2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2019-14119HIGH7u'While processing SMCInvoke asynchronous message header, message count is modified leading to a TOCTOU race condition a...
CVE-2019-14117HIGH7.8u'Whenever the page list is updated via privileged user, the previous list elements are freed but are not deleted from t...
CVE-2019-14089HIGH7.8u'Keymaster attestation key and device IDs provisioning which is a one time process is incorrectly allowed to be re-prov...
CVE-2019-14074HIGH7.8u'Heap overflow in diag command handler due to lack of check of packet length received from user' in Snapdragon Auto, Sn...
CVE-2019-14065HIGH7.8u'Pointer double free in HavenSvc due to not setting the pointer to NULL after freeing it' in Snapdragon Auto, Snapdrago...
CVE-2019-14056HIGH7.8u'Possible integer overflow in API due to lack of check on large oid range count in cert extension field' in Snapdragon ...
CVE-2019-13999HIGH7.8u'Lack of check for integer overflow for round up and addition operations result into memory corruption and potential in...
CVE-2019-13998HIGH7.8u'Lack of check that the TX FIFO write and read indices that are read from shared RAM are less than the FIFO size result...
CVE-2019-13995HIGH7.8u'Lack of integer overflow check for addition of fragment size and remaining size that are read from shared memory can l...
CVE-2019-13994HIGH7.8u'Lack of check that the current received data fragment size of a particular packet that are read from shared memory are...
CVE-2019-13992HIGH7.8u'Out of bound memory access if stack push and pop operation are performed without doing a bound check on stack top' in ...
CVE-2019-10629HIGH7.8u'User Process can potentially corrupt kernel virtual page by passing a crafted page in API' in Snapdragon Auto, Snapdra...
CVE-2019-10628HIGH7.8u'Memory can be potentially corrupted if random index is allowed to manipulate TLB entries in Kernel from user library' ...
CVE-2019-10615HIGH7.8u'Possibility of integer overflow in keymaster 4 while allocating memory due to multiplication of large numcerts value a...
CVE-2019-10596HIGH7.8u'Improper access control can lead signed process to guess pid of other processes and access their address space' in Sna...
CVE-2019-10562HIGH7.8u'Improper authentication and signature verification of debug polices in secure boot loader will allow unverified debug ...
CVE-2019-10527HIGH7.8u'SMEM partition can be manipulated in case of any compromise on HLOS, thus resulting in access to memory outside of SME...
CVE-2019-20916HIGH7.5The pip package before 19.2 for Python allows Directory Traversal when a URL is given in an install command, because a C...
CVE-2019-3881HIGH7.8Bundler prior to 2.1.0 uses a predictable path in /tmp/, created with insecure permissions as a storage location for gem...
CVE-2019-10679HIGH7.8Thomson Reuters Eikon 4.0.42144 allows all local users to modify the service executable file because of weak %PROGRAMFIL...
CVE-2019-5645HIGH7.5By sending a specially crafted HTTP GET request to a listening Rapid7 Metasploit HTTP handler, an attacker can register ...
CVE-2019-5321HIGH8.8Aruba Intelligent Edge Switch Series 2540, 2530, 2930F, 2930M, 2920, 5400R, and 3810M with firmware 16.08.* before 16.08...
CVE-2019-4713HIGH8.8IBM Security Guardium Data Encryption (GDE) 3.0.0.2 could allow a remote authenticated attacker to execute arbitrary com...
CVE-2019-4698HIGH7.5IBM Security Guardium Data Encryption (GDE) 3.0.0.2 does not require that users should have strong passwords by default,...
CVE-2019-4689HIGH7.5IBM Security Guardium Data Encryption (GDE) 3.0.0.2 could allow a remote attacker to obtain sensitive information, cause...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now