CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2019-0756

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Execution Vulnerability'.

    Published: 9 Apr 2019
    5.5
    Medium

    CVE-2019-0759

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists when the Windows Print Spooler does not properly handle objects in memory, aka 'Windows Print Spooler Information Disclosure Vulnerability'.

    Published: 9 Apr 2019
    6.5
    Medium

    CVE-2019-0761

    Last Modified: 21 Nov 2024

    A security feature bypass vulnerability exists when Internet Explorer fails to validate the correct Security Zone of requests for specific URLs, aka 'Internet Explorer Security Feature Bypass Vulnerability'. This CVE ID is unique from CVE-2019-0768.

    Published: 9 Apr 2019
    4.3
    Medium

    CVE-2019-0762

    Last Modified: 21 Nov 2024

    A security feature bypass vulnerability exists when Microsoft browsers improperly handle requests of different origins, aka 'Microsoft Browsers Security Feature Bypass Vulnerability'.

    Published: 9 Apr 2019
    7.5
    High

    CVE-2019-0763

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka 'Internet Explorer Memory Corruption Vulnerability'.

    Published: 9 Apr 2019
    8.8
    High

    CVE-2019-0765

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in the way that comctl32.dll handles objects in memory, aka 'Comctl32 Remote Code Execution Vulnerability'.

    Published: 9 Apr 2019
    7.8
    High

    CVE-2019-0766

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists in Windows AppX Deployment Server that allows file creation in arbitrary locations. To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Windows Elevation of Privilege Vulnerability'.

    Published: 9 Apr 2019
    5.5
    Medium

    CVE-2019-0767

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists when the Windows kernel improperly initializes objects in memory.To exploit this vulnerability, an authenticated attacker could run a specially crafted application, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0702, CVE-2019-0755, CVE-2019-0775, CVE-2019-0782.

    Published: 9 Apr 2019
    4.3
    Medium

    CVE-2019-0768

    Last Modified: 21 Nov 2024

    A security feature bypass vulnerability exists when Internet Explorer VBScript execution policy does not properly restrict VBScript under specific conditions, and to allow requests that should otherwise be ignored, aka 'Internet Explorer Security Feature Bypass Vulnerability'. This CVE ID is unique from CVE-2019-0761.

    Published: 9 Apr 2019
    7.5
    High

    CVE-2019-0769

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0609, CVE-2019-0639, CVE-2019-0680, CVE-2019-0770, CVE-2019-0771, CVE-2019-0773, CVE-2019-0783.

    Published: 9 Apr 2019
    6.1
    Medium

    CVE-2019-3870

    Last Modified: 14 Jan 2025

    A vulnerability was found in Samba from version (including) 4.9 to versions before 4.9.6 and 4.10.2. During the creation of a new Samba AD DC, files are created in a private subdirectory of the install location. This directory is typically mode 0700, that is owner (root) only access. However in some upgraded installations it will have other permissions, such as 0755, because this was the default before Samba 4.8. Within this directory, files are created with mode 0666, which is world-writable, including a sample krb5.conf, and the list of DNS names and servicePrincipalName values to update.

    Published: 9 Apr 2019
    5.4
    Medium

    CVE-2019-3880

    Last Modified: 21 Nov 2024

    A flaw was found in the way samba implemented an RPC endpoint emulating the Windows registry service API. An unprivileged attacker could use this flaw to create a new registry hive file anywhere they have unix permissions which could lead to creation of a new file in the Samba share. Versions before 4.8.11, 4.9.6 and 4.10.2 are vulnerable.

    Published: 9 Apr 2019
    5.9
    Medium

    CVE-2019-11065

    Last Modified: 21 Nov 2024

    Gradle versions from 1.4 to 5.3.1 use an insecure HTTP URL to download dependencies when the built-in JavaScript or CoffeeScript Gradle plugins are used. Dependency artifacts could have been maliciously compromised by a MITM attack against the ajax.googleapis.com web site.

