Google Security Advisories · June 2019 — Google Security Advisories
120 advisories 80 CVEs 15 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2019-06. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 15 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

DEBIAN-CVE-2019-5786

Open SourceExploitedCISA KEV listedMEDIUM2019-06-27

DEBIAN-CVE-2019-5786

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2019-11708

GoogleExploitedCISA KEV listedCRITICAL2019-06-21

Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent process opening web content chosen by a compromised child process. When combined with additional vulner...

CVEs:CVE-2019-11708

Affected products

ProductStatusVendorPackageEcosystem
firefox affected mozilla
thunderbird affected mozilla
Upstream advisory

CVE-2019-11708

Project ZeroExploitedCISA KEV listed2019-06-21

Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent process opening web content chosen by a compromised child process. When combined with additional vulnerabilities this could result in executing arbitrary code on the user's computer. This vulnerability affects Firefox ESR < 60.7.2, Firefox < 67.0.4, and Thunderbird < 60.7.2.

CVEs:CVE-2019-11708

Upstream advisory

CVE-2019-11707

GoogleExploitedCISA KEV listedHIGH2019-06-19

A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < ...

CVEs:CVE-2019-11707

Affected products

ProductStatusVendorPackageEcosystem
firefox affected mozilla
thunderbird affected mozilla
Upstream advisory

CVE-2019-11707

Project ZeroExploitedCISA KEV listed2019-06-19

A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 60.7.1, Firefox < 67.0.3, and Thunderbird < 60.7.2.

CVEs:CVE-2019-11707

Upstream advisory

SUSE-SU-2019:1234-2

Open SourceExploitedVulnCheck KEV listedCRITICAL2019-06-13

Security update for containerd, docker, docker-runc, go, go1.11, go1.12, golang-github-docker-libnetwork

Affected products

ProductStatusVendorPackageEcosystem
containerd affected SUSE:Linux Enterprise Module for Containers 15 SP1 containerd
docker affected SUSE:Linux Enterprise Module for Containers 15 SP1 docker
docker-runc affected SUSE:Linux Enterprise Module for Containers 15 SP1 docker-runc
golang-github-docker-libnetwork affected SUSE:Linux Enterprise Module for Containers 15 SP1 golang-github-docker-libnetwork
Upstream advisory

openSUSE-SU-2019:1499-1

Open SourceExploitedVulnCheck KEV listedCRITICAL2019-06-03

Security update for containerd, docker, docker-runc, go, go1.11, go1.12, golang-github-docker-libnetwork

Affected products

ProductStatusVendorPackageEcosystem
containerd affected openSUSE:Leap 15.0 containerd
docker affected openSUSE:Leap 15.0 docker
docker-runc affected openSUSE:Leap 15.0 docker-runc
go affected openSUSE:Leap 15.0 go
go1.11 affected openSUSE:Leap 15.0 go1.11
go1.12 affected openSUSE:Leap 15.0 go1.12
golang-github-docker-libnetwork affected openSUSE:Leap 15.0 golang-github-docker-libnetwork
Upstream advisory

openSUSE-SU-2019:1666-1

Open SourceExploitedVulnCheck KEV listedCRITICAL2019-06-28

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 12 SP3 chromium
chromium affected SUSE:Package Hub 15 chromium
chromium affected openSUSE:Leap 15.0 chromium
chromium affected openSUSE:Leap 15.1 chromium
Upstream advisory

openSUSE-SU-2019:1558-1

Open SourceExploitedVulnCheck KEV listedCRITICAL2019-06-15

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected openSUSE:Leap 15.0 chromium
Upstream advisory

openSUSE-SU-2019:1557-1

Open SourceExploitedVulnCheck KEV listedCRITICAL2019-06-15

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected openSUSE:Leap 15.1 chromium
Upstream advisory

DEBIAN-CVE-2019-5840

Open SourceExploitedVulnCheck KEV listedMEDIUM2019-06-27

DEBIAN-CVE-2019-5840

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2019-5840

GoogleExploitedVulnCheck KEV listedMEDIUM2019-06-05

Incorrect security UI in popup blocker in Google Chrome on iOS prior to 75.0.3770.80 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

