cj Firmware Dec 16, 2019
CVE-2019-19378
7.8 high

In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image can lead to slab-out-of-bounds write access in index_rbio_pages in fs/btrfs/raid56.c.

Linux Linux Kernel Nov 29, 2019
CVE-2019-13721
8.8 high

Use after free in PDFium in Google Chrome prior to 78.0.3904.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Google Chrome Nov 25, 2019
CVE-2019-6852
7.5 high

A CWE-200: Information Exposure vulnerability exists in Modicon Controllers (M340 CPUs, M340 communication modules, Premium CPUs, Premium communication modules, Quantum CPUs, Quantum communication modules - see security notification for specific versions), which could cause the disclosure of FTP har

Schneider-Electric Bmx P34X Firmware Nov 20, 2019
CVE-2019-11135
6.5 medium

TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access.

Opensuse Leap Nov 14, 2019
CVE-2019-14360
4.6 medium

On Hyundai Pay Kasse HK-1000 devices, a side channel for the row-based OLED display was found. The power consumption of each row-based display cycle depends on the number of illuminated pixels, allowing a partial recovery of display contents. For example, a hardware implant in the USB cable might be

Hyundai-Pay Kasse Hk-1000 Firmware Nov 2, 2019
CVE-2019-18197
7.5 high

In xsltCopyText in transform.c in libxslt 1.1.33, a pointer variable isn't reset under certain circumstances. If the relevant memory area happened to be freed and reused in a certain way, a bounds check could fail and memory outside a buffer could be written to, or uninitialized data could be disclo

Xmlsoft Libxslt Oct 18, 2019
CVE-2019-16910
5.3 medium

Arm Mbed TLS before 2.19.0 and Arm Mbed Crypto before 2.0.0, when deterministic ECDSA is enabled, use an RNG with insufficient entropy for blinding, which might allow an attacker to recover a private key via side-channel attacks if a victim signs the same message many times. (For Mbed TLS, the fix i

Arm Mbed Crypto Sep 26, 2019
CVE-2019-10996
7.8 high

Red Lion Controls Crimson, version 3.0 and prior and version 3.1 prior to release 3112.00, allow multiple vulnerabilities to be exploited when a valid user opens a specially crafted, malicious input file that can reference memory after it has been freed.

Redlion Crimson Sep 23, 2019
CVE-2019-10990
6.5 medium

Red Lion Controls Crimson, version 3.0 and prior and version 3.1 prior to release 3112.00, uses a hard-coded password to encrypt protected files in transit and at rest, which may allow an attacker to access configuration files.

Redlion Crimson Sep 23, 2019
CVE-2019-10984
7.8 high

Red Lion Controls Crimson, version 3.0 and prior and version 3.1 prior to release 3112.00, allow multiple vulnerabilities to be exploited when a valid user opens a specially crafted, malicious input file that causes the program to mishandle pointers.

Redlion Crimson Sep 23, 2019
CVE-2019-10978
7.8 high

Red Lion Controls Crimson, version 3.0 and prior and version 3.1 prior to release 3112.00, allow multiple vulnerabilities to be exploited when a valid user opens a specially crafted, malicious input file that operates outside of the designated memory area.

Redlion Crimson Sep 23, 2019
CVE-2019-6829
7.5 high

A CWE-248: Uncaught Exception vulnerability exists in Modicon M580 (firmware version prior to V2.90) and Modicon M340 (firmware version prior to V3.10), which could cause a possible denial of service when writing to specific memory addresses in the controller over Modbus.

Schneider-Electric Modicon M580 Firmware Sep 17, 2019
CVE-2019-16230
4.7 medium

drivers/gpu/drm/radeon/radeon_display.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer dereference. NOTE: A third-party software maintainer states that the work queue allocation is happening during device initialization, which for a graphics car

Linux Linux Kernel Sep 11, 2019
CVE-2019-16168
6.5 medium

In SQLite through 3.29.0, whereLoopAddBtreeIndex in sqlite3.c can crash a browser or other application because of missing validation of a sqlite_stat1 sz field, aka a "severe division by zero in the query planner."

Sqlite Sqlite Sep 9, 2019
CVE-2019-15213
4.6 medium

An issue was discovered in the Linux kernel before 5.2.3. There is a use-after-free caused by a malicious USB device in the drivers/media/usb/dvb-usb/dvb-usb-init.c driver.

Linux Linux Kernel Aug 19, 2019
CVE-2019-1010292
9.8 critical

Linaro/OP-TEE OP-TEE Prior to version v3.4.0 is affected by: Boundary checks. The impact is: This could lead to corruption of any memory which the TA can access. The component is: optee_os. The fixed version is: v3.4.0.

Trustedfirmware Op-Tee Jul 16, 2019
CVE-2019-1010298
9.8 critical

Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Buffer Overflow. The impact is: Code execution in the context of TEE core (kernel). The component is: optee_os. The fixed version is: 3.4.0 and later.

Trustedfirmware Op-Tee Jul 15, 2019
CVE-2019-1010297
9.8 critical

Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Buffer Overflow. The impact is: Execution of code in TEE core (kernel) context. The component is: optee_os. The fixed version is: 3.4.0 and later.

Trustedfirmware Op-Tee Jul 15, 2019
CVE-2019-1010296
9.8 critical

Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Buffer Overflow. The impact is: Code execution in context of TEE core (kernel). The component is: optee_os. The fixed version is: 3.4.0 and later.

Trustedfirmware Op-Tee Jul 15, 2019
CVE-2019-1010295
9.8 critical

Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Buffer Overflow. The impact is: Memory corruption and disclosure of memory content. The component is: optee_os. The fixed version is: 3.4.0 and later.

Trustedfirmware Op-Tee Jul 15, 2019
CVE-2019-1010294
7.5 high

Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Rounding error. The impact is: Potentially leaking code and/or data from previous Trusted Application. The component is: optee_os. The fixed version is: 3.4.0 and later.

Trustedfirmware Op-Tee Jul 15, 2019