2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-14012HIGH7.5Possibility of null pointer deference as the array of video codecs from media info is referenced without null checking w...
CVE-2019-14011CRITICAL9.1Multiple Read overflows issue due to improper length check while decoding 3G attach accept/ SMS/ pdn connection reject/ ...
CVE-2019-14009HIGH7.8Out of bound memory access while processing TZ command handler due to improper input validation on response length recei...
CVE-2019-14007MEDIUM5.5Due to the use of non-time-constant comparison functions there is issue in timing side channels which can be used as a p...
CVE-2019-14001HIGH7.8Wrong public key usage from existing oem_keystore for hash generation in Snapdragon Auto, Snapdragon Consumer IOT, Snapd...
CVE-2019-10625HIGH7.1Out of bound access in diag services when DCI command buffer reallocation is not done properly with required capacity in...
CVE-2019-10624HIGH7.8While handling the vendor command there is an integer truncation issue that could yield a buffer overflow due to int dat...
CVE-2019-10623HIGH7.1Possible integer overflow can happen in host driver while processing user controlled string due to improper validation o...
CVE-2019-10622CRITICAL9.1Out of bound memory access can happen while parsing ADSP message due to lack of check of size of payload received from u...
CVE-2019-10621HIGH7.8Use after free issue when MAP and UNMAP calls at same time as data structure used my MAP may be freed by UNMAP function ...
CVE-2019-10620HIGH7.8Kernel memory error in debug module due to improper check of user data length before copying into memory in Snapdragon A...
CVE-2019-10610CRITICAL9.1Possible buffer over read when trying to process SDP message Video media line with frame-size attribute in video Media l...
CVE-2019-10609CRITICAL9.8Out of bound write can happen due to lack of check of array index value while calculating it. in Snapdragon Auto, Snapdr...
CVE-2019-10608MEDIUM5.5Information disclosure issue occurs as there is no binding between the secure keypad session and the secure display sess...
CVE-2019-10589CRITICAL9.8Lack of length check of response buffer can lead to buffer over-flow while GP command response buffer handling in Snapdr...
CVE-2019-10588CRITICAL9.8Copying RTCP messages into the output buffer without checking the destination buffer size which could lead to a remote s...
CVE-2019-10575HIGH7.8Wlan binary which is not signed with OEMs RoT is working on secure device without authentication failure in Snapdragon C...
CVE-2019-10574HIGH7.1Lack of boundary checks for data offsets received from HLOS can lead to out-of-bound read in Snapdragon Auto, Snapdragon...
CVE-2019-10556HIGH7.8Missing length check before copying the data from kernel space to userspace through the copy function can lead to buffer...
CVE-2019-10551CRITICAL9.1String error while processing non standard SIP messages received can lead to buffer overread and then denial of service ...
CVE-2019-10547HIGH7.8When issuing IOCTL calls to ION, Memory leak can occur due to failure in unassign pages under certain conditions in Snap...
CVE-2019-10523MEDIUM5.5Target specific data is being sent to remote server and leads to information exposure in Snapdragon Auto, Snapdragon Com...
CVE-2019-10483MEDIUM5.5Side channel issue in QTEE due to usage of non-time-constant comparison function such as memcmp or strcmp in Snapdragon ...
CVE-2019-20681HIGH8.8Certain NETGEAR devices are affected by authentication bypass. This affects D6200 before 1.1.00.34, D7000 before 1.0.1.6...
CVE-2019-20680HIGH8Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7000v2 before 1.0.0.53...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now