2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-10611 | CRITICAL | 9.8 | 0.9% | Jan 21, 2020 | Buffer overflow can occur while processing clip due to lack of check of object size before parsing in Snapdragon Auto, S... |
| CVE-2019-10606 | HIGH | 7.8 | 0.2% | Jan 21, 2020 | Out-of-bound access will occur in USB driver due to lack of check to validate the frame size passed by user in Snapdrago... |
| CVE-2019-10602 | HIGH | 7.8 | 0.2% | Jan 21, 2020 | Potential use-after-free heap error during Validate/Present calls on display HW composer in Snapdragon Auto, Snapdragon ... |
| CVE-2019-10585 | HIGH | 7.8 | 0.2% | Jan 21, 2020 | Possible integer overflow happens when mmap find function will increment refcount every time when it invokes and can lea... |
| CVE-2019-10583 | HIGH | 7.8 | 0.2% | Jan 21, 2020 | Use after free issue occurs when camera access sensors data through direct report mode in Snapdragon Auto, Snapdragon Co... |
| CVE-2019-10582 | HIGH | 7.8 | 0.2% | Jan 21, 2020 | Use after free issue due to using of invalidated iterator to delete an object in sensors HAL in Snapdragon Auto, Snapdra... |
| CVE-2019-10581 | CRITICAL | 9.8 | 1.1% | Jan 21, 2020 | NULL is assigned to local instance of audio device pointer after free instead of global static pointer and can lead to u... |
| CVE-2019-10579 | CRITICAL | 9.1 | 0.9% | Jan 21, 2020 | Buffer over-read can occur while playing the video clip which is not standard in Snapdragon Auto, Snapdragon Compute, Sn... |
| CVE-2019-10578 | HIGH | 7.5 | 0.8% | Jan 21, 2020 | Null pointer dereference can occur while parsing the clip which is nonstandard in Snapdragon Auto, Snapdragon Compute, S... |
| CVE-2019-10561 | MEDIUM | 5.5 | 0.4% | Jan 21, 2020 | Improper initialization of local variables which are parameters to sfs api may cause invalid pointer dereference and lea... |
| CVE-2019-10558 | HIGH | 7.8 | 0.2% | Jan 21, 2020 | While transferring data from APPS to DSP, Out of bound in FastRPC HLOS Driver due to the data buffer which can be contro... |
| CVE-2019-10548 | HIGH | 7.8 | 0.2% | Jan 21, 2020 | While trying to obtain datad ipc handle during DPL initialization, Heap use-after-free issue can occur if modem SSR occu... |
| CVE-2019-10532 | CRITICAL | 9.8 | 1.1% | Jan 21, 2020 | Null-pointer dereference issue can occur while calculating string length when source string length is zero in Snapdragon... |
| CVE-2019-20386 | LOW | 2.4 | 0.4% | Jan 21, 2020 | An issue was discovered in button_open in login/logind-button.c in systemd before 243. When executing the udevadm trigge... |
| CVE-2019-20385 | HIGH | 8.8 | 1.1% | Jan 21, 2020 | The CSV upload feature in /supervisor/procesa_carga.php on Logaritmo Aware CallManager 2012 devices allows upload of .ph... |
| CVE-2019-20384 | MEDIUM | 5.5 | 0.3% | Jan 21, 2020 | Gentoo Portage through 2.3.84 allows local users to place a Trojan horse plugin in the /usr/lib64/nagios/plugins directo... |
| CVE-2019-20381 | MEDIUM | 6.1 | 0.9% | Jan 20, 2020 | TestLink before 1.9.20 allows XSS via non-lowercase javascript: in the index.php reqURI parameter. NOTE: this issue exis... |
| CVE-2019-20357 | HIGH | 7.8 | 0.7% | Jan 18, 2020 | A Persistent Arbitrary Code Execution vulnerability exists in the Trend Micro Security 2020 (v160 and 2019 (v15) consume... |
| CVE-2019-19697 | MEDIUM | 6.7 | 0.8% | Jan 18, 2020 | An arbitrary code execution vulnerability exists in the Trend Micro Security 2019 (v15) consumer family of products whic... |
| CVE-2019-19696 | MEDIUM | 5.5 | 0.5% | Jan 18, 2020 | A RootCA vulnerability found in Trend Micro Password Manager for Windows and macOS exists where the localhost.key of Roo... |
| CVE-2019-15625 | MEDIUM | 5.5 | 1.0% | Jan 18, 2020 | A memory usage vulnerability exists in Trend Micro Password Manager 3.8 that could allow an attacker with access and per... |
| CVE-2019-19339 | MEDIUM | 6.5 | 0.3% | Jan 17, 2020 | It was found that the Red Hat Enterprise Linux 8 kpatch update did not include the complete fix for CVE-2018-12207. A fl... |
| CVE-2019-17635 | HIGH | 7.8 | 1.3% | Jan 17, 2020 | Eclipse Memory Analyzer version 1.9.1 and earlier is subject to a deserialization vulnerability if an index file of a pa... |
| CVE-2019-17634 | CRITICAL | 9 | 1.9% | Jan 17, 2020 | Eclipse Memory Analyzer version 1.9.1 and earlier is subject to a cross site scripting (XSS) vulnerability when generati... |
| CVE-2019-17127 | MEDIUM | 6.1 | 1.9% | Jan 17, 2020 | A Stored Client Side Template Injection (CSTI) with Angular was discovered in the SolarWinds Orion Platform 2019.2 HF1 i... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now