2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-14115 | MEDIUM | 5.5 | 0.2% | Sep 8, 2020 | u'Information disclosure issue occurs as in current logic as secure touch is released without clearing the display sessi... |
| CVE-2019-14089 | HIGH | 7.8 | 0.2% | Sep 8, 2020 | u'Keymaster attestation key and device IDs provisioning which is a one time process is incorrectly allowed to be re-prov... |
| CVE-2019-14074 | HIGH | 7.8 | 0.2% | Sep 8, 2020 | u'Heap overflow in diag command handler due to lack of check of packet length received from user' in Snapdragon Auto, Sn... |
| CVE-2019-14065 | HIGH | 7.8 | 0.2% | Sep 8, 2020 | u'Pointer double free in HavenSvc due to not setting the pointer to NULL after freeing it' in Snapdragon Auto, Snapdrago... |
| CVE-2019-14056 | HIGH | 7.8 | 0.2% | Sep 8, 2020 | u'Possible integer overflow in API due to lack of check on large oid range count in cert extension field' in Snapdragon ... |
| CVE-2019-14052 | CRITICAL | 9.8 | 0.9% | Sep 8, 2020 | u'Accessing an uninitialized data structure could result in partially copying of contents and thus incorrect processing'... |
| CVE-2019-14025 | MEDIUM | 5.5 | 0.2% | Sep 8, 2020 | u'When a new session is created, Object is returned that contains TZ addresses and it get passed to HLOS as an handle to... |
| CVE-2019-13999 | HIGH | 7.8 | 0.2% | Sep 8, 2020 | u'Lack of check for integer overflow for round up and addition operations result into memory corruption and potential in... |
| CVE-2019-13998 | HIGH | 7.8 | 0.2% | Sep 8, 2020 | u'Lack of check that the TX FIFO write and read indices that are read from shared RAM are less than the FIFO size result... |
| CVE-2019-13995 | HIGH | 7.8 | 0.2% | Sep 8, 2020 | u'Lack of integer overflow check for addition of fragment size and remaining size that are read from shared memory can l... |
| CVE-2019-13994 | HIGH | 7.8 | 0.2% | Sep 8, 2020 | u'Lack of check that the current received data fragment size of a particular packet that are read from shared memory are... |
| CVE-2019-13992 | HIGH | 7.8 | 0.2% | Sep 8, 2020 | u'Out of bound memory access if stack push and pop operation are performed without doing a bound check on stack top' in ... |
| CVE-2019-10629 | HIGH | 7.8 | 0.2% | Sep 8, 2020 | u'User Process can potentially corrupt kernel virtual page by passing a crafted page in API' in Snapdragon Auto, Snapdra... |
| CVE-2019-10628 | HIGH | 7.8 | 0.2% | Sep 8, 2020 | u'Memory can be potentially corrupted if random index is allowed to manipulate TLB entries in Kernel from user library' ... |
| CVE-2019-10615 | HIGH | 7.8 | 0.2% | Sep 8, 2020 | u'Possibility of integer overflow in keymaster 4 while allocating memory due to multiplication of large numcerts value a... |
| CVE-2019-10596 | HIGH | 7.8 | 0.2% | Sep 8, 2020 | u'Improper access control can lead signed process to guess pid of other processes and access their address space' in Sna... |
| CVE-2019-10562 | HIGH | 7.8 | 0.2% | Sep 8, 2020 | u'Improper authentication and signature verification of debug polices in secure boot loader will allow unverified debug ... |
| CVE-2019-10527 | HIGH | 7.8 | 0.2% | Sep 8, 2020 | u'SMEM partition can be manipulated in case of any compromise on HLOS, thus resulting in access to memory outside of SME... |
| CVE-2019-20916 | HIGH | 7.5 | 3.0% | Sep 4, 2020 | The pip package before 19.2 for Python allows Directory Traversal when a URL is given in an install command, because a C... |
| CVE-2019-3881 | HIGH | 7.8 | 0.5% | Sep 4, 2020 | Bundler prior to 2.1.0 uses a predictable path in /tmp/, created with insecure permissions as a storage location for gem... |
| CVE-2019-11928 | MEDIUM | 6.1 | 1.0% | Sep 3, 2020 | An input validation issue in WhatsApp Desktop versions prior to v0.3.4932 could have allowed cross-site scripting upon c... |
| CVE-2019-10679 | HIGH | 7.8 | 0.5% | Sep 3, 2020 | Thomson Reuters Eikon 4.0.42144 allows all local users to modify the service executable file because of weak %PROGRAMFIL... |
| CVE-2019-5645 | HIGH | 7.5 | 41.7% | Sep 1, 2020 | By sending a specially crafted HTTP GET request to a listening Rapid7 Metasploit HTTP handler, an attacker can register ... |
| CVE-2019-4579 | MEDIUM | 4.3 | 0.7% | Aug 28, 2020 | IBM Resilient SOAR 38 uses incomplete blacklisting for input validation which allows attackers to bypass application con... |
| CVE-2019-4533 | MEDIUM | 4.3 | 1.0% | Aug 28, 2020 | IBM Resilient SOAR V38.0 users may experience a denial of service of the SOAR Platform due to a insufficient input valid... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now