2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-13097 | — | — | 1.4% | Jul 22, 2019 | The application API of Cat Runner Decorate Home version 2.8.0 for Android does not sufficiently verify inputs that are a... |
| CVE-2019-13096 | — | — | 1.1% | Jul 22, 2019 | TronLink Wallet 2.2.0 stores user wallet keystore in plaintext and places them in insecure storage. An attacker can read... |
| CVE-2019-12326 | HIGH | 7.2 | 3.0% | Jul 22, 2019 | Missing file and path validation in the ringtone upload function of the Akuvox R50P VoIP phone 50.0.6.156 allows an atta... |
| CVE-2019-1010228 | CRITICAL | 9.8 | 7.6% | Jul 22, 2019 | OFFIS.de DCMTK 3.6.3 and below is affected by: Buffer Overflow. The impact is: Possible code execution and confirmed Den... |
| CVE-2019-13100 | — | — | 0.8% | Jul 22, 2019 | The Send Anywhere application 9.4.18 for Android stores confidential information insecurely on the system (i.e., in clea... |
| CVE-2019-13099 | — | — | 0.8% | Jul 22, 2019 | The Momo application 2.1.9 for Android stores confidential information insecurely on the system (i.e., in cleartext), wh... |
| CVE-2019-13098 | — | — | 1.3% | Jul 22, 2019 | The user password via the registration form of TronLink Wallet 2.2.0 is stored in the log when the class CreateWalletTwo... |
| CVE-2019-12325 | HIGH | 8.8 | 2.0% | Jul 22, 2019 | The Htek UC902 VoIP phone web management interface contains several buffer overflow vulnerabilities in the firmware vers... |
| CVE-2019-12324 | HIGH | 7.2 | 4.3% | Jul 22, 2019 | A command injection (missing input validation) issue in the IP address field for the logging server in the configuration... |
| CVE-2019-1010232 | — | — | 1.0% | Jul 22, 2019 | Juniper juniper/libslax libslax latest version (as of commit 084ddf6ab4a55b59dfa9a53f9c5f14d192c4f8e5 Commits on Sep 1, ... |
| CVE-2019-9959 | MEDIUM | 6.5 | 1.9% | Jul 22, 2019 | The JPXStream::init function in Poppler 0.78.0 and earlier doesn't check for negative values of stream length, leading t... |
| CVE-2019-1010237 | — | — | 1.7% | Jul 22, 2019 | Ilias 5.3 before 5.3.12; 5.2 before 5.2.21 is affected by: Cross Site Scripting (XSS) - CWE-79 Type 2: Stored XSS (or Pe... |
| CVE-2019-1010235 | — | — | 0.6% | Jul 22, 2019 | Frog CMS 1.1 is affected by: Cross Site Scripting (XSS). The impact is: Cookie stealing, Alert pop-up on page, Redirecti... |
| CVE-2019-1010234 | — | — | 1.7% | Jul 22, 2019 | The Linux Foundation ONOS 1.15.0 and ealier is affected by: Improper Input Validation. The impact is: The attacker can r... |
| CVE-2019-4267 | HIGH | 7.8 | 0.4% | Jul 22, 2019 | The IBM Spectrum Protect 7.1 and 8.1 Backup-Archive Client is vulnerable to a buffer overflow. This could allow executio... |
| CVE-2019-4236 | MEDIUM | 4.4 | 0.3% | Jul 22, 2019 | A IBM Spectrum Protect 7.l client backup or archive operation running for an HP-UX VxFS object is silently skipping Acce... |
| CVE-2019-2292 | — | — | 0.2% | Jul 22, 2019 | Out of bound access can occur due to buffer copy without checking size of input received from WLAN firmware in Snapdrago... |
| CVE-2019-2287 | — | — | 0.9% | Jul 22, 2019 | Improper validation for inputs received from firmware can lead to an out of bound write issue in video driver. in Snapdr... |
| CVE-2019-2279 | — | — | 0.9% | Jul 22, 2019 | Shared memory gets updated with invalid data and may lead to access beyond the allocated memory. in Snapdragon Auto, Sna... |
| CVE-2019-2277 | — | — | 0.2% | Jul 22, 2019 | Out of bound read can happen due to lack of NULL termination on user controlled data in WLAN in Snapdragon Auto, Snapdra... |
| CVE-2019-2269 | — | — | 0.7% | Jul 22, 2019 | Possible buffer overflow while processing the high level lim process action frame due to improper buffer length validati... |
| CVE-2019-2264 | — | — | 0.2% | Jul 22, 2019 | Null pointer dereference occurs for channel context while opening glink channel in Snapdragon Auto, Snapdragon Consumer ... |
| CVE-2019-2261 | — | — | 0.2% | Jul 22, 2019 | Unauthorized access from GPU subsystem to HLOS or other non secure subsystem memory can lead to information disclosure i... |
| CVE-2019-2260 | — | — | 0.1% | Jul 22, 2019 | A race condition occurs while processing perf-event which can lead to a use after free condition in Snapdragon Auto, Sna... |
| CVE-2019-2243 | — | — | 0.2% | Jul 22, 2019 | Possible buffer overflow at the end of iterating loop while getting the version info and lead to information disclosure.... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now