Google Security Advisories · July 2019 — Google Security Advisories
72 advisories 36 CVEs 6 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2019-07. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 6 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2019-1132

GoogleExploitedCISA KEV listedCRITICAL2019-07-10

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'.

CVEs:CVE-2019-1132

Affected products

ProductStatusVendorPackageEcosystem
windows_7 affected microsoft
windows_server_2008 affected microsoft
Upstream advisory

CVE-2019-1132

Project ZeroExploitedCISA KEV listed2019-07-10

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'.

CVEs:CVE-2019-1132

Upstream advisory

CVE-2019-0880

Project ZeroExploitedCISA KEV listed2019-07-10

A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls, aka 'Microsoft splwow64 Elevation of Privilege Vulnerability'.

CVEs:CVE-2019-0880

Upstream advisory

CVE-2019-0880

GoogleExploitedCISA KEV listedCRITICAL2019-07-10

A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls, aka 'Microsoft splwow64 Elevation of Privilege Vulnerability'.

CVEs:CVE-2019-0880

Affected products

ProductStatusVendorPackageEcosystem
windows_10_1507 affected microsoft
windows_10_1607 affected microsoft
windows_10_1703 affected microsoft
windows_10_1709 affected microsoft
windows_10_1803 affected microsoft
windows_10_1809 affected microsoft
windows_10_1903 affected microsoft
windows_8.1 affected microsoft
windows_rt_8.1 affected microsoft
windows_server_1903 affected microsoft
windows_server_2012 affected microsoft
windows_server_2016 affected microsoft
windows_server_2019 affected microsoft
Upstream advisory

CVE-2019-2107

Open SourceWeaponized exploitHIGH2019-07-02

In ihevcd_parse_pps of ihevcd_parse_headers.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. ...

CVEs:CVE-2019-2107

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-13990

GoogleActive exploitation (sightings)CRITICAL2019-07-26

initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.

CVEs:CVE-2019-13990

Affected products

ProductStatusVendorPackageEcosystem
active_iq_unified_manager affected netapp
apache_batik_mapviewer affected oracle
banking_enterprise_originations affected oracle
banking_enterprise_product_manufacturing affected oracle
banking_payments affected oracle
cloud_secure_agent affected netapp
communications_ip_service_activator affected oracle
communications_session_route_manager affected oracle
customer_management_and_segmentation_foundation affected oracle
documaker affected oracle
enterprise_manager_base_platform affected oracle
enterprise_manager_ops_center affected oracle
flexcube_investor_servicing affected oracle
flexcube_private_banking affected oracle
fusion_middleware_mapviewer affected oracle
google_guava_mapviewer affected oracle
hyperion_infrastructure_technology affected oracle
jd_edwards_enterpriseone_orchestrator affected oracle
jira_service_management affected atlassian
primavera_unifier affected oracle
quartz affected softwareag
retail_back_office affected oracle
retail_central_office affected oracle
retail_integration_bus affected oracle
retail_order_broker affected oracle
retail_point-of-service affected oracle
retail_returns_management affected oracle
retail_xstore_point_of_service affected oracle
terracotta_quartz_scheduler_mapviewer affected oracle
tomee affected apache
webcenter_sites affected oracle
Upstream advisory

CVE-2019-13990

GoogleActive exploitation (sightings)CRITICAL2019-07-26

XML external entity injection in Terracotta Quartz Scheduler

CVEs:CVE-2019-13990

Affected products

ProductStatusVendorPackageEcosystem
org.quartz-scheduler:quartz affected Maven org.quartz-scheduler:quartz
Upstream advisory

CVE-2019-5860

GoogleCoalition ESS 30-63%CRITICAL2019-07-31

Use after free in PDFium in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.

CVEs:CVE-2019-5860

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2019-1010200

GoogleCoalition ESS < 30%HIGH2019-07-23

Voice Builder Prior to commit c145d4604df67e6fc625992412eef0bf9a85e26b and f6660e6d8f0d1d931359d591dbdec580fef36d36 is affected by: CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'). The impact is: Remot...

CVEs:CVE-2019-1010200

Affected products

ProductStatusVendorPackageEcosystem
voice_builder affected google
Upstream advisory

CVE-2019-2109

Open SourceCoalition ESS < 30%HIGH2019-07-02

In MakeMPEG4VideoCodecSpecificData of AVIExtractor.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for ex...