CVEs:CVE-2019-5840

Affected products

ProductStatusVendorPackageEcosystem
backports affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

DEBIAN-CVE-2019-5822

Open SourcePoC exploitHIGH2019-06-27

DEBIAN-CVE-2019-5822

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2019-5784

Open SourcePoC exploitMEDIUM2019-06-27

DEBIAN-CVE-2019-5784

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

RUSTSEC-2019-0003

Open SourceCoalition ESS < 30%HIGH2019-06-08

Out of Memory in stream::read_raw_bytes_into()

Affected products

ProductStatusVendorPackageEcosystem
protobuf affected crates.io protobuf
Upstream advisory

CVE-2019-15544

Open SourceCoalition ESS < 30%HIGH2019-06-08

Uncontrolled memory consumption in protobuf

CVEs:CVE-2019-15544

Affected products

ProductStatusVendorPackageEcosystem
protobuf affected crates.io protobuf
Upstream advisory

CVE-2019-15544

Open SourceCoalition ESS < 30%HIGH2019-06-08

An issue was discovered in the protobuf crate before 2.6.0 for Rust. Attackers can exhaust all memory via Vec::reserve calls.

CVEs:CVE-2019-15544

Affected products

ProductStatusVendorPackageEcosystem
hbase affected apache
rust-protobuf affected rust-protobuf_project
Upstream advisory

DLA-1840-1

Open SourceCoalition ESS < 30%2019-06-30

golang-go.crypto - security update

Affected products

ProductStatusVendorPackageEcosystem
golang-go.crypto affected Debian:8 golang-go.crypto
Upstream advisory

CVE-2019-12995

Open SourceCoalition ESS < 30%HIGH2019-06-28

Istio before 1.2.2 mishandles certain access tokens, leading to "Epoch 0 terminated with an error" in Envoy. This is related to a jwt_authenticator.cc segmentation fault.

CVEs:CVE-2019-12995

Affected products

ProductStatusVendorPackageEcosystem
istio affected istio
Upstream advisory

DEBIAN-CVE-2019-5827

Open SourceCoalition ESS < 30%CRITICAL2019-06-27

DEBIAN-CVE-2019-5827

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:13 chromium
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:14 chromium
sqlite3 affected Debian:11 sqlite3
sqlite3 affected Debian:12 sqlite3
sqlite3 affected Debian:13 sqlite3
sqlite3 affected Debian:14 sqlite3
Upstream advisory

openSUSE-SU-2019:1488-1

Open SourceCoalition ESS < 30%CRITICAL2019-06-02

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 chromium
Upstream advisory

DEBIAN-CVE-2019-5831

Open SourceCoalition ESS < 30%HIGH2019-06-27

DEBIAN-CVE-2019-5831

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2019-5831

GoogleCoalition ESS < 30%HIGH2019-06-05

Object lifecycle issue in V8 in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2019-5831

Affected products

ProductStatusVendorPackageEcosystem
backports affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

DEBIAN-CVE-2019-5808

Open SourceCoalition ESS < 30%CRITICAL2019-06-27

DEBIAN-CVE-2019-5808

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2019-5835

Open SourceCoalition ESS < 30%MEDIUM2019-06-27

DEBIAN-CVE-2019-5835

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2019-5835

GoogleCoalition ESS < 30%MEDIUM2019-06-05

Object lifecycle issue in SwiftShader in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.

CVEs:CVE-2019-5835

Affected products

ProductStatusVendorPackageEcosystem
backports affected opensuse
chrome affected google
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

DEBIAN-CVE-2019-5818

Open SourceCoalition ESS < 30%HIGH2019-06-27

DEBIAN-CVE-2019-5818

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2019-5837

Open SourceCoalition ESS < 30%CRITICAL2019-06-27

DEBIAN-CVE-2019-5837

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2019-5837

GoogleCoalition ESS < 30%CRITICAL2019-06-05

Resource size information leakage in Blink in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVEs:CVE-2019-5837

Affected products

ProductStatusVendorPackageEcosystem
backports affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

