17,305 vulnerabilities published in 2019
A CWE-427: Uncontrolled Search Path Element vulnerability exists in ProClima (all versions prior to version 8.0.0) which
A CWE-787: Out-of-bounds Write vulnerability exists in Interactive Graphical SCADA System (IGSS), Version 14 and prior,
nfdump 1.6.16 and earlier is affected by: Buffer Overflow. The impact is: The impact could range from a denial of servic
In NSA Ghidra before 9.1, path traversal can occur in RestoreTask.java (from the package ghidra.app.plugin.core.archive)
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
AIX builds of Eclipse OpenJ9 before 0.15.0 contain unused RPATHs which may facilitate code injection and privilege eleva
Comodo Antivirus versions up to 12.0.0.6810 are vulnerable to Local Privilege Escalation due to CmdAgent's handling of C
Dell EMC Unity and UnityVSA versions prior to 5.0.0.0.5.116 contain a plain-text password storage vulnerability. A Unisp
Adobe Dreamweaver direct download installer versions 19.0 and below, 18.0 and below have an Insecure Library Loading (DL
Akeo Consulting Rufus 3.0 and earlier is affected by: DLL search order hijacking. The impact is: Arbitrary code executio
dpic 2019.06.20 has a Stack-based Buffer Overflow in the wfloat() function in main.c.
XBL_SEC image authentication and other crypto related validations are accessible to a compromised OEM XBL Loader due to
Debug policy with invalid signature can be loaded when the debug policy functionality is disabled by using the parallel
Null pointer dereference occurs for channel context while opening glink channel in Snapdragon Auto, Snapdragon Consumer
Out of bound read can happen due to lack of NULL termination on user controlled data in WLAN in Snapdragon Auto, Snapdra
Out of bound access can occur due to buffer copy without checking size of input received from WLAN firmware in Snapdrago
The IBM Spectrum Protect 7.1 and 8.1 Backup-Archive Client is vulnerable to a buffer overflow. This could allow executio
Files with the .JNLP extension used for "Java web start" applications are not treated as executable content for download
Upwork Time Tracker 5.2.2.716 doesn't verify the SHA256 hash of the downloaded program update before running it, which c
Socusoft Co Photo 2 Video Converter 8.0.0 is affected by: Buffer Overflow - Local shell-code execution and Denial of Ser
GNU gdb All versions is affected by: Buffer Overflow - Out of bound memory access. The impact is: Deny of Service, Memor
Delta Electronics CNCSoft ScreenEditor, Versions 1.00.89 and prior. Multiple heap-based buffer overflow vulnerabilities
IBM Cloud Private 3.1.1 and 3.1.2 could allow a local user to obtain elevated privileges due to improper security contex
Buffer overflow occurs when emulated RPMB is used due to sector size assumptions in the TA rollback protection logic. in
Lack of check of data type can lead to subsequent loop-expression potentially go negative and the condition will still e
Access to freed memory can happen while reading from diag driver due to use after free issue in Snapdragon Auto, Snapdra
Buffer overflow can occur in display function due to lack of validation of header block size set by user. in Snapdragon
User keystore signature is ignored in boot and can lead to bypass boot image signature verification in Snapdragon Auto,
An unauthenticated bitmap image can be loaded in to memory and subsequently cause execution of unverified code. in Snapd
Multiple open and close from multiple threads will lead camera driver to access destroyed session data pointer in Snapdr
Pointer dereference while freeing IFE resources due to lack of length check of in port resource. in Snapdragon Consumer
Protection is missing while accessing md sessions info via macro which can lead to use-after-free in Snapdragon Auto, Sn
An out-of-bound write can be triggered by a specially-crafted command supplied by a userspace application. in Snapdragon
Possibility of out-of-bound read if id received from SPI is not in range of FIFO in Snapdragon Auto, Snapdragon Compute,
Improper casting of structure while handling the buffer leads to out of bound read in display in Snapdragon Auto, Snapdr
User application could potentially make RPC call to the fastrpc driver and the driver will allow the message to go throu
When handling the vendor command there exists a potential buffer overflow due to lack of input validation of data buffer
Data token is received from ADSP and is used without validation as an index into the array leads to out of bound access
Possible buffer overflow when number of channels passed is more than size of channel mapping array in Snapdragon Auto, S
Firmware is getting into loop of overwriting memory when scan command is given from host because of improper validation.
VCFTools vcftools prior to version 0.1.15 is affected by: Use-after-free. The impact is: Denial of Service or possibly o
In FreeBSD 12.0-STABLE before r350261, 12.0-RELEASE before 12.0-RELEASE-p8, 11.3-STABLE before r350263, 11.3-RELEASE bef
In FreeBSD 12.0-STABLE before r349805, 12.0-RELEASE before 12.0-RELEASE-p8, 11.3-STABLE before r349806, 11.3-RELEASE bef
In FreeBSD 12.0-STABLE before r350222, 12.0-RELEASE before 12.0-RELEASE-p8, 11.3-STABLE before r350223, 11.3-RELEASE bef
An issue was discovered in the Linux kernel before 4.20. drivers/phy/mscc/phy-ocelot-serdes.c has an off-by-one error wi
An issue was discovered in the Linux kernel before 4.18.7. In block/blk-core.c, there is an __blk_drain_queue() use-afte
UploaderService in SnagIT 2019.1.2 allows elevation of privilege by placing an invalid presentation file in %PROGRAMDATA
GNU patch through 2.7.6 is vulnerable to OS shell command injection that can be exploited by opening a crafted patch fil
A DLL side-loading vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow an authenticated attacker to gain
An issue was discovered in Xpdf 4.01.01. There is an Integer overflow in the function JBIG2Bitmap::combine at JBIG2Strea
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started