2019 CVE Vulnerabilities
17,624 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-14021 | HIGH | 7.8 | 0.2% | Apr 16, 2020 | Possible buffer overrun when processing EFS filename and payload sent over diag interface due to lack of check for filen... |
| CVE-2019-14020 | CRITICAL | 9.1 | 0.9% | Apr 16, 2020 | Multiple Read overflows issue due to improper length check while decoding dedicated_eps_bearer_req/ act_def_context_req/... |
| CVE-2019-14019 | CRITICAL | 9.1 | 0.9% | Apr 16, 2020 | Multiple Read overflows issue due to improper length check while decoding RAU accept/PDN disconnect Rej/Modify EPS ctxt ... |
| CVE-2019-14018 | HIGH | 7.8 | 0.2% | Apr 16, 2020 | Possible out of bound array access as there is no check on carrier index passed in Snapdragon Auto, Snapdragon Compute, ... |
| CVE-2019-14012 | HIGH | 7.5 | 0.8% | Apr 16, 2020 | Possibility of null pointer deference as the array of video codecs from media info is referenced without null checking w... |
| CVE-2019-14011 | CRITICAL | 9.1 | 0.9% | Apr 16, 2020 | Multiple Read overflows issue due to improper length check while decoding 3G attach accept/ SMS/ pdn connection reject/ ... |
| CVE-2019-14009 | HIGH | 7.8 | 0.2% | Apr 16, 2020 | Out of bound memory access while processing TZ command handler due to improper input validation on response length recei... |
| CVE-2019-14007 | MEDIUM | 5.5 | 0.2% | Apr 16, 2020 | Due to the use of non-time-constant comparison functions there is issue in timing side channels which can be used as a p... |
| CVE-2019-14001 | HIGH | 7.8 | 0.1% | Apr 16, 2020 | Wrong public key usage from existing oem_keystore for hash generation in Snapdragon Auto, Snapdragon Consumer IOT, Snapd... |
| CVE-2019-10625 | HIGH | 7.1 | 0.2% | Apr 16, 2020 | Out of bound access in diag services when DCI command buffer reallocation is not done properly with required capacity in... |
| CVE-2019-10624 | HIGH | 7.8 | 0.2% | Apr 16, 2020 | While handling the vendor command there is an integer truncation issue that could yield a buffer overflow due to int dat... |
| CVE-2019-10623 | HIGH | 7.1 | 0.2% | Apr 16, 2020 | Possible integer overflow can happen in host driver while processing user controlled string due to improper validation o... |
| CVE-2019-10622 | CRITICAL | 9.1 | 0.5% | Apr 16, 2020 | Out of bound memory access can happen while parsing ADSP message due to lack of check of size of payload received from u... |
| CVE-2019-10621 | HIGH | 7.8 | 0.2% | Apr 16, 2020 | Use after free issue when MAP and UNMAP calls at same time as data structure used my MAP may be freed by UNMAP function ... |
| CVE-2019-10620 | HIGH | 7.8 | 0.2% | Apr 16, 2020 | Kernel memory error in debug module due to improper check of user data length before copying into memory in Snapdragon A... |
| CVE-2019-10610 | CRITICAL | 9.1 | 0.9% | Apr 16, 2020 | Possible buffer over read when trying to process SDP message Video media line with frame-size attribute in video Media l... |
| CVE-2019-10609 | CRITICAL | 9.8 | 0.9% | Apr 16, 2020 | Out of bound write can happen due to lack of check of array index value while calculating it. in Snapdragon Auto, Snapdr... |
| CVE-2019-10608 | MEDIUM | 5.5 | 0.2% | Apr 16, 2020 | Information disclosure issue occurs as there is no binding between the secure keypad session and the secure display sess... |
| CVE-2019-10589 | CRITICAL | 9.8 | 0.9% | Apr 16, 2020 | Lack of length check of response buffer can lead to buffer over-flow while GP command response buffer handling in Snapdr... |
| CVE-2019-10588 | CRITICAL | 9.8 | 0.9% | Apr 16, 2020 | Copying RTCP messages into the output buffer without checking the destination buffer size which could lead to a remote s... |
| CVE-2019-10575 | HIGH | 7.8 | 0.2% | Apr 16, 2020 | Wlan binary which is not signed with OEMs RoT is working on secure device without authentication failure in Snapdragon C... |
| CVE-2019-10574 | HIGH | 7.1 | 1.6% | Apr 16, 2020 | Lack of boundary checks for data offsets received from HLOS can lead to out-of-bound read in Snapdragon Auto, Snapdragon... |
| CVE-2019-10556 | HIGH | 7.8 | 0.2% | Apr 16, 2020 | Missing length check before copying the data from kernel space to userspace through the copy function can lead to buffer... |
| CVE-2019-10551 | CRITICAL | 9.1 | 0.9% | Apr 16, 2020 | String error while processing non standard SIP messages received can lead to buffer overread and then denial of service ... |
| CVE-2019-10547 | HIGH | 7.8 | 0.2% | Apr 16, 2020 | When issuing IOCTL calls to ION, Memory leak can occur due to failure in unassign pages under certain conditions in Snap... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now