2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-15930MEDIUM4.3Intesync Solismed 3.3sp allows Clickjacking.
CVE-2019-14849MEDIUM5.4A vulnerability was found in 3scale before version 2.6, did not set the HTTPOnly attribute on the user session cookie. A...
CVE-2019-13945MEDIUM6.8A vulnerability has been identified in SIMATIC S7-1200 CPU family (incl. SIPLUS variants) (All versions), SIMATIC S7-120...
CVE-2019-13927MEDIUM5.3A vulnerability has been identified in Desigo PX automation controllers PXC00-E.D, PXC50-E.D, PXC100-E.D, PXC200-E.D wit...
CVE-2019-2338HIGH7.1Crafted image that has a valid signature from a non-QC entity can be loaded which can read/write memory that belongs to ...
CVE-2019-2337HIGH7.5While Skipping unknown IES, EMM is reading the buffer even if the no of bytes to read are more than message length which...
CVE-2019-2321HIGH7.8Incorrect length used while validating the qsee log buffer sent from HLOS which could then lead to remap conflict in Sna...
CVE-2019-2320CRITICAL9.8Possible out of bounds write in a MT SMS/SS scenario due to improper validation of array index in Snapdragon Auto, Snapd...
CVE-2019-2319HIGH7.8HLOS could corrupt CPZ page table memory for S1 managed VMs in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectiv...
CVE-2019-2310HIGH7.5Out of bound read would occur while trying to read action category and action ID without validating the action length of...
CVE-2019-2288HIGH7.8Out of bound write in TZ while copying the secure dump structure on HLOS provided buffer as a part of memory dump in Sna...
CVE-2019-10618MEDIUM5.5Driver may access an invalid address while processing IO control due to lack of check of address validation in Snapdrago...
CVE-2019-10592HIGH7.8Possible integer overflow while multiplying two integers of 32 bit in QDCM API of get display modes as there is no check...
CVE-2019-10571HIGH7.8Snapshot of IB can lead to invalid address access due to missing check for size in the related function in Snapdragon Au...
CVE-2019-10559CRITICAL9.8Accessing data buffer beyond the available data while parsing ogg clip can lead to null-pointer dereference and then mem...
CVE-2019-10555HIGH7.8Buffer overflow can occur due to usage of wrong datatype and missing length check before copying into buffer in Snapdrag...
CVE-2019-10545MEDIUM5.5Null pointer dereference issue in kernel due to missing check related to LLC support in GPU in Snapdragon Auto, Snapdrag...
CVE-2019-10530HIGH7.8Lack of check of data truncation on user supplied data in kernel leads to buffer overflow in Snapdragon Auto, Snapdragon...
CVE-2019-10520MEDIUM5.5An unprivileged application can allocate GPU memory by calling memory allocation ioctl function and can exhaust all the ...
CVE-2019-10511CRITICAL9.8Possibility of memory overflow while decoding GSNDCP compressed mode PDU in Snapdragon Auto, Snapdragon Compute, Snapdra...
CVE-2019-10494HIGH8.1Race condition between the camera functions due to lack of resource lock which will lead to memory corruption and UAF is...
CVE-2019-10493CRITICAL9.8Position determination accuracy may be degraded due to wrongly decoded information in Snapdragon Auto, Snapdragon Comput...
CVE-2019-10485HIGH7.5Infinite loop while decoding compressed data can lead to overrun condition in Snapdragon Auto, Snapdragon Compute, Snapd...
CVE-2019-10484MEDIUM5.5Use after free issue occurs when command destructors access dynamically allocated response buffer which is already deall...
CVE-2019-19748MEDIUM6.1The Work Time Calendar app before 4.7.1 for Jira allows XSS.

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now