2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-2332 | CRITICAL | 9.8 | 0.9% | Nov 6, 2019 | Memory corruption while accessing the memory as payload size is not validated before access in Snapdragon Auto, Snapdrag... |
| CVE-2019-2331 | CRITICAL | 9.8 | 1.2% | Nov 6, 2019 | Possible Integer overflow because of subtracting two integers without checking if the result would overflow or not in Sn... |
| CVE-2019-2325 | CRITICAL | 9.8 | 0.9% | Nov 6, 2019 | Out of boundary access due to token received from ADSP and is used without validation as an index into the array in Snap... |
| CVE-2019-2324 | CRITICAL | 9.8 | 0.9% | Nov 6, 2019 | When ADSP is compromised, the audio port index that`s returned from ADSP might be out of the valid range and leads to ou... |
| CVE-2019-2323 | CRITICAL | 9.8 | 0.9% | Nov 6, 2019 | Lack of check to ensure crypto engine data passed by user is initialized can result in bus error in Snapdragon Auto, Sna... |
| CVE-2019-2302 | CRITICAL | 9.8 | 0.7% | Nov 6, 2019 | While processing vendor command which contains corrupted channel count, an integer overflow occurs and finally will lead... |
| CVE-2019-2285 | CRITICAL | 9.8 | 1.1% | Nov 6, 2019 | Out of bound write issue is observed while giving information about properties that have been set so far for playing vid... |
| CVE-2019-2283 | CRITICAL | 9.8 | 0.9% | Nov 6, 2019 | Improper validation of read and write index of tx and rx fifo`s before calculating pointer can lead to out-of-bound acce... |
| CVE-2019-2258 | CRITICAL | 9.8 | 0.9% | Nov 6, 2019 | Improper validation of array index causes OOB write and then leads to memory corruption in MMCP in Snapdragon Auto, Snap... |
| CVE-2019-2249 | CRITICAL | 9.8 | 1.4% | Nov 6, 2019 | Kernel can do a memory read from arbitrary address passed by user during execution of a syscall in Snapdragon Auto, Snap... |
| CVE-2019-10565 | CRITICAL | 9.8 | 0.7% | Nov 6, 2019 | Double free issue can happen when sensor power settings is freed by some thread while another thread try to access. in S... |
| CVE-2019-10542 | CRITICAL | 9.8 | 0.7% | Nov 6, 2019 | Buffer over-read may occur when downloading a corrupted firmware file that has chunk length in header which doesn`t matc... |
| CVE-2019-10541 | CRITICAL | 9.8 | 0.9% | Nov 6, 2019 | Dereference on uninitialized buffer can happen when parsing FLV clip with corrupted codec specific data in Snapdragon Au... |
| CVE-2019-10534 | CRITICAL | 9.8 | 1.1% | Nov 6, 2019 | Null-pointer dereference can occur while accessing the super index entry when it is not been allocated in Snapdragon Aut... |
| CVE-2019-10533 | CRITICAL | 9.8 | 0.9% | Nov 6, 2019 | Out of bound access due to improper validation of array index cause the index table entry to get corrupt in Snapdragon A... |
| CVE-2019-10531 | CRITICAL | 9.8 | 0.9% | Nov 6, 2019 | Incorrect reading of system image resulting in buffer overflow when size of system image is increased in Snapdragon Auto... |
| CVE-2019-10528 | CRITICAL | 9.8 | 0.7% | Nov 6, 2019 | Use after free issue in kernel while accessing freed mdlog session info and its attributes after closing the session in ... |
| CVE-2019-10522 | CRITICAL | 9.8 | 0.7% | Nov 6, 2019 | While playing the clip which is nonstandard buffer overflow can occur while parsing in Snapdragon Auto, Snapdragon Compu... |
| CVE-2019-10505 | CRITICAL | 9.8 | 0.7% | Nov 6, 2019 | Out of bound access while processing a non-standard IE measurement request with length crossing past the size of frame i... |
| CVE-2019-12918 | CRITICAL | 9.8 | 1.1% | Nov 6, 2019 | Quest KACE Systems Management Appliance Server Center version 9.1.317 is vulnerable to SQL injection. The affected file ... |
| CVE-2019-18784 | CRITICAL | 9.8 | 1.1% | Nov 6, 2019 | SuiteCRM 7.10.x versions prior to 7.10.21 and 7.11.x versions prior to 7.11.9 allow SQL Injection. |
| CVE-2019-8158 | CRITICAL | 9.8 | 1.3% | Nov 6, 2019 | An XPath entity injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. A... |
| CVE-2019-8149 | CRITICAL | 9.8 | 2.1% | Nov 6, 2019 | Insecure authentication and session management vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to... |
| CVE-2019-8144 | CRITICAL | 9.8 | 2.5% | Nov 6, 2019 | A remote code execution vulnerability exists in Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An unauthenticated user can inse... |
| CVE-2019-8136 | CRITICAL | 9.8 | 1.2% | Nov 6, 2019 | An insecure component vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. Magen... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now