17,305 vulnerabilities published in 2019
A memory leak in the sdma_init() function in drivers/infiniband/hw/hfi1/sdma.c in the Linux kernel before 5.3.9 allows a
A memory leak in the bfad_im_get_stats() function in drivers/scsi/bfa/bfad_attr.c in the Linux kernel through 5.3.11 all
Memory leaks in *create_resource_pool() functions under drivers/gpu/drm/amd/display/dc in the Linux kernel through 5.3.1
Memory leaks in *clock_source_create() functions under drivers/gpu/drm/amd/display/dc in the Linux kernel before 5.3.8 a
xcfa before 5.0.1 creates temporary files insecurely which could allow local users to launch a symlink attack and overwr
libbluray MountManager class has a time-of-check time-of-use (TOCTOU) race when expanding JAR files
The Linux kernel before 5.4.1 on powerpc allows Information Exposure because the Spectre-RSB mitigation is not in place
shadow: TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees
In several functions of NotificationManagerService.java and related files, there is a possible way to record audio from
In the Linux kernel through 5.4.6, there is a NULL pointer dereference in drivers/scsi/libsas/sas_discover.c because of
Multiple race conditions in the (1) mount.cifs and (2) umount.cifs programs in Samba 3.6 allow local users to cause a de
An elevation of privilege vulnerability exists when Skype for Andriod fails to properly handle specific authentication r
A vulnerability in Cisco Jabber Client Framework (JCF) could allow an authenticated, remote attacker to conduct a cross-
A vulnerability in Cisco Webex Meetings for Android could allow an unauthenticated, local attacker to perform a cross-si
Insufficient input validation in Intel CSME before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 or Intel TXE before v
The function hso_get_config_data in drivers/net/usb/hso.c in the Linux kernel through 4.19.8 reads if_num from the USB d
IBM API Connect 5.0.0.0 through 5.0.8.5 could display highly sensitive information to an attacker with physical access t
A lock screen issue allowed access to the share function on a locked device. This issue was addressed by restricting opt
The workspace client of TIBCO Software Inc.'s TIBCO ActiveMatrix BPM, TIBCO ActiveMatrix BPM Distribution for TIBCO Silv
A vulnerability in Cisco Application Policy Infrastructure Controller (APIC) Software could allow an unauthenticated, lo
A vulnerability in the Trusted Platform Module (TPM) functionality of software for Cisco Nexus 9000 Series Fabric Switch
The Rediffmail (aka com.rediff.mail.and) application 2.2.6 for Android has cleartext mail content in file storage, persi
There is an information leak vulnerability in some Huawei phones, versions earlier than Jackman-L21 8.2.0.155(C185R1P2).
There is a Factory Reset Protection (FRP) bypass security vulnerability in P20 Huawei smart phones versions before Emily
There is an information disclosure vulnerability on Mate 9 Pro Huawei smartphones versions earlier than LON-AL00B9.0.1.1
There is Factory Reset Protection (FRP) bypass security vulnerability in P20 Huawei smart phones versions earlier than E
Emily-L29C Huawei phones versions earlier than 9.0.0.159 (C185E2R1P12T8) have a Factory Reset Protection (FRP) bypass se
Marvell SSD Controller (88SS1074, 88SS1079, 88SS1080, 88SS1093, 88SS1092, 88SS1095, 88SS9174, 88SS9175, 88SS9187, 88SS91
Marvell SSD Controller (88SS1074, 88SS1079, 88SS1080, 88SS1093, 88SS1092, 88SS1095, 88SS9174, 88SS9175, 88SS9187, 88SS91
All versions up to UKBB_WF820+_1.0.0B06 of ZTE WF820+ LTE Outdoor CPE product are impacted by Cross-Site Request Forgery
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an aut
An issue was discovered in Open Ticket Request System (OTRS) 6.0.x through 6.0.7. A carefully constructed email could be
There is a Factory Reset Protection (FRP) bypass vulnerability on several smartphones. The system does not sufficiently
Vulnerability in the Oracle Text component of Oracle Database Server. Supported versions that are affected are 11.2.0.4,
Mitigates a stored cross site scripting issue in ArcSight Logger versions prior to 6.7.1
Mitigates a stored cross site scripting issue in ArcSight Security Management Center versions prior to 2.9.1
Bypass lock protection in the Nextcloud Android app prior to version 3.6.1 allows accessing the files when repeatedly op
drivers/net/wireless/ath/ath6kl/usb.c in the Linux kernel through 5.2.9 has a NULL pointer dereference via an incomplete
xtrlock through 2.10 does not block multitouch events. Consequently, an attacker at a locked screen can send input to (a
An issue was discovered in the Linux kernel before 5.2.6. There is a use-after-free caused by a malicious USB device in
An issue was discovered in the Linux kernel before 5.1.8. There is a double-free caused by a malicious USB device in the
An issue was discovered in the Linux kernel before 5.2.3. There is a use-after-free caused by a malicious USB device in
An issue was discovered in the Linux kernel before 5.2.6. There is a use-after-free caused by a malicious USB device in
An issue was discovered in the Linux kernel before 5.0.14. There is a NULL pointer dereference caused by a malicious USB
An issue was discovered in the Linux kernel before 5.2.3. There is a NULL pointer dereference caused by a malicious USB
An issue was discovered in the Linux kernel before 5.1.8. There is a NULL pointer dereference caused by a malicious USB
An issue was discovered in the Linux kernel before 5.1.8. There is a NULL pointer dereference caused by a malicious USB
An issue was discovered in the Linux kernel before 5.2.1. There is a use-after-free caused by a malicious USB device in
An issue was discovered in the Linux kernel before 5.1.17. There is a NULL pointer dereference caused by a malicious USB
An issue was discovered in the Linux kernel before 5.2.8. There is a NULL pointer dereference caused by a malicious USB
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started