2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-2135 | — | — | 0.5% | Aug 20, 2019 | In Mfc_Transceive of phNxpExtns_MifareStd.cpp, there is a possible out of bounds read due to a missing bounds check. Thi... |
| CVE-2019-2134 | — | — | 0.5% | Aug 20, 2019 | In phFriNfc_ExtnsTransceive of phNxpExtns_MifareStd.cpp, there is a possible out of bounds write due to an integer overf... |
| CVE-2019-2133 | — | — | 0.5% | Aug 20, 2019 | In Mfc_Transceive of phNxpExtns_MifareStd.cpp, there is a possible out of bounds write due to a heap buffer overflow. Th... |
| CVE-2019-2132 | — | — | 0.5% | Aug 20, 2019 | It is possible to overlay the VPN dialog by a malicious application. This could lead to local escalation of privilege wi... |
| CVE-2019-2131 | — | — | 0.5% | Aug 20, 2019 | An application with overlay permission can display overlays on top of settings UI. This could lead to local escalation o... |
| CVE-2019-2130 | — | — | 1.7% | Aug 20, 2019 | In CompilationJob::FinalizeJob of compiler.cc, there is a possible remote code execution due to type confusion. This cou... |
| CVE-2019-2129 | — | — | 0.7% | Aug 20, 2019 | In extract3GPPGlobalDescriptions of TextDescriptions.cpp, there is a possible out of bounds read due to a missing bounds... |
| CVE-2019-2128 | — | — | 0.2% | Aug 20, 2019 | In ACELP_4t64_fx of c4t64fx.c, there is a possible out of bounds write due to a missing bounds check. This could lead to... |
| CVE-2019-2127 | — | — | 0.2% | Aug 20, 2019 | In AudioInputDescriptor::setClientActive of AudioInputDescriptor.cpp, there is possible memory corruption due to a use a... |
| CVE-2019-2126 | HIGH | 8.8 | 5.4% | Aug 20, 2019 | In ParseContentEncodingEntry of mkvparser.cc, there is a possible double free due to a missing reset of a freed pointer.... |
| CVE-2019-2125 | — | — | 0.1% | Aug 20, 2019 | In ChangeDefaultDialerDialog.java, there is a possible escalation of privilege due to an overlay attack. This could lead... |
| CVE-2019-2122 | — | — | 0.2% | Aug 20, 2019 | In LockTaskController.lockKeyguardIfNeeded of the LockTaskController.java, there was a difference in the handling of the... |
| CVE-2019-2121 | — | — | 0.1% | Aug 20, 2019 | In ActivityManagerService.attachApplication of ActivityManagerService, there is a possible race condition. This could le... |
| CVE-2019-2120 | — | — | 0.2% | Aug 20, 2019 | In OatFileAssistant::GenerateOatFile of oat_file_assistant.cc, there is a possible file corruption issue due to an insec... |
| CVE-2019-13520 | HIGH | 7.8 | 2.9% | Aug 20, 2019 | Multiple buffer overflow issues have been identified in Alpha5 Smart Loader: All versions prior to 4.2. An attacker coul... |
| CVE-2019-11924 | — | — | 2.4% | Aug 20, 2019 | A peer could send empty handshake fragments containing only padding which would be kept in memory until a full handshake... |
| CVE-2019-7594 | MEDIUM | 6.8 | 0.6% | Aug 20, 2019 | Metasys® ADS/ADX servers and NAE/NIE/NCE engines prior to 9.0 make use of a hardcoded RC2 key for certain encryption ope... |
| CVE-2019-7593 | MEDIUM | 6.8 | 0.8% | Aug 20, 2019 | Metasys® ADS/ADX servers and NAE/NIE/NCE engines prior to 9.0 make use of a shared RSA key pair for certain encryption o... |
| CVE-2019-4485 | MEDIUM | 4.3 | 1.0% | Aug 20, 2019 | IBM Emptoris Sourcing 10.1.0 through 10.1.3, IBM Contract Management 10.1.0 through 10.1.3, and IBM Emptoris Spend Analy... |
| CVE-2019-4484 | MEDIUM | 4.3 | 1.0% | Aug 20, 2019 | IBM Emptoris Sourcing 10.1.0 through 10.1.3, IBM Contract Management 10.1.0 through 10.1.3, and IBM Emptoris Spend Analy... |
| CVE-2019-4483 | CRITICAL | 9.8 | 2.0% | Aug 20, 2019 | IBM Contract Management 10.1.0 through 10.1.3 and IBM Emptoris Spend Analysis 10.1.0 through 10.1.3 is vulnerable to SQL... |
| CVE-2019-4481 | CRITICAL | 9.8 | 2.0% | Aug 20, 2019 | IBM Contract Management 10.1.0 through 10.1.3 and IBM Emptoris Spend Analysis 10.1.0 through 10.1.3 is vulnerable to SQL... |
| CVE-2019-4460 | HIGH | 7.5 | 2.6% | Aug 20, 2019 | IBM API Connect 5.0.0.0 through 5.0.8.6 developer portal could allow a remote attacker to traverse directories on the sy... |
| CVE-2019-4433 | HIGH | 8.2 | 3.9% | Aug 20, 2019 | IBM InfoSphere Global Name Management 5.0 and 6.0 and IBM InfoSphere Identity Insight 8.1 and 9.0 is vulnerable to an XM... |
| CVE-2019-4425 | MEDIUM | 5.7 | 1.2% | Aug 20, 2019 | IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, and 18.0.0.2 could allow a user to obtain highly sensitive informat... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now