    Published: 9 Apr 2019
    9.8
    Critical

    CVE-2019-7096

    Last Modified: 21 Nov 2024

    Adobe Flash Player versions 32.0.0.156 and earlier, 32.0.0.156 and earlier, and 32.0.0.156 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 9 Apr 2019
    7.5
    High

    CVE-2019-7108

    Last Modified: 21 Nov 2024

    Adobe Flash Player versions 32.0.0.156 and earlier, 32.0.0.156 and earlier, and 32.0.0.156 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure .

    Published: 9 Apr 2019
    7.5
    High

    CVE-2019-0227

    Last Modified: 8 May 2025

    A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projects Axis 1.x Subversion repository, legacy users are encouraged to build from source. The successor to Axis 1.x is Axis2, the latest version is 1.7.9 and is not vulnerable to this issue.

    Published: 9 Apr 2019
    9.8
    Critical

    CVE-2019-0697

    Last Modified: 21 Nov 2024

    A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP responses to a client, aka 'Windows DHCP Client Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0698, CVE-2019-0726.

    Published: 8 Apr 2019
    9.8
    Critical

    CVE-2019-0698

    Last Modified: 21 Nov 2024

    A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP responses to a client, aka 'Windows DHCP Client Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0697, CVE-2019-0726.

    Published: 8 Apr 2019
    6.8
    Medium

    CVE-2019-0701

    Last Modified: 21 Nov 2024

    A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0690, CVE-2019-0695.

    Published: 8 Apr 2019
    5.5
    Medium

    CVE-2019-0702

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0755, CVE-2019-0767, CVE-2019-0775, CVE-2019-0782.

    Published: 8 Apr 2019
    6.5
    Medium

    CVE-2019-0703

    Last Modified: 29 Oct 2025

    An information disclosure vulnerability exists in the way that the Windows SMB Server handles certain requests, aka 'Windows SMB Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0704, CVE-2019-0821.

    Published: 8 Apr 2019
    6.5
    Medium

    CVE-2019-0704

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists in the way that the Windows SMB Server handles certain requests, aka 'Windows SMB Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0703, CVE-2019-0821.

    Published: 8 Apr 2019
    9.8
    Critical

    CVE-2019-0726

    Last Modified: 21 Nov 2024

    A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP responses to a client, aka 'Windows DHCP Client Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0697, CVE-2019-0698.

    Published: 8 Apr 2019
    6.5
    Medium

    CVE-2019-0746

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists when the scripting engine does not properly handle objects in memory in Microsoft Edge, aka 'Scripting Engine Information Disclosure Vulnerability'.

    Published: 8 Apr 2019
    7.8
    High

    CVE-2019-0748

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability'.

    Published: 8 Apr 2019
    5.5
    Medium

    CVE-2019-0754

    Last Modified: 21 Nov 2024

    A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Service Vulnerability'.

    Published: 8 Apr 2019
    5.5
    Medium

    CVE-2019-0755

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0702, CVE-2019-0767, CVE-2019-0775, CVE-2019-0782.

    Published: 8 Apr 2019
    6.8
    Medium

    CVE-2019-0678

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists when Microsoft Edge does not properly enforce cross-domain policies, which could allow an attacker to access information from one domain and inject it into another domain.In a web-based attack scenario, an attacker could host a website that is used to attempt to exploit the vulnerability, aka 'Microsoft Edge Elevation of Privilege Vulnerability'.

    Published: 8 Apr 2019
    7.5
    High

    CVE-2019-0680

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0609, CVE-2019-0639, CVE-2019-0769, CVE-2019-0770, CVE-2019-0771, CVE-2019-0773, CVE-2019-0783.

    Published: 8 Apr 2019
    7.8
    High

    CVE-2019-0682

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists due to an integer overflow in Windows Subsystem for Linux, aka 'Windows Subsystem for Linux Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0689, CVE-2019-0692, CVE-2019-0693, CVE-2019-0694.

    Published: 8 Apr 2019
    5.9
    Medium

    CVE-2019-0683

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists in Active Directory Forest trusts due to a default setting that lets an attacker in the trusting forest request delegation of a TGT for an identity from the trusted forest, aka 'Active Directory Elevation of Privilege Vulnerability'.

