2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-20503MEDIUM6.5usrsctp before 2019-12-20 has out-of-bounds reads in sctp_load_addresses_from_init.
CVE-2019-20502HIGH7.5An issue was discovered in EFS Easy Chat Server 3.1. There is a buffer overflow via a long body2.ghp message parameter.
CVE-2019-17647CRITICAL9.8An issue was discovered in Centreon before 2.8.30, 18.10.8, 19.04.5, and 19.10.2. SQL Injection exists via the include/m...
CVE-2019-17646HIGH7.5An issue was discovered in Centreon before 18.10.8, 19.04.5, and 19.10.2. It provides sensitive information via an unaut...
CVE-2019-20382LOW3.5QEMU 4.1.0 has a memory leak in zrle_compress_data in ui/vnc-enc-zrle.c during a VNC disconnect operation because libz i...
CVE-2019-14886MEDIUM6.5A vulnerability was found in business-central, as shipped in rhdm-7.5.1 and rhpam-7.5.1, where encoded passwords are sto...
CVE-2019-17645HIGH7.5An issue was discovered in Centreon before 2.8.31, 18.10.9, 19.04.6, and 19.10.3. It provides sensitive information via ...
CVE-2019-17642HIGH8.8An issue was discovered in Centreon before 18.10.8, 19.10.1, and 19.04.2. It allows CSRF with resultant remote command e...
CVE-2019-20501HIGH7.8D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Upgrade Firmwa...
CVE-2019-20500HIGH7.8D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Save Configura...
CVE-2019-20499HIGH7.8D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Restore Config...
CVE-2019-20107HIGH8.8Multiple SQL injection vulnerabilities in TestLink through 1.9.19 allows remote authenticated users to execute arbitrary...
CVE-2019-2317CRITICAL9.8The secret key used to make the Initial Sequence Number in the TCP SYN packet could be brute forced and therefore can be...
CVE-2019-2311CRITICAL9.8Possible buffer overflow in WLAN handler due to lack of validation of destination buffer size before copying it in Snapd...
CVE-2019-2300CRITICAL9.8Possible buffer overflow in WLAN handler due to lack of validation of destination buffer size before copying into it in ...
CVE-2019-14098CRITICAL9.8Possible buffer overflow in data offload handler due to lack of check of keydata length when copying data in Snapdragon ...
CVE-2019-14097CRITICAL9.8Possible buffer overflow in WLAN Parser due to lack of length check when copying data in Snapdragon Auto, Snapdragon Com...
CVE-2019-14095CRITICAL9.8Buffer overflow occurs while processing LMP packet in which name length parameter exceeds value specified in BT-specific...
CVE-2019-14086CRITICAL9.8Possible integer overflow while checking the length of frame which is a 32 bit integer and is added to another 32 bit in...
CVE-2019-14085HIGH7.8Possible Integer underflow in WLAN function due to lack of check of data received from user side in Snapdragon Auto, Sna...
CVE-2019-14083CRITICAL9.8While parsing Service Descriptor Extended Attribute received as part of SDF frame, there is a possibility that incorrect...
CVE-2019-14082CRITICAL9.1Potential buffer over-read due to lack of bound check of memory offset passed in WLAN firmware in Snapdragon Compute, Sn...
CVE-2019-14081HIGH7.1Buffer Over-read when WLAN module gets a WMI message for SAR limits with invalid number of limits to be enforced in Snap...
CVE-2019-14079HIGH7.8Access to the uninitialized variable when the driver tries to unmap the dma buffer of a request which was never mapped i...
CVE-2019-14072HIGH7Unhandled paging request is observed due to dereferencing an already freed object because of race condition between spar...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now