DEBIAN-CVE-2019-5809

Open SourceCoalition ESS < 30%CRITICAL2019-06-27

DEBIAN-CVE-2019-5809

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2019-5805

Open SourceCoalition ESS < 30%CRITICAL2019-06-27

DEBIAN-CVE-2019-5805

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2019-5820

Open SourceCoalition ESS < 30%CRITICAL2019-06-27

DEBIAN-CVE-2019-5820

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2019-5836

Open SourceCoalition ESS < 30%CRITICAL2019-06-27

DEBIAN-CVE-2019-5836

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2019-5836

GoogleCoalition ESS < 30%CRITICAL2019-06-05

Heap buffer overflow in ANGLE in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2019-5836

Affected products

ProductStatusVendorPackageEcosystem
backports affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

DEBIAN-CVE-2019-5821

Open SourceCoalition ESS < 30%CRITICAL2019-06-27

DEBIAN-CVE-2019-5821

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2019-5807

Open SourceCoalition ESS < 30%HIGH2019-06-27

DEBIAN-CVE-2019-5807

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:13 chromium
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2019-5830

Open SourceCoalition ESS < 30%CRITICAL2019-06-27

DEBIAN-CVE-2019-5830

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2019-5830

GoogleCoalition ESS < 30%CRITICAL2019-06-05

Insufficient policy enforcement in CORS in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVEs:CVE-2019-5830

Affected products

ProductStatusVendorPackageEcosystem
backports affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

DEBIAN-CVE-2019-5828

Open SourceCoalition ESS < 30%HIGH2019-06-27

DEBIAN-CVE-2019-5828

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2019-5828

GoogleCoalition ESS < 30%HIGH2019-06-05

Object lifecycle issue in ServiceWorker in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.

CVEs:CVE-2019-5828

Affected products

ProductStatusVendorPackageEcosystem
backports affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

DEBIAN-CVE-2019-5824

Open SourceCoalition ESS < 30%HIGH2019-06-27

DEBIAN-CVE-2019-5824

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2019-5813

Open SourceCoalition ESS < 30%CRITICAL2019-06-27

DEBIAN-CVE-2019-5813

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
chromium affected Debian:11 chromium
Upstream advisory

CVE-2019-2097

Open SourceCoalition ESS < 30%HIGH2019-06-06

In HAliasAnalyzer.Query of hydrogen-alias-analysis.h, there is possible memory corruption due to type confusion. This could lead to remote code execution from a malicious proxy configuration, with no additional execution privileges needed. User interac...

CVEs:CVE-2019-2097

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

DEBIAN-CVE-2019-5829

Open SourceCoalition ESS < 30%CRITICAL2019-06-27

DEBIAN-CVE-2019-5829

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2019-5829

GoogleCoalition ESS < 30%CRITICAL2019-06-05

Integer overflow in download manager in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.

CVEs:CVE-2019-5829

Affected products

ProductStatusVendorPackageEcosystem
backports affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

DEBIAN-CVE-2019-5806

Open SourceCoalition ESS < 30%CRITICAL2019-06-27

DEBIAN-CVE-2019-5806

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2019-5832

Open SourceCoalition ESS < 30%CRITICAL2019-06-27

DEBIAN-CVE-2019-5832

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2019-5832

GoogleCoalition ESS < 30%CRITICAL2019-06-05

Insufficient policy enforcement in XMLHttpRequest in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVEs:CVE-2019-5832

Affected products

ProductStatusVendorPackageEcosystem
backports affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

DEBIAN-CVE-2019-5839

Open SourceCoalition ESS < 30%MEDIUM2019-06-27

DEBIAN-CVE-2019-5839

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2019-5839

GoogleCoalition ESS < 30%MEDIUM2019-06-05

Excessive data validation in URL parser in Google Chrome prior to 75.0.3770.80 allowed a remote attacker who convinced a user to input a URL to bypass website URL validation via a crafted URL.

CVEs:CVE-2019-5839

Affected products

ProductStatusVendorPackageEcosystem
backports affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

DEBIAN-CVE-2019-5811

Open SourceCoalition ESS < 30%HIGH2019-06-27

DEBIAN-CVE-2019-5811

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2019-12243

Open SourceCoalition ESS < 30%HIGH2019-06-05

Istio 1.1.x through 1.1.6 has Incorrect Access Control.