    Published: 8 Apr 2019
    7.8
    High

    CVE-2019-0689

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists due to an integer overflow in Windows Subsystem for Linux, aka 'Windows Subsystem for Linux Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0682, CVE-2019-0692, CVE-2019-0693, CVE-2019-0694.

    Published: 8 Apr 2019
    6.8
    Medium

    CVE-2019-0690

    Last Modified: 21 Nov 2024

    A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0695, CVE-2019-0701.

    Published: 8 Apr 2019
    7.8
    High

    CVE-2019-0692

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists due to an integer overflow in Windows Subsystem for Linux, aka 'Windows Subsystem for Linux Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0682, CVE-2019-0689, CVE-2019-0693, CVE-2019-0694.

    Published: 8 Apr 2019
    7.8
    High

    CVE-2019-0693

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists due to an integer overflow in Windows Subsystem for Linux, aka 'Windows Subsystem for Linux Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0682, CVE-2019-0689, CVE-2019-0692, CVE-2019-0694.

    Published: 8 Apr 2019
    7.8
    High

    CVE-2019-0694

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists due to an integer overflow in Windows Subsystem for Linux, aka 'Windows Subsystem for Linux Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0682, CVE-2019-0689, CVE-2019-0692, CVE-2019-0693.

    Published: 8 Apr 2019
    6.8
    Medium

    CVE-2019-0695

    Last Modified: 21 Nov 2024

    A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0690, CVE-2019-0701.

    Published: 8 Apr 2019
    7.8
    High

    CVE-2019-0696

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'.

    Published: 8 Apr 2019
    7.5
    High

    CVE-2019-0667

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'Windows VBScript Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0665, CVE-2019-0666, CVE-2019-0772.

    Published: 8 Apr 2019
    7.5
    High

    CVE-2019-0666

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'Windows VBScript Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0665, CVE-2019-0667, CVE-2019-0772.

    Published: 8 Apr 2019
    7.5
    High

    CVE-2019-0665

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'Windows VBScript Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0666, CVE-2019-0667, CVE-2019-0772.

    Published: 8 Apr 2019
    7.5
    High

    CVE-2019-0639

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0609, CVE-2019-0680, CVE-2019-0769, CVE-2019-0770, CVE-2019-0771, CVE-2019-0773, CVE-2019-0783.

    Published: 8 Apr 2019
    7.8
    High

    CVE-2019-0617

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'.

    Published: 8 Apr 2019
    6.5
    Medium

    CVE-2019-0614

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0774.

    Published: 8 Apr 2019
    5.3
    Medium

    CVE-2019-0612

    Last Modified: 21 Nov 2024

    A security feature bypass vulnerability exists when Click2Play protection in Microsoft Edge improperly handles flash objects. By itself, this bypass vulnerability does not allow arbitrary code execution, aka 'Microsoft Edge Security Feature Bypass Vulnerability'.

    Published: 8 Apr 2019
    7.5
    High

    CVE-2019-0611

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0592.

    Published: 8 Apr 2019
    7.5
    High

    CVE-2019-0609

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0639, CVE-2019-0680, CVE-2019-0769, CVE-2019-0770, CVE-2019-0771, CVE-2019-0773, CVE-2019-0783.

    Published: 8 Apr 2019
    7.5
    High

    CVE-2019-0603

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in the way that Windows Deployment Services TFTP Server handles objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code with elevated permissions on a target system. To exploit the vulnerability, an attacker could create a specially crafted request, causing Windows to execute arbitrary code with elevated permissions. The security update addresses the vulnerability by correcting how Windows Deployment Services TFTP Server handles objects in memory, aka 'Windows Deployment Services TFTP Server Remote Code Execution Vulnerability'.

    Published: 8 Apr 2019
    7.5
    High

    CVE-2019-0592

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0611.

    Published: 8 Apr 2019
    6.5
    Medium

    CVE-2019-11026

    Last Modified: 21 Nov 2024

    FontInfoScanner::scanFonts in FontInfo.cc in Poppler 0.75.0 has infinite recursion, leading to a call to the error function in Error.cc.

    Published: 8 Apr 2019