2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-14119 | HIGH | 7 | 0.1% | Sep 8, 2020 | u'While processing SMCInvoke asynchronous message header, message count is modified leading to a TOCTOU race condition a... |
| CVE-2019-14117 | HIGH | 7.8 | 0.2% | Sep 8, 2020 | u'Whenever the page list is updated via privileged user, the previous list elements are freed but are not deleted from t... |
| CVE-2019-14089 | HIGH | 7.8 | 0.2% | Sep 8, 2020 | u'Keymaster attestation key and device IDs provisioning which is a one time process is incorrectly allowed to be re-prov... |
| CVE-2019-14074 | HIGH | 7.8 | 0.2% | Sep 8, 2020 | u'Heap overflow in diag command handler due to lack of check of packet length received from user' in Snapdragon Auto, Sn... |
| CVE-2019-14065 | HIGH | 7.8 | 0.2% | Sep 8, 2020 | u'Pointer double free in HavenSvc due to not setting the pointer to NULL after freeing it' in Snapdragon Auto, Snapdrago... |
| CVE-2019-14056 | HIGH | 7.8 | 0.2% | Sep 8, 2020 | u'Possible integer overflow in API due to lack of check on large oid range count in cert extension field' in Snapdragon ... |
| CVE-2019-13999 | HIGH | 7.8 | 0.2% | Sep 8, 2020 | u'Lack of check for integer overflow for round up and addition operations result into memory corruption and potential in... |
| CVE-2019-13998 | HIGH | 7.8 | 0.2% | Sep 8, 2020 | u'Lack of check that the TX FIFO write and read indices that are read from shared RAM are less than the FIFO size result... |
| CVE-2019-13995 | HIGH | 7.8 | 0.2% | Sep 8, 2020 | u'Lack of integer overflow check for addition of fragment size and remaining size that are read from shared memory can l... |
| CVE-2019-13994 | HIGH | 7.8 | 0.2% | Sep 8, 2020 | u'Lack of check that the current received data fragment size of a particular packet that are read from shared memory are... |
| CVE-2019-13992 | HIGH | 7.8 | 0.2% | Sep 8, 2020 | u'Out of bound memory access if stack push and pop operation are performed without doing a bound check on stack top' in ... |
| CVE-2019-10629 | HIGH | 7.8 | 0.2% | Sep 8, 2020 | u'User Process can potentially corrupt kernel virtual page by passing a crafted page in API' in Snapdragon Auto, Snapdra... |
| CVE-2019-10628 | HIGH | 7.8 | 0.2% | Sep 8, 2020 | u'Memory can be potentially corrupted if random index is allowed to manipulate TLB entries in Kernel from user library' ... |
| CVE-2019-10615 | HIGH | 7.8 | 0.2% | Sep 8, 2020 | u'Possibility of integer overflow in keymaster 4 while allocating memory due to multiplication of large numcerts value a... |
| CVE-2019-10596 | HIGH | 7.8 | 0.2% | Sep 8, 2020 | u'Improper access control can lead signed process to guess pid of other processes and access their address space' in Sna... |
| CVE-2019-10562 | HIGH | 7.8 | 0.2% | Sep 8, 2020 | u'Improper authentication and signature verification of debug polices in secure boot loader will allow unverified debug ... |
| CVE-2019-10527 | HIGH | 7.8 | 0.2% | Sep 8, 2020 | u'SMEM partition can be manipulated in case of any compromise on HLOS, thus resulting in access to memory outside of SME... |
| CVE-2019-20916 | HIGH | 7.5 | 3.0% | Sep 4, 2020 | The pip package before 19.2 for Python allows Directory Traversal when a URL is given in an install command, because a C... |
| CVE-2019-3881 | HIGH | 7.8 | 0.5% | Sep 4, 2020 | Bundler prior to 2.1.0 uses a predictable path in /tmp/, created with insecure permissions as a storage location for gem... |
| CVE-2019-10679 | HIGH | 7.8 | 0.5% | Sep 3, 2020 | Thomson Reuters Eikon 4.0.42144 allows all local users to modify the service executable file because of weak %PROGRAMFIL... |
| CVE-2019-5645 | HIGH | 7.5 | 41.7% | Sep 1, 2020 | By sending a specially crafted HTTP GET request to a listening Rapid7 Metasploit HTTP handler, an attacker can register ... |
| CVE-2019-5321 | HIGH | 8.8 | 2.4% | Aug 26, 2020 | Aruba Intelligent Edge Switch Series 2540, 2530, 2930F, 2930M, 2920, 5400R, and 3810M with firmware 16.08.* before 16.08... |
| CVE-2019-4713 | HIGH | 8.8 | 2.6% | Aug 26, 2020 | IBM Security Guardium Data Encryption (GDE) 3.0.0.2 could allow a remote authenticated attacker to execute arbitrary com... |
| CVE-2019-4698 | HIGH | 7.5 | 0.8% | Aug 26, 2020 | IBM Security Guardium Data Encryption (GDE) 3.0.0.2 does not require that users should have strong passwords by default,... |
| CVE-2019-4689 | HIGH | 7.5 | 0.6% | Aug 26, 2020 | IBM Security Guardium Data Encryption (GDE) 3.0.0.2 could allow a remote attacker to obtain sensitive information, cause... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now