CVEs:CVE-2019-12243

Affected products

ProductStatusVendorPackageEcosystem
istio affected istio
Upstream advisory

CVE-2019-12243

Open SourceCoalition ESS < 30%HIGH2019-06-05

Istio may not check inbound TCP connections against istio-policy

CVEs:CVE-2019-12243

Affected products

ProductStatusVendorPackageEcosystem
istio affected istio.io istio.io/istio
Upstream advisory

CVE-2019-2093

Open SourceCoalition ESS < 30%HIGH2019-06-06

In huff_dec_1D of nlc_dec.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android...

CVEs:CVE-2019-2093

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

DEBIAN-CVE-2019-5810

Open SourceCoalition ESS < 30%HIGH2019-06-27

DEBIAN-CVE-2019-5810

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2019-2094

Open SourceCoalition ESS < 30%HIGH2019-06-06

In parseMPEGCCData of NuPlayerCCDecoder.cpp, there is a possible out of bounds write due to missing bounds checks. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Pro...

CVEs:CVE-2019-2094

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

DEBIAN-CVE-2019-5823

Open SourceCoalition ESS < 30%CRITICAL2019-06-27

DEBIAN-CVE-2019-5823

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2019-5833

Open SourceCoalition ESS < 30%MEDIUM2019-06-27

DEBIAN-CVE-2019-5833

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2019-5833

GoogleCoalition ESS < 30%MEDIUM2019-06-05

Incorrect dialog box scoping in browser in Google Chrome on Android prior to 75.0.3770.80 allowed a remote attacker to display misleading security UI via a crafted HTML page.

CVEs:CVE-2019-5833

Affected products

ProductStatusVendorPackageEcosystem
backports affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

DEBIAN-CVE-2019-5814

Open SourceCoalition ESS < 30%CRITICAL2019-06-27

DEBIAN-CVE-2019-5814

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2019-5838

Open SourceCoalition ESS < 30%CRITICAL2019-06-27

DEBIAN-CVE-2019-5838

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2019-5838

GoogleCoalition ESS < 30%CRITICAL2019-06-05

Insufficient policy enforcement in extensions API in Google Chrome prior to 75.0.3770.80 allowed an attacker who convinced a user to install a malicious extension to bypass restrictions on file URIs via a crafted Chrome Extension.

CVEs:CVE-2019-5838

Affected products

ProductStatusVendorPackageEcosystem
backports affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

CVE-2019-5842

GoogleCoalition ESS < 30%CRITICAL2019-06-14

Use after free in Blink in Google Chrome prior to 75.0.3770.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2019-5842

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2019-5834

GoogleCoalition ESS < 30%MEDIUM2019-06-05

Insufficient data validation in Blink in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to perform domain spoofing via a crafted HTML page.

CVEs:CVE-2019-5834

Affected products

ProductStatusVendorPackageEcosystem
backports affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

CVE-2019-2095

Open SourceCoalition ESS < 30%HIGH2019-06-06

In callGenIDChangeListeners and related functions of SkPixelRef.cpp, there is a possible use after free due to a race condition. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exp...

CVEs:CVE-2019-2095

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2099

Open SourceCoalition ESS < 30%HIGH2019-06-06

In nfa_rw_store_ndef_rx_buf of nfa_rw_act.cc, there is a possible out-of-bound write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploita...

CVEs:CVE-2019-2099

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2101

Open SourceCoalition ESS < 30%MEDIUM2019-06-06

In uvc_parse_standard_control of uvc_driver.c, there is a possible out-of-bound read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for ex...

CVEs:CVE-2019-2101

Affected products

ProductStatusVendorPackageEcosystem
android affected google
debian_linux affected debian
ubuntu_linux affected canonical
Upstream advisory

DEBIAN-CVE-2019-5819

Open SourceCoalition ESS < 30%HIGH2019-06-27

DEBIAN-CVE-2019-5819

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2019-2102

Open SourceCoalition ESS < 30%HIGH2019-06-06

In the Bluetooth Low Energy (BLE) specification, there is a provided example Long Term Key (LTK). If a BLE device were to use this as a hardcoded LTK, it is theoretically possible for a proximate attacker to remotely inject keystrokes on a paired Andro...

