2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-10544 | HIGH | 7.8 | 0.2% | Dec 18, 2019 | Improper length check on source buffer to handle userspace data received can lead to out-of-bound access in diag handler... |
| CVE-2019-10537 | HIGH | 7.8 | 0.2% | Dec 18, 2019 | Improper validation of event buffer extracted from FW response can lead to integer overflow, which will allow to pass th... |
| CVE-2019-10536 | HIGH | 7.8 | 0.2% | Dec 18, 2019 | Potential double free scenario if driver receives another DIAG_EVENT_LOG_SUPPORTED event from firmware as the pointer is... |
| CVE-2019-10518 | HIGH | 7.8 | 0.2% | Dec 18, 2019 | Use after free of a pointer in iWLAN scenario during netmgr state transition to CONNECT in Snapdragon Auto, Snapdragon C... |
| CVE-2019-10517 | HIGH | 7.8 | 0.2% | Dec 18, 2019 | Memory is being freed up twice when two concurrent threads are executing in parallel in Snapdragon Auto, Snapdragon Comp... |
| CVE-2019-10481 | HIGH | 7.8 | 0.2% | Dec 18, 2019 | Out of bound access occurs while handling the WMI FW event due to lack of check of buffer argument which comes directly ... |
| CVE-2019-10480 | HIGH | 7.8 | 0.2% | Dec 18, 2019 | Out of bound write can happen in WMI firmware event handler due to lack of validation of data received from WLAN firmwar... |
| CVE-2019-7481 | HIGH | 7.5 | 99.9% | Dec 17, 2019 | Vulnerability in SonicWall SMA100 allow unauthenticated user to gain read-only access to unauthorized resources. This vu... |
| CVE-2019-11657 | HIGH | 8.8 | 0.5% | Dec 17, 2019 | Cross-Site Request Forgery vulnerability in all Micro Focus ArcSight Logger affecting all product versions below version... |
| CVE-2019-3995 | HIGH | 7.5 | 28.5% | Dec 17, 2019 | ELOG 3.1.4-57bea22 and below is affected by a denial of service vulnerability due to a NULL pointer dereference. A remot... |
| CVE-2019-3994 | HIGH | 7.5 | 2.9% | Dec 17, 2019 | ELOG 3.1.4-57bea22 and below is affected by a denial of service vulnerability due to a use after free. A remote unauthen... |
| CVE-2019-3993 | HIGH | 7.5 | 45.7% | Dec 17, 2019 | ELOG 3.1.4-57bea22 and below is affected by an information disclosure vulnerability. A remote unauthenticated attacker c... |
| CVE-2019-3992 | HIGH | 7.5 | 1.3% | Dec 17, 2019 | ELOG 3.1.4-57bea22 and below is affected by an information disclosure vulnerability. A remote unauthenticated attacker c... |
| CVE-2019-17334 | HIGH | 8 | 1.0% | Dec 17, 2019 | The Visualizations component of TIBCO Software Inc.'s TIBCO Spotfire Analyst, TIBCO Spotfire Analytics Platform for AWS ... |
| CVE-2019-19241 | HIGH | 7.8 | 1.1% | Dec 17, 2019 | In the Linux kernel before 5.4.2, the io_uring feature leads to requests that inadvertently have UID 0 and full capabili... |
| CVE-2019-0384 | HIGH | 8.8 | 0.9% | Dec 17, 2019 | Transaction Management in SAP Treasury and Risk Management (corrected in S4CORE versions 1.01, 1.02, 1.03, 1.04 and EA-F... |
| CVE-2019-0383 | HIGH | 8.8 | 1.1% | Dec 17, 2019 | Transaction Management in SAP Treasury and Risk Management (corrected in S4CORE versions 1.01, 1.02, 1.03, 1.04 and EA-F... |
| CVE-2019-19850 | HIGH | 7.2 | 0.9% | Dec 17, 2019 | An issue was discovered in TYPO3 before 8.7.30, 9.x before 9.5.12, and 10.x before 10.2.2. Because escaping of user-subm... |
| CVE-2019-19849 | HIGH | 8.8 | 1.3% | Dec 17, 2019 | An issue was discovered in TYPO3 before 8.7.30, 9.x before 9.5.12, and 10.x before 10.2.2. It has been discovered that t... |
| CVE-2019-19848 | HIGH | 7.2 | 1.5% | Dec 17, 2019 | An issue was discovered in TYPO3 before 8.7.30, 9.x before 9.5.12, and 10.x before 10.2.2. It has been discovered that t... |
| CVE-2019-19847 | HIGH | 8.1 | 1.4% | Dec 17, 2019 | Libspiro through 20190731 has a stack-based buffer overflow in the spiro_to_bpath0() function in spiro.c. |
| CVE-2019-18670 | HIGH | 7.8 | 0.8% | Dec 17, 2019 | In the Quick Access Service (QAAdminAgent.exe) in Acer Quick Access V2.01.3000 through 2.01.3027 and V3.00.3000 through ... |
| CVE-2019-19745 | HIGH | 8.8 | 1.1% | Dec 17, 2019 | Contao 4.0 through 4.8.5 allows PHP local file inclusion. A back end user with access to the form generator can upload a... |
| CVE-2019-19675 | HIGH | 7.8 | 0.5% | Dec 17, 2019 | In Ivanti Workspace Control before 10.3.180.0. a locally authenticated user with low privileges can bypass Managed Appli... |
| CVE-2019-19315 | HIGH | 7.1 | 0.6% | Dec 17, 2019 | NLSSRV32.EXE in Nalpeiron Licensing Service 7.3.4.0, as used with Nitro PDF and other products, allows Elevation of Priv... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now