2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-14012 | HIGH | 7.5 | 0.8% | Apr 16, 2020 | Possibility of null pointer deference as the array of video codecs from media info is referenced without null checking w... |
| CVE-2019-14011 | CRITICAL | 9.1 | 0.9% | Apr 16, 2020 | Multiple Read overflows issue due to improper length check while decoding 3G attach accept/ SMS/ pdn connection reject/ ... |
| CVE-2019-14009 | HIGH | 7.8 | 0.2% | Apr 16, 2020 | Out of bound memory access while processing TZ command handler due to improper input validation on response length recei... |
| CVE-2019-14007 | MEDIUM | 5.5 | 0.2% | Apr 16, 2020 | Due to the use of non-time-constant comparison functions there is issue in timing side channels which can be used as a p... |
| CVE-2019-14001 | HIGH | 7.8 | 0.1% | Apr 16, 2020 | Wrong public key usage from existing oem_keystore for hash generation in Snapdragon Auto, Snapdragon Consumer IOT, Snapd... |
| CVE-2019-10625 | HIGH | 7.1 | 0.2% | Apr 16, 2020 | Out of bound access in diag services when DCI command buffer reallocation is not done properly with required capacity in... |
| CVE-2019-10624 | HIGH | 7.8 | 0.2% | Apr 16, 2020 | While handling the vendor command there is an integer truncation issue that could yield a buffer overflow due to int dat... |
| CVE-2019-10623 | HIGH | 7.1 | 0.2% | Apr 16, 2020 | Possible integer overflow can happen in host driver while processing user controlled string due to improper validation o... |
| CVE-2019-10622 | CRITICAL | 9.1 | 0.5% | Apr 16, 2020 | Out of bound memory access can happen while parsing ADSP message due to lack of check of size of payload received from u... |
| CVE-2019-10621 | HIGH | 7.8 | 0.2% | Apr 16, 2020 | Use after free issue when MAP and UNMAP calls at same time as data structure used my MAP may be freed by UNMAP function ... |
| CVE-2019-10620 | HIGH | 7.8 | 0.2% | Apr 16, 2020 | Kernel memory error in debug module due to improper check of user data length before copying into memory in Snapdragon A... |
| CVE-2019-10610 | CRITICAL | 9.1 | 0.9% | Apr 16, 2020 | Possible buffer over read when trying to process SDP message Video media line with frame-size attribute in video Media l... |
| CVE-2019-10609 | CRITICAL | 9.8 | 0.9% | Apr 16, 2020 | Out of bound write can happen due to lack of check of array index value while calculating it. in Snapdragon Auto, Snapdr... |
| CVE-2019-10608 | MEDIUM | 5.5 | 0.2% | Apr 16, 2020 | Information disclosure issue occurs as there is no binding between the secure keypad session and the secure display sess... |
| CVE-2019-10589 | CRITICAL | 9.8 | 0.9% | Apr 16, 2020 | Lack of length check of response buffer can lead to buffer over-flow while GP command response buffer handling in Snapdr... |
| CVE-2019-10588 | CRITICAL | 9.8 | 0.9% | Apr 16, 2020 | Copying RTCP messages into the output buffer without checking the destination buffer size which could lead to a remote s... |
| CVE-2019-10575 | HIGH | 7.8 | 0.2% | Apr 16, 2020 | Wlan binary which is not signed with OEMs RoT is working on secure device without authentication failure in Snapdragon C... |
| CVE-2019-10574 | HIGH | 7.1 | 1.6% | Apr 16, 2020 | Lack of boundary checks for data offsets received from HLOS can lead to out-of-bound read in Snapdragon Auto, Snapdragon... |
| CVE-2019-10556 | HIGH | 7.8 | 0.2% | Apr 16, 2020 | Missing length check before copying the data from kernel space to userspace through the copy function can lead to buffer... |
| CVE-2019-10551 | CRITICAL | 9.1 | 0.9% | Apr 16, 2020 | String error while processing non standard SIP messages received can lead to buffer overread and then denial of service ... |
| CVE-2019-10547 | HIGH | 7.8 | 0.2% | Apr 16, 2020 | When issuing IOCTL calls to ION, Memory leak can occur due to failure in unassign pages under certain conditions in Snap... |
| CVE-2019-10523 | MEDIUM | 5.5 | 0.2% | Apr 16, 2020 | Target specific data is being sent to remote server and leads to information exposure in Snapdragon Auto, Snapdragon Com... |
| CVE-2019-10483 | MEDIUM | 5.5 | 0.2% | Apr 16, 2020 | Side channel issue in QTEE due to usage of non-time-constant comparison function such as memcmp or strcmp in Snapdragon ... |
| CVE-2019-20681 | HIGH | 8.8 | 1.1% | Apr 15, 2020 | Certain NETGEAR devices are affected by authentication bypass. This affects D6200 before 1.1.00.34, D7000 before 1.0.1.6... |
| CVE-2019-20680 | HIGH | 8 | 0.8% | Apr 15, 2020 | Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7000v2 before 1.0.0.53... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now