2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-18426 | HIGH | 8.2 | 67.9% | Jan 21, 2020 | A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.... |
| CVE-2019-17584 | HIGH | 7.5 | 1.1% | Jan 21, 2020 | The Meinberg SyncBox/PTP/PTPv2 devices have default SSH keys which allow attackers to get root access to the devices. Al... |
| CVE-2019-18932 | HIGH | 7 | 0.3% | Jan 21, 2020 | log.c in Squid Analysis Report Generator (sarg) through 2.3.11 allows local privilege escalation. By default, it uses a ... |
| CVE-2019-3864 | HIGH | 8.8 | 0.4% | Jan 21, 2020 | A vulnerability was discovered in all quay-2 versions before quay-3.0.0, in the Quay web GUI where POST requests include... |
| CVE-2019-14768 | HIGH | 8.8 | 4.3% | Jan 21, 2020 | An Arbitrary File Upload issue in the file browser of DIMO YellowBox CRM before 6.3.4 allows a standard authenticated us... |
| CVE-2019-14767 | HIGH | 7.5 | 1.4% | Jan 21, 2020 | In DIMO YellowBox CRM before 6.3.4, Path Traversal in images/Apparence (dossier=../) and servletrecuperefichier (documen... |
| CVE-2019-14765 | HIGH | 8.8 | 1.1% | Jan 21, 2020 | Incorrect Access Control in AfficheExplorateurParam() in DIMO YellowBox CRM before 6.3.4 allows a standard authenticated... |
| CVE-2019-2267 | HIGH | 7.8 | 0.2% | Jan 21, 2020 | Locked regions may be modified through other interfaces in secure boot loader image due to improper access control. in S... |
| CVE-2019-14036 | HIGH | 7.8 | 0.2% | Jan 21, 2020 | Possible buffer overflow issue in error processing due to improper validation of array index value in Snapdragon Auto, S... |
| CVE-2019-14034 | HIGH | 7.8 | 0.2% | Jan 21, 2020 | Use after free while processing eeprom query as there is a chance to not unlock mutex after error occurs in Snapdragon A... |
| CVE-2019-14024 | HIGH | 7.8 | 0.2% | Jan 21, 2020 | Possible stack-use-after-scope issue in NFC usecase for card emulation in Snapdragon Auto, Snapdragon Industrial IOT, Sn... |
| CVE-2019-14023 | HIGH | 7.8 | 0.2% | Jan 21, 2020 | String format issue will occur while processing HLOS data as there is no user input validation to ensure inputs are prop... |
| CVE-2019-14010 | HIGH | 7.5 | 0.7% | Jan 21, 2020 | The device may enter into error state when some tool or application gets failure at 1st buffer map all and performs 2nd ... |
| CVE-2019-14008 | HIGH | 7.5 | 0.8% | Jan 21, 2020 | Possible null pointer dereference issue in location assistance data processing due to missing null check on resources be... |
| CVE-2019-14003 | HIGH | 7.5 | 0.8% | Jan 21, 2020 | Null pointer exception can happen while parsing invalid MKV clip where cue information is parsed before segment informat... |
| CVE-2019-10606 | HIGH | 7.8 | 0.2% | Jan 21, 2020 | Out-of-bound access will occur in USB driver due to lack of check to validate the frame size passed by user in Snapdrago... |
| CVE-2019-10602 | HIGH | 7.8 | 0.2% | Jan 21, 2020 | Potential use-after-free heap error during Validate/Present calls on display HW composer in Snapdragon Auto, Snapdragon ... |
| CVE-2019-10585 | HIGH | 7.8 | 0.2% | Jan 21, 2020 | Possible integer overflow happens when mmap find function will increment refcount every time when it invokes and can lea... |
| CVE-2019-10583 | HIGH | 7.8 | 0.2% | Jan 21, 2020 | Use after free issue occurs when camera access sensors data through direct report mode in Snapdragon Auto, Snapdragon Co... |
| CVE-2019-10582 | HIGH | 7.8 | 0.2% | Jan 21, 2020 | Use after free issue due to using of invalidated iterator to delete an object in sensors HAL in Snapdragon Auto, Snapdra... |
| CVE-2019-10578 | HIGH | 7.5 | 0.8% | Jan 21, 2020 | Null pointer dereference can occur while parsing the clip which is nonstandard in Snapdragon Auto, Snapdragon Compute, S... |
| CVE-2019-10558 | HIGH | 7.8 | 0.2% | Jan 21, 2020 | While transferring data from APPS to DSP, Out of bound in FastRPC HLOS Driver due to the data buffer which can be contro... |
| CVE-2019-10548 | HIGH | 7.8 | 0.2% | Jan 21, 2020 | While trying to obtain datad ipc handle during DPL initialization, Heap use-after-free issue can occur if modem SSR occu... |
| CVE-2019-20385 | HIGH | 8.8 | 1.1% | Jan 21, 2020 | The CSV upload feature in /supervisor/procesa_carga.php on Logaritmo Aware CallManager 2012 devices allows upload of .ph... |
| CVE-2019-20357 | HIGH | 7.8 | 0.7% | Jan 18, 2020 | A Persistent Arbitrary Code Execution vulnerability exists in the Trend Micro Security 2020 (v160 and 2019 (v15) consume... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now