2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-15930 | MEDIUM | 4.3 | 1.4% | Dec 12, 2019 | Intesync Solismed 3.3sp allows Clickjacking. |
| CVE-2019-14849 | MEDIUM | 5.4 | 0.5% | Dec 12, 2019 | A vulnerability was found in 3scale before version 2.6, did not set the HTTPOnly attribute on the user session cookie. A... |
| CVE-2019-13945 | MEDIUM | 6.8 | 0.5% | Dec 12, 2019 | A vulnerability has been identified in SIMATIC S7-1200 CPU family (incl. SIPLUS variants) (All versions), SIMATIC S7-120... |
| CVE-2019-13927 | MEDIUM | 5.3 | 1.7% | Dec 12, 2019 | A vulnerability has been identified in Desigo PX automation controllers PXC00-E.D, PXC50-E.D, PXC100-E.D, PXC200-E.D wit... |
| CVE-2019-2338 | HIGH | 7.1 | 0.2% | Dec 12, 2019 | Crafted image that has a valid signature from a non-QC entity can be loaded which can read/write memory that belongs to ... |
| CVE-2019-2337 | HIGH | 7.5 | 0.7% | Dec 12, 2019 | While Skipping unknown IES, EMM is reading the buffer even if the no of bytes to read are more than message length which... |
| CVE-2019-2321 | HIGH | 7.8 | 0.2% | Dec 12, 2019 | Incorrect length used while validating the qsee log buffer sent from HLOS which could then lead to remap conflict in Sna... |
| CVE-2019-2320 | CRITICAL | 9.8 | 0.9% | Dec 12, 2019 | Possible out of bounds write in a MT SMS/SS scenario due to improper validation of array index in Snapdragon Auto, Snapd... |
| CVE-2019-2319 | HIGH | 7.8 | 0.2% | Dec 12, 2019 | HLOS could corrupt CPZ page table memory for S1 managed VMs in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectiv... |
| CVE-2019-2310 | HIGH | 7.5 | 0.7% | Dec 12, 2019 | Out of bound read would occur while trying to read action category and action ID without validating the action length of... |
| CVE-2019-2288 | HIGH | 7.8 | 0.2% | Dec 12, 2019 | Out of bound write in TZ while copying the secure dump structure on HLOS provided buffer as a part of memory dump in Sna... |
| CVE-2019-10618 | MEDIUM | 5.5 | 0.2% | Dec 12, 2019 | Driver may access an invalid address while processing IO control due to lack of check of address validation in Snapdrago... |
| CVE-2019-10592 | HIGH | 7.8 | 0.2% | Dec 12, 2019 | Possible integer overflow while multiplying two integers of 32 bit in QDCM API of get display modes as there is no check... |
| CVE-2019-10571 | HIGH | 7.8 | 0.2% | Dec 12, 2019 | Snapshot of IB can lead to invalid address access due to missing check for size in the related function in Snapdragon Au... |
| CVE-2019-10559 | CRITICAL | 9.8 | 0.9% | Dec 12, 2019 | Accessing data buffer beyond the available data while parsing ogg clip can lead to null-pointer dereference and then mem... |
| CVE-2019-10555 | HIGH | 7.8 | 0.2% | Dec 12, 2019 | Buffer overflow can occur due to usage of wrong datatype and missing length check before copying into buffer in Snapdrag... |
| CVE-2019-10545 | MEDIUM | 5.5 | 0.2% | Dec 12, 2019 | Null pointer dereference issue in kernel due to missing check related to LLC support in GPU in Snapdragon Auto, Snapdrag... |
| CVE-2019-10530 | HIGH | 7.8 | 0.2% | Dec 12, 2019 | Lack of check of data truncation on user supplied data in kernel leads to buffer overflow in Snapdragon Auto, Snapdragon... |
| CVE-2019-10520 | MEDIUM | 5.5 | 0.2% | Dec 12, 2019 | An unprivileged application can allocate GPU memory by calling memory allocation ioctl function and can exhaust all the ... |
| CVE-2019-10511 | CRITICAL | 9.8 | 0.9% | Dec 12, 2019 | Possibility of memory overflow while decoding GSNDCP compressed mode PDU in Snapdragon Auto, Snapdragon Compute, Snapdra... |
| CVE-2019-10494 | HIGH | 8.1 | 0.3% | Dec 12, 2019 | Race condition between the camera functions due to lack of resource lock which will lead to memory corruption and UAF is... |
| CVE-2019-10493 | CRITICAL | 9.8 | 0.9% | Dec 12, 2019 | Position determination accuracy may be degraded due to wrongly decoded information in Snapdragon Auto, Snapdragon Comput... |
| CVE-2019-10485 | HIGH | 7.5 | 0.7% | Dec 12, 2019 | Infinite loop while decoding compressed data can lead to overrun condition in Snapdragon Auto, Snapdragon Compute, Snapd... |
| CVE-2019-10484 | MEDIUM | 5.5 | 0.2% | Dec 12, 2019 | Use after free issue occurs when command destructors access dynamically allocated response buffer which is already deall... |
| CVE-2019-19748 | MEDIUM | 6.1 | 0.7% | Dec 12, 2019 | The Work Time Calendar app before 4.7.1 for Jira allows XSS. |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now