2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-16684 | MEDIUM | 4.8 | 1.0% | Sep 30, 2019 | An issue was discovered in the image-manager in Xoops 2.5.10. When any image with a JavaScript payload as its name is ho... |
| CVE-2019-16683 | MEDIUM | 4.8 | 1.0% | Sep 30, 2019 | An issue was discovered in the image-manager in Xoops 2.5.10. When the breadcrumb showing the category name is hovered o... |
| CVE-2019-10540 | CRITICAL | 9.8 | 1.1% | Sep 30, 2019 | Buffer overflow in WLAN NAN function due to lack of check of count value received in NAN availability attribute in Snapd... |
| CVE-2019-10539 | CRITICAL | 9.8 | 0.9% | Sep 30, 2019 | Possible buffer overflow issue due to lack of length check when parsing the extended cap IE header length in Snapdragon ... |
| CVE-2019-10538 | CRITICAL | 9.8 | 1.1% | Sep 30, 2019 | Lack of check of address range received from firmware response allows modem to respond arbitrary pages into its address ... |
| CVE-2019-10510 | HIGH | 8.2 | 0.7% | Sep 30, 2019 | BT process died and BT toggled due to null pointer dereference when invalid vendor pass through command sent from remote... |
| CVE-2019-10509 | CRITICAL | 9.8 | 0.9% | Sep 30, 2019 | Device record of the pairing device used after free during ACL disconnection in Snapdragon Auto, Snapdragon Compute, Sna... |
| CVE-2019-10508 | HIGH | 7.8 | 0.2% | Sep 30, 2019 | Lack of input validation for data received from user space can lead to OOB access in WLAN in Snapdragon Auto, Snapdragon... |
| CVE-2019-10507 | HIGH | 7.8 | 0.2% | Sep 30, 2019 | Lack of check of extscan change results received from firmware can lead to an out of buffer read in Snapdragon Auto, Sna... |
| CVE-2019-10506 | HIGH | 7.8 | 0.2% | Sep 30, 2019 | While processing QCA_NL80211_VENDOR_SUBCMD_AVOID_FREQUENCY vendor command, driver does not validate the data obtained fr... |
| CVE-2019-10501 | HIGH | 7.8 | 0.2% | Sep 30, 2019 | Possible use after free issue due to improper input validation in volume listener library in Snapdragon Auto, Snapdragon... |
| CVE-2019-10499 | HIGH | 7.8 | 0.2% | Sep 30, 2019 | Improper validation of read and write index of tx and rx fifo`s before using for data copy from fifo can lead to out-of-... |
| CVE-2019-10498 | HIGH | 7.8 | 0.2% | Sep 30, 2019 | Buffer overflow scenario if the client sends more than 5 io_vec requests to the server in Snapdragon Auto, Snapdragon Co... |
| CVE-2019-10497 | HIGH | 7.8 | 0.2% | Sep 30, 2019 | Use after free issue occurs If another instance of open for voice_svc node has been called from application without clos... |
| CVE-2019-10492 | HIGH | 7.8 | 0.1% | Sep 30, 2019 | Boot image not getting verified by AVB in Snapdragon Auto, Snapdragon Mobile, Snapdragon Wearables in MDM9607, MSM8909W,... |
| CVE-2019-10489 | HIGH | 7.5 | 0.8% | Sep 30, 2019 | Possible null-pointer dereference can occur while parsing avi clip during copy in Snapdragon Auto, Snapdragon Compute, S... |
| CVE-2019-17046 | HIGH | 7.2 | 4.4% | Sep 30, 2019 | Ilch 2.1.22 allows remote code execution because php is listed under "Allowed files" on the index.php/admin/media/settin... |
| CVE-2019-17045 | MEDIUM | 4.8 | 0.7% | Sep 30, 2019 | Ilch 2.1.22 allows stored XSS via the title, text, or email id to the Jobs Tab. |
| CVE-2019-17040 | CRITICAL | 9.8 | 2.4% | Sep 30, 2019 | contrib/pmdb2diag/pmdb2diag.c in Rsyslog v8.1908.0 allows out-of-bounds access because the level length is mishandled. |
| CVE-2019-16916 | — | — | — | Sep 30, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2019-16999 | CRITICAL | 9.8 | 1.5% | Sep 30, 2019 | CloudBoot through 2019-03-08 allows SQL Injection via a crafted Status field in JSON data to the api/osinstall/v1/device... |
| CVE-2019-16997 | HIGH | 7.2 | 49.4% | Sep 30, 2019 | In Metinfo 7.0.0beta, a SQL Injection was discovered in app/system/language/admin/language_general.class.php via the adm... |
| CVE-2019-16996 | HIGH | 7.2 | 12.4% | Sep 30, 2019 | In Metinfo 7.0.0beta, a SQL Injection was discovered in app/system/product/admin/product_admin.class.php via the admin/?... |
| CVE-2019-16995 | HIGH | 7.5 | 3.5% | Sep 30, 2019 | In the Linux kernel before 5.0.3, a memory leak exits in hsr_dev_finalize() in net/hsr/hsr_device.c if hsr_add_port fail... |
| CVE-2019-16994 | MEDIUM | 4.7 | 0.5% | Sep 30, 2019 | In the Linux kernel before 5.0, a memory leak exists in sit_init_net() in net/ipv6/sit.c when register_netdev() fails to... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now