2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-10611CRITICAL9.8Buffer overflow can occur while processing clip due to lack of check of object size before parsing in Snapdragon Auto, S...
CVE-2019-10606HIGH7.8Out-of-bound access will occur in USB driver due to lack of check to validate the frame size passed by user in Snapdrago...
CVE-2019-10602HIGH7.8Potential use-after-free heap error during Validate/Present calls on display HW composer in Snapdragon Auto, Snapdragon ...
CVE-2019-10585HIGH7.8Possible integer overflow happens when mmap find function will increment refcount every time when it invokes and can lea...
CVE-2019-10583HIGH7.8Use after free issue occurs when camera access sensors data through direct report mode in Snapdragon Auto, Snapdragon Co...
CVE-2019-10582HIGH7.8Use after free issue due to using of invalidated iterator to delete an object in sensors HAL in Snapdragon Auto, Snapdra...
CVE-2019-10581CRITICAL9.8NULL is assigned to local instance of audio device pointer after free instead of global static pointer and can lead to u...
CVE-2019-10579CRITICAL9.1Buffer over-read can occur while playing the video clip which is not standard in Snapdragon Auto, Snapdragon Compute, Sn...
CVE-2019-10578HIGH7.5Null pointer dereference can occur while parsing the clip which is nonstandard in Snapdragon Auto, Snapdragon Compute, S...
CVE-2019-10561MEDIUM5.5Improper initialization of local variables which are parameters to sfs api may cause invalid pointer dereference and lea...
CVE-2019-10558HIGH7.8While transferring data from APPS to DSP, Out of bound in FastRPC HLOS Driver due to the data buffer which can be contro...
CVE-2019-10548HIGH7.8While trying to obtain datad ipc handle during DPL initialization, Heap use-after-free issue can occur if modem SSR occu...
CVE-2019-10532CRITICAL9.8Null-pointer dereference issue can occur while calculating string length when source string length is zero in Snapdragon...
CVE-2019-20386LOW2.4An issue was discovered in button_open in login/logind-button.c in systemd before 243. When executing the udevadm trigge...
CVE-2019-20385HIGH8.8The CSV upload feature in /supervisor/procesa_carga.php on Logaritmo Aware CallManager 2012 devices allows upload of .ph...
CVE-2019-20384MEDIUM5.5Gentoo Portage through 2.3.84 allows local users to place a Trojan horse plugin in the /usr/lib64/nagios/plugins directo...
CVE-2019-20381MEDIUM6.1TestLink before 1.9.20 allows XSS via non-lowercase javascript: in the index.php reqURI parameter. NOTE: this issue exis...
CVE-2019-20357HIGH7.8A Persistent Arbitrary Code Execution vulnerability exists in the Trend Micro Security 2020 (v160 and 2019 (v15) consume...
CVE-2019-19697MEDIUM6.7An arbitrary code execution vulnerability exists in the Trend Micro Security 2019 (v15) consumer family of products whic...
CVE-2019-19696MEDIUM5.5A RootCA vulnerability found in Trend Micro Password Manager for Windows and macOS exists where the localhost.key of Roo...
CVE-2019-15625MEDIUM5.5A memory usage vulnerability exists in Trend Micro Password Manager 3.8 that could allow an attacker with access and per...
CVE-2019-19339MEDIUM6.5It was found that the Red Hat Enterprise Linux 8 kpatch update did not include the complete fix for CVE-2018-12207. A fl...
CVE-2019-17635HIGH7.8Eclipse Memory Analyzer version 1.9.1 and earlier is subject to a deserialization vulnerability if an index file of a pa...
CVE-2019-17634CRITICAL9Eclipse Memory Analyzer version 1.9.1 and earlier is subject to a cross site scripting (XSS) vulnerability when generati...
CVE-2019-17127MEDIUM6.1A Stored Client Side Template Injection (CSTI) with Angular was discovered in the SolarWinds Orion Platform 2019.2 HF1 i...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now