2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-10525 | CRITICAL | 9.8 | 0.9% | Dec 18, 2019 | Buffer overflow during SIB read when network configures complete sib list along with first and last segment of other SIB... |
| CVE-2019-10518 | HIGH | 7.8 | 0.2% | Dec 18, 2019 | Use after free of a pointer in iWLAN scenario during netmgr state transition to CONNECT in Snapdragon Auto, Snapdragon C... |
| CVE-2019-10517 | HIGH | 7.8 | 0.2% | Dec 18, 2019 | Memory is being freed up twice when two concurrent threads are executing in parallel in Snapdragon Auto, Snapdragon Comp... |
| CVE-2019-10516 | CRITICAL | 9.8 | 0.9% | Dec 18, 2019 | Multiple read overflows in MM while decoding service accept,service reject,attach reject and MT detach in Snapdragon Aut... |
| CVE-2019-10513 | MEDIUM | 5.5 | 0.2% | Dec 18, 2019 | Possibility of Null pointer access if the SPDM commands are executed in the non-standard way in Trustzone in Snapdragon ... |
| CVE-2019-10500 | CRITICAL | 9.8 | 0.9% | Dec 18, 2019 | While processing MT Secondary PDP request, Buffer overflow will happen due to incorrect calculation of buffer size in Sn... |
| CVE-2019-10487 | CRITICAL | 9.8 | 0.9% | Dec 18, 2019 | Buffer over read can happen while parsing SMS OTA messages at transport layer if network sends un-intended values in Sna... |
| CVE-2019-10482 | MEDIUM | 5.9 | 0.6% | Dec 18, 2019 | Due to the use of non-time-constant comparison functions there is issue in timing side channels which can be used as a p... |
| CVE-2019-10481 | HIGH | 7.8 | 0.2% | Dec 18, 2019 | Out of bound access occurs while handling the WMI FW event due to lack of check of buffer argument which comes directly ... |
| CVE-2019-10480 | HIGH | 7.8 | 0.2% | Dec 18, 2019 | Out of bound write can happen in WMI firmware event handler due to lack of validation of data received from WLAN firmwar... |
| CVE-2019-19846 | CRITICAL | 9.8 | 1.7% | Dec 18, 2019 | In Joomla! before 3.9.14, the lack of validation of configuration parameters used in SQL queries caused various SQL inje... |
| CVE-2019-19845 | MEDIUM | 5.3 | 1.1% | Dec 18, 2019 | In Joomla! before 3.9.14, a missing access check in framework files could lead to a path disclosure. |
| CVE-2019-19775 | MEDIUM | 6.1 | 0.9% | Dec 18, 2019 | The image thumbnailing handler in Zulip Server versions 1.9.0 to before 2.0.8 allowed an open redirect that was visible ... |
| CVE-2019-15013 | MEDIUM | 4.3 | 1.2% | Dec 18, 2019 | The WorkflowResource class removeStatus method in Jira before version 7.13.12, from version 8.0.0 before version 8.4.3, ... |
| CVE-2019-7481 | HIGH | 7.5 | 99.9% | Dec 17, 2019 | Vulnerability in SonicWall SMA100 allow unauthenticated user to gain read-only access to unauthorized resources. This vu... |
| CVE-2019-18257 | CRITICAL | 9.8 | 2.8% | Dec 17, 2019 | In Advantech DiagAnywhere Server, Versions 3.07.11 and prior, multiple stack-based buffer overflow vulnerabilities exist... |
| CVE-2019-11657 | HIGH | 8.8 | 0.5% | Dec 17, 2019 | Cross-Site Request Forgery vulnerability in all Micro Focus ArcSight Logger affecting all product versions below version... |
| CVE-2019-3996 | MEDIUM | 6.5 | 5.9% | Dec 17, 2019 | ELOG 3.1.4-57bea22 and below can be used as an HTTP GET request proxy when unauthenticated remote attackers send crafted... |
| CVE-2019-3995 | HIGH | 7.5 | 28.5% | Dec 17, 2019 | ELOG 3.1.4-57bea22 and below is affected by a denial of service vulnerability due to a NULL pointer dereference. A remot... |
| CVE-2019-3994 | HIGH | 7.5 | 2.9% | Dec 17, 2019 | ELOG 3.1.4-57bea22 and below is affected by a denial of service vulnerability due to a use after free. A remote unauthen... |
| CVE-2019-3993 | HIGH | 7.5 | 45.7% | Dec 17, 2019 | ELOG 3.1.4-57bea22 and below is affected by an information disclosure vulnerability. A remote unauthenticated attacker c... |
| CVE-2019-3992 | HIGH | 7.5 | 1.3% | Dec 17, 2019 | ELOG 3.1.4-57bea22 and below is affected by an information disclosure vulnerability. A remote unauthenticated attacker c... |
| CVE-2019-17337 | MEDIUM | 5.4 | 0.7% | Dec 17, 2019 | The Spotfire library component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace and TIBCO ... |
| CVE-2019-17336 | MEDIUM | 6.5 | 0.9% | Dec 17, 2019 | The Data access layer component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace and TIBCO... |
| CVE-2019-17335 | MEDIUM | 6.5 | 0.8% | Dec 17, 2019 | The Data access layer component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace and TIBCO... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now