2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-2135In Mfc_Transceive of phNxpExtns_MifareStd.cpp, there is a possible out of bounds read due to a missing bounds check. Thi...
CVE-2019-2134In phFriNfc_ExtnsTransceive of phNxpExtns_MifareStd.cpp, there is a possible out of bounds write due to an integer overf...
CVE-2019-2133In Mfc_Transceive of phNxpExtns_MifareStd.cpp, there is a possible out of bounds write due to a heap buffer overflow. Th...
CVE-2019-2132It is possible to overlay the VPN dialog by a malicious application. This could lead to local escalation of privilege wi...
CVE-2019-2131An application with overlay permission can display overlays on top of settings UI. This could lead to local escalation o...
CVE-2019-2130In CompilationJob::FinalizeJob of compiler.cc, there is a possible remote code execution due to type confusion. This cou...
CVE-2019-2129In extract3GPPGlobalDescriptions of TextDescriptions.cpp, there is a possible out of bounds read due to a missing bounds...
CVE-2019-2128In ACELP_4t64_fx of c4t64fx.c, there is a possible out of bounds write due to a missing bounds check. This could lead to...
CVE-2019-2127In AudioInputDescriptor::setClientActive of AudioInputDescriptor.cpp, there is possible memory corruption due to a use a...
CVE-2019-2126HIGH8.8In ParseContentEncodingEntry of mkvparser.cc, there is a possible double free due to a missing reset of a freed pointer....
CVE-2019-2125In ChangeDefaultDialerDialog.java, there is a possible escalation of privilege due to an overlay attack. This could lead...
CVE-2019-2122In LockTaskController.lockKeyguardIfNeeded of the LockTaskController.java, there was a difference in the handling of the...
CVE-2019-2121In ActivityManagerService.attachApplication of ActivityManagerService, there is a possible race condition. This could le...
CVE-2019-2120In OatFileAssistant::GenerateOatFile of oat_file_assistant.cc, there is a possible file corruption issue due to an insec...
CVE-2019-13520HIGH7.8Multiple buffer overflow issues have been identified in Alpha5 Smart Loader: All versions prior to 4.2. An attacker coul...
CVE-2019-11924A peer could send empty handshake fragments containing only padding which would be kept in memory until a full handshake...
CVE-2019-7594MEDIUM6.8Metasys® ADS/ADX servers and NAE/NIE/NCE engines prior to 9.0 make use of a hardcoded RC2 key for certain encryption ope...
CVE-2019-7593MEDIUM6.8Metasys® ADS/ADX servers and NAE/NIE/NCE engines prior to 9.0 make use of a shared RSA key pair for certain encryption o...
CVE-2019-4485MEDIUM4.3IBM Emptoris Sourcing 10.1.0 through 10.1.3, IBM Contract Management 10.1.0 through 10.1.3, and IBM Emptoris Spend Analy...
CVE-2019-4484MEDIUM4.3IBM Emptoris Sourcing 10.1.0 through 10.1.3, IBM Contract Management 10.1.0 through 10.1.3, and IBM Emptoris Spend Analy...
CVE-2019-4483CRITICAL9.8IBM Contract Management 10.1.0 through 10.1.3 and IBM Emptoris Spend Analysis 10.1.0 through 10.1.3 is vulnerable to SQL...
CVE-2019-4481CRITICAL9.8IBM Contract Management 10.1.0 through 10.1.3 and IBM Emptoris Spend Analysis 10.1.0 through 10.1.3 is vulnerable to SQL...
CVE-2019-4460HIGH7.5IBM API Connect 5.0.0.0 through 5.0.8.6 developer portal could allow a remote attacker to traverse directories on the sy...
CVE-2019-4433HIGH8.2IBM InfoSphere Global Name Management 5.0 and 6.0 and IBM InfoSphere Identity Insight 8.1 and 9.0 is vulnerable to an XM...
CVE-2019-4425MEDIUM5.7IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, and 18.0.0.2 could allow a user to obtain highly sensitive informat...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now