2019 CVE Vulnerabilities
17,624 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-1537 | — | — | — | Sep 10, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2019-1536 | — | — | — | Sep 10, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2019-1535 | — | — | — | Sep 10, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2019-14119 | HIGH | 7 | 0.1% | Sep 8, 2020 | u'While processing SMCInvoke asynchronous message header, message count is modified leading to a TOCTOU race condition a... |
| CVE-2019-14117 | HIGH | 7.8 | 0.2% | Sep 8, 2020 | u'Whenever the page list is updated via privileged user, the previous list elements are freed but are not deleted from t... |
| CVE-2019-14115 | MEDIUM | 5.5 | 0.2% | Sep 8, 2020 | u'Information disclosure issue occurs as in current logic as secure touch is released without clearing the display sessi... |
| CVE-2019-14089 | HIGH | 7.8 | 0.2% | Sep 8, 2020 | u'Keymaster attestation key and device IDs provisioning which is a one time process is incorrectly allowed to be re-prov... |
| CVE-2019-14074 | HIGH | 7.8 | 0.2% | Sep 8, 2020 | u'Heap overflow in diag command handler due to lack of check of packet length received from user' in Snapdragon Auto, Sn... |
| CVE-2019-14065 | HIGH | 7.8 | 0.2% | Sep 8, 2020 | u'Pointer double free in HavenSvc due to not setting the pointer to NULL after freeing it' in Snapdragon Auto, Snapdrago... |
| CVE-2019-14056 | HIGH | 7.8 | 0.2% | Sep 8, 2020 | u'Possible integer overflow in API due to lack of check on large oid range count in cert extension field' in Snapdragon ... |
| CVE-2019-14052 | CRITICAL | 9.8 | 0.9% | Sep 8, 2020 | u'Accessing an uninitialized data structure could result in partially copying of contents and thus incorrect processing'... |
| CVE-2019-14025 | MEDIUM | 5.5 | 0.2% | Sep 8, 2020 | u'When a new session is created, Object is returned that contains TZ addresses and it get passed to HLOS as an handle to... |
| CVE-2019-13999 | HIGH | 7.8 | 0.2% | Sep 8, 2020 | u'Lack of check for integer overflow for round up and addition operations result into memory corruption and potential in... |
| CVE-2019-13998 | HIGH | 7.8 | 0.2% | Sep 8, 2020 | u'Lack of check that the TX FIFO write and read indices that are read from shared RAM are less than the FIFO size result... |
| CVE-2019-13995 | HIGH | 7.8 | 0.2% | Sep 8, 2020 | u'Lack of integer overflow check for addition of fragment size and remaining size that are read from shared memory can l... |
| CVE-2019-13994 | HIGH | 7.8 | 0.2% | Sep 8, 2020 | u'Lack of check that the current received data fragment size of a particular packet that are read from shared memory are... |
| CVE-2019-13992 | HIGH | 7.8 | 0.2% | Sep 8, 2020 | u'Out of bound memory access if stack push and pop operation are performed without doing a bound check on stack top' in ... |
| CVE-2019-10629 | HIGH | 7.8 | 0.2% | Sep 8, 2020 | u'User Process can potentially corrupt kernel virtual page by passing a crafted page in API' in Snapdragon Auto, Snapdra... |
| CVE-2019-10628 | HIGH | 7.8 | 0.2% | Sep 8, 2020 | u'Memory can be potentially corrupted if random index is allowed to manipulate TLB entries in Kernel from user library' ... |
| CVE-2019-10615 | HIGH | 7.8 | 0.2% | Sep 8, 2020 | u'Possibility of integer overflow in keymaster 4 while allocating memory due to multiplication of large numcerts value a... |
| CVE-2019-10596 | HIGH | 7.8 | 0.2% | Sep 8, 2020 | u'Improper access control can lead signed process to guess pid of other processes and access their address space' in Sna... |
| CVE-2019-10562 | HIGH | 7.8 | 0.2% | Sep 8, 2020 | u'Improper authentication and signature verification of debug polices in secure boot loader will allow unverified debug ... |
| CVE-2019-10527 | HIGH | 7.8 | 0.2% | Sep 8, 2020 | u'SMEM partition can be manipulated in case of any compromise on HLOS, thus resulting in access to memory outside of SME... |
| CVE-2019-20916 | HIGH | 7.5 | 3.0% | Sep 4, 2020 | The pip package before 19.2 for Python allows Directory Traversal when a URL is given in an install command, because a C... |
| CVE-2019-3881 | HIGH | 7.8 | 0.5% | Sep 4, 2020 | Bundler prior to 2.1.0 uses a predictable path in /tmp/, created with insecure permissions as a storage location for gem... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now