2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-16772 | MEDIUM | 6.1 | 0.6% | Dec 7, 2019 | The serialize-to-js NPM package before version 3.0.1 is vulnerable to Cross-site Scripting (XSS). It does not properly m... |
| CVE-2019-9464 | MEDIUM | 5.5 | 0.4% | Dec 6, 2019 | In various functions of RecentLocationApps.java, DevicePolicyManagerService.java, and RecognitionService.java, there is ... |
| CVE-2019-2232 | HIGH | 7.5 | 1.1% | Dec 6, 2019 | In handleRun of TextLine.java, there is a possible application crash due to improper input validation. This could lead t... |
| CVE-2019-2231 | MEDIUM | 4.4 | 0.1% | Dec 6, 2019 | In Blob::Blob of blob.cpp, there is a possible unencrypted master key due to improper input validation. This could lead ... |
| CVE-2019-2230 | HIGH | 7.5 | 0.8% | Dec 6, 2019 | In nfcManager_routeAid and nfcManager_unrouteAid of NativeNfcManager.cpp, there is possible memory reuse due to a use af... |
| CVE-2019-2229 | MEDIUM | 5.5 | 0.1% | Dec 6, 2019 | In updateWidget of BaseWidgetProvider.java, there is a possible leak of user data due to a missing permission check. Thi... |
| CVE-2019-2228 | MEDIUM | 5.5 | 0.2% | Dec 6, 2019 | In array_find of array.c, there is a possible out-of-bounds read due to an incorrect bounds check. This could lead to lo... |
| CVE-2019-2227 | MEDIUM | 6.5 | 0.3% | Dec 6, 2019 | In DeepCopy of btif_av.cc, there is a possible out of bounds read due to improper casting. This could lead to remote inf... |
| CVE-2019-2226 | MEDIUM | 5.5 | 0.1% | Dec 6, 2019 | In device_class_to_int of device_class.cc, there is a possible out of bounds read due to improper casting. This could le... |
| CVE-2019-2225 | HIGH | 8.8 | 0.4% | Dec 6, 2019 | When pairing with a Bluetooth device, it may be possible to pair a malicious device without any confirmation from the us... |
| CVE-2019-2224 | — | — | — | Dec 6, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-15140. Reason: This candidate is a duplicate of ... |
| CVE-2019-2223 | HIGH | 7.8 | 0.6% | Dec 6, 2019 | In ihevcd_ref_list of ihevcd_ref_list.c, there is a possible out of bounds write due to a missing bounds check. This cou... |
| CVE-2019-2222 | HIGH | 7.8 | 0.6% | Dec 6, 2019 | n ihevcd_parse_slice_data of ihevcd_parse_slice.c, there is a possible out of bounds write due to a missing bounds check... |
| CVE-2019-2221 | HIGH | 7.8 | 0.2% | Dec 6, 2019 | In hasActivityInVisibleTask of WindowProcessController.java there’s a possible bypass of user interaction requirements d... |
| CVE-2019-2220 | MEDIUM | 5.5 | 0.2% | Dec 6, 2019 | In checkOperation of AppOpsService.java, there is a possible bypass of user interaction requirements due to mishandling ... |
| CVE-2019-2219 | MEDIUM | 4.7 | 0.1% | Dec 6, 2019 | In several functions of NotificationManagerService.java and related files, there is a possible way to record audio from ... |
| CVE-2019-2218 | HIGH | 7.8 | 0.2% | Dec 6, 2019 | In createSessionInternal of PackageInstallerService.java, there is a possible improper permission grant due to a missing... |
| CVE-2019-2217 | HIGH | 7.8 | 0.2% | Dec 6, 2019 | In setCpuVulkanInUse of GpuStats.cpp, there is possible memory corruption due to a use after free. This could lead to lo... |
| CVE-2019-10769 | CRITICAL | 9.8 | 2.6% | Dec 6, 2019 | safer-eval is a npm package to sandbox the he evaluation of code used within the eval function. Affected versions of thi... |
| CVE-2019-18575 | HIGH | 7.1 | 0.3% | Dec 6, 2019 | Dell Command Configure versions prior to 4.2.1 contain an uncontrolled search path vulnerability. A locally authenticate... |
| CVE-2019-11293 | MEDIUM | 6.5 | 1.3% | Dec 6, 2019 | Cloud Foundry UAA Release, versions prior to v74.10.0, when set to logging level DEBUG, logs client_secret credentials w... |
| CVE-2019-16771 | MEDIUM | 6.5 | 1.0% | Dec 6, 2019 | Versions of Armeria 0.85.0 through and including 0.96.0 are vulnerable to HTTP response splitting, which allows remote a... |
| CVE-2019-1551 | MEDIUM | 5.3 | 14.3% | Dec 6, 2019 | There is an overflow bug in the x64_64 Montgomery squaring procedure used in exponentiation with 512-bit moduli. No EC a... |
| CVE-2019-18672 | HIGH | 7.5 | 0.8% | Dec 6, 2019 | Insufficient checks in the finite state machine of the ShapeShift KeepKey hardware wallet before firmware 6.2.2 allow a ... |
| CVE-2019-18671 | CRITICAL | 9.8 | 3.3% | Dec 6, 2019 | Insufficient checks in the USB packet handling of the ShapeShift KeepKey hardware wallet before firmware 6.2.2 allow out... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now