2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-16684MEDIUM4.8An issue was discovered in the image-manager in Xoops 2.5.10. When any image with a JavaScript payload as its name is ho...
CVE-2019-16683MEDIUM4.8An issue was discovered in the image-manager in Xoops 2.5.10. When the breadcrumb showing the category name is hovered o...
CVE-2019-10540CRITICAL9.8Buffer overflow in WLAN NAN function due to lack of check of count value received in NAN availability attribute in Snapd...
CVE-2019-10539CRITICAL9.8Possible buffer overflow issue due to lack of length check when parsing the extended cap IE header length in Snapdragon ...
CVE-2019-10538CRITICAL9.8Lack of check of address range received from firmware response allows modem to respond arbitrary pages into its address ...
CVE-2019-10510HIGH8.2BT process died and BT toggled due to null pointer dereference when invalid vendor pass through command sent from remote...
CVE-2019-10509CRITICAL9.8Device record of the pairing device used after free during ACL disconnection in Snapdragon Auto, Snapdragon Compute, Sna...
CVE-2019-10508HIGH7.8Lack of input validation for data received from user space can lead to OOB access in WLAN in Snapdragon Auto, Snapdragon...
CVE-2019-10507HIGH7.8Lack of check of extscan change results received from firmware can lead to an out of buffer read in Snapdragon Auto, Sna...
CVE-2019-10506HIGH7.8While processing QCA_NL80211_VENDOR_SUBCMD_AVOID_FREQUENCY vendor command, driver does not validate the data obtained fr...
CVE-2019-10501HIGH7.8Possible use after free issue due to improper input validation in volume listener library in Snapdragon Auto, Snapdragon...
CVE-2019-10499HIGH7.8Improper validation of read and write index of tx and rx fifo`s before using for data copy from fifo can lead to out-of-...
CVE-2019-10498HIGH7.8Buffer overflow scenario if the client sends more than 5 io_vec requests to the server in Snapdragon Auto, Snapdragon Co...
CVE-2019-10497HIGH7.8Use after free issue occurs If another instance of open for voice_svc node has been called from application without clos...
CVE-2019-10492HIGH7.8Boot image not getting verified by AVB in Snapdragon Auto, Snapdragon Mobile, Snapdragon Wearables in MDM9607, MSM8909W,...
CVE-2019-10489HIGH7.5Possible null-pointer dereference can occur while parsing avi clip during copy in Snapdragon Auto, Snapdragon Compute, S...
CVE-2019-17046HIGH7.2Ilch 2.1.22 allows remote code execution because php is listed under "Allowed files" on the index.php/admin/media/settin...
CVE-2019-17045MEDIUM4.8Ilch 2.1.22 allows stored XSS via the title, text, or email id to the Jobs Tab.
CVE-2019-17040CRITICAL9.8contrib/pmdb2diag/pmdb2diag.c in Rsyslog v8.1908.0 allows out-of-bounds access because the level length is mishandled.
CVE-2019-16916Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2019-16999CRITICAL9.8CloudBoot through 2019-03-08 allows SQL Injection via a crafted Status field in JSON data to the api/osinstall/v1/device...
CVE-2019-16997HIGH7.2In Metinfo 7.0.0beta, a SQL Injection was discovered in app/system/language/admin/language_general.class.php via the adm...
CVE-2019-16996HIGH7.2In Metinfo 7.0.0beta, a SQL Injection was discovered in app/system/product/admin/product_admin.class.php via the admin/?...
CVE-2019-16995HIGH7.5In the Linux kernel before 5.0.3, a memory leak exits in hsr_dev_finalize() in net/hsr/hsr_device.c if hsr_add_port fail...
CVE-2019-16994MEDIUM4.7In the Linux kernel before 5.0, a memory leak exists in sit_init_net() in net/ipv6/sit.c when register_netdev() fails to...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now