CVEs:CVE-2019-2102

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-12762

GoogleCoalition ESS < 30%MEDIUM2019-06-06

Xiaomi Mi 5s Plus devices allow attackers to trigger touchscreen anomalies via a radio signal between 198 kHz and 203 kHz, as demonstrated by a transmitter and antenna hidden just beneath the surface of a coffee-shop table, aka Ghost Touch.

CVEs:CVE-2019-12762

Affected products

ProductStatusVendorPackageEcosystem
aquos_zeta_sh-04f_firmware affected sharp
arrows_nx_f05-f_firmware affected fujitsu
galaxy_s4_firmware affected samsung
galaxy_s6_edge_firmware affected samsung
mi_5s_plus_firmware affected mi
nexus_7_firmware affected google
nexus_9_firmware affected google
xperia_z4_firmware affected sony
Upstream advisory

CVE-2019-2096

Open SourceCoalition ESS < 30%HIGH2019-06-06

In EffectRelease of EffectBundle.cpp, there is a possible memory corruption due to a double free. This could lead to local escalation of privilege in the audio server with no additional execution privileges needed. User interaction is not needed for ex...

CVEs:CVE-2019-2096

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2091

Open SourceCoalition ESS < 30%HIGH2019-06-06

In GetPermittedAccessibilityServicesForUser of DevicePolicyManagerService.java, there is a possible permissions bypass due to a missing permission check. This could lead to local escalation of privilege, with no additional permissions required. User in...

CVEs:CVE-2019-2091

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2092

Open SourceCoalition ESS < 30%HIGH2019-06-06

In isSeparateProfileChallengeAllowed of DevicePolicyManagerService.java, there is a possible permissions bypass due to a missing permission check. This could lead to local escalation of privilege, with no additional permissions required. User interacti...

CVEs:CVE-2019-2092

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2098

Open SourceCoalition ESS < 30%HIGH2019-06-06

In areNotificationsEnabledForPackage of NotificationManagerService.java, there is a possible permissions bypass due to a missing permissions check. This could lead to local escalation of privilege, with no additional privileges needed. User interaction...

CVEs:CVE-2019-2098

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2090

Open SourceCoalition ESS < 30%HIGH2019-06-06

In isPackageDeviceAdminOnAnyUser of PackageManagerService.java, there is a possible permissions bypass due to a missing permissions check. This could lead to local escalation of privilege, with no additional permissions required. User interaction is no...

CVEs:CVE-2019-2090

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-5028

GoogleEPSS <= 49%MEDIUM2019-06-27

Insufficient data validation in V8 in Google Chrome prior to 56.0.2924.76 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVEs:CVE-2017-5028

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2018-17460

GoogleEPSS <= 49%MEDIUM2019-06-27

Insufficient data validation in filesystem URIs in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.

CVEs:CVE-2018-17460

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2018-16064

GoogleEPSS <= 49%MEDIUM2019-06-27

Insufficient data validation in Extensions API in Google Chrome prior to 68.0.3440.75 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension.

CVEs:CVE-2018-16064

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2018-16086

GoogleEPSS <= 49%CRITICAL2019-06-27

Insufficient policy enforcement in extensions API in Google Chrome prior to 69.0.3497.81 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension.

CVEs:CVE-2018-16086

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2018-20073

Open SourceEPSS <= 49%MEDIUM2019-06-27

DEBIAN-CVE-2018-20073

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2018-20073

GoogleEPSS <= 49%MEDIUM2019-06-27

Use of extended attributes in downloads in Google Chrome prior to 72.0.3626.81 allowed a local attacker to read download URLs via the filesystem.

CVEs:CVE-2018-20073

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

GHSA-28hp-fgcr-2r4h

Open SourceAll remainingCRITICAL2019-06-27

Cross-Site Scripting via JSONP

Affected products

ProductStatusVendorPackageEcosystem
angular affected npm angular
Upstream advisory

GHSA-28hp-fgcr-2r4h

Open SourceAll remainingCRITICAL2019-06-27

Cross-Site Scripting via JSONP

Affected products

ProductStatusVendorPackageEcosystem
angular affected npm angular
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.