CVEs:CVE-2019-2109

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2106

Open SourceCoalition ESS < 30%HIGH2019-07-02

In ihevcd_sao_shift_ctb of ihevcd_sao.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Produc...

CVEs:CVE-2019-2106

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-5852

GoogleCoalition ESS < 30%HIGH2019-07-31

Inappropriate implementation in JavaScript in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

CVEs:CVE-2019-5852

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2019-5850

GoogleCoalition ESS < 30%CRITICAL2019-07-31

Use after free in offline mode in Google Chrome prior to 76.0.3809.87 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

CVEs:CVE-2019-5850

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2019-5853

GoogleCoalition ESS < 30%HIGH2019-07-31

Inappropriate implementation in JavaScript in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2019-5853

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2019-5858

GoogleCoalition ESS < 30%HIGH2019-07-31

Incorrect security UI in MacOS services integration in Google Chrome on OS X prior to 76.0.3809.87 allowed a local attacker to execute arbitrary code via a crafted HTML page.

CVEs:CVE-2019-5858

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2019-5851

GoogleCoalition ESS < 30%CRITICAL2019-07-31

Use after free in WebAudio in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2019-5851

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2019-5859

GoogleCoalition ESS < 30%HIGH2019-07-31

Insufficient filtering in URI schemes in Google Chrome on Windows prior to 76.0.3809.87 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

CVEs:CVE-2019-5859

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2019-5854

GoogleCoalition ESS < 30%CRITICAL2019-07-31

Integer overflow in PDFium in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.

CVEs:CVE-2019-5854

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

openSUSE-SU-2019:1815-1

Open SourceCoalition ESS < 30%HIGH2019-07-30

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 12 SP3 chromium
chromium affected SUSE:Package Hub 15 chromium
chromium affected openSUSE:Leap 15.0 chromium
chromium affected openSUSE:Leap 15.1 chromium
Upstream advisory

CVE-2019-5847

GoogleCoalition ESS < 30%MEDIUM2019-07-16

Inappropriate implementation in JavaScript in Google Chrome prior to 75.0.3770.142 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2019-5847

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2019-2111

Open SourceCoalition ESS < 30%CRITICAL2019-07-02

In loop of DnsTlsSocket.cpp, there is a possible heap memory corruption due to a use after free. This could lead to remote code execution in the netd server with no additional execution privileges needed. User interaction is not needed for exploitation...

CVEs:CVE-2019-2111

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2116

Open SourceCoalition ESS < 30%HIGH2019-07-02

In save_attr_seq of sdp_discovery.cc, there is a possible out-of-bound read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation....

CVEs:CVE-2019-2116

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-5856

GoogleCoalition ESS < 30%CRITICAL2019-07-31

Insufficient policy enforcement in storage in Google Chrome prior to 76.0.3809.87 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.

CVEs:CVE-2019-5856

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2019-5862

GoogleCoalition ESS < 30%MEDIUM2019-07-31

Insufficient data validation in AppCache in Google Chrome prior to 76.0.3809.87 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.

CVEs:CVE-2019-5862

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2019-5865

GoogleCoalition ESS < 30%CRITICAL2019-07-31

Insufficient policy enforcement in navigations in Google Chrome prior to 76.0.3809.87 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.

CVEs:CVE-2019-5865

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2019-5855

GoogleCoalition ESS < 30%CRITICAL2019-07-31

Integer overflow in PDFium in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.

CVEs:CVE-2019-5855

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2019-2105

Open SourceCoalition ESS < 30%HIGH2019-07-02

In FileInputStream::Read of file_input_stream.cc, there is a possible memory corruption due to uninitialized data. This could lead to remote code execution in an unprivileged process with no additional execution privileges needed. User interaction is n...

CVEs:CVE-2019-2105

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-5857

GoogleCoalition ESS < 30%MEDIUM2019-07-31

Inappropriate implementation in JavaScript in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page.

CVEs:CVE-2019-5857

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2019-5861

GoogleCoalition ESS < 30%MEDIUM2019-07-31

Insufficient data validation in Blink in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to bypass anti-clickjacking policy via a crafted HTML page.

CVEs:CVE-2019-5861

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2019-5848

GoogleCoalition ESS < 30%HIGH2019-07-16

Incorrect font handling in autofill in Google Chrome prior to 75.0.3770.142 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

CVEs:CVE-2019-5848

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2019-5864

GoogleCoalition ESS < 30%MEDIUM2019-07-31

Insufficient data validation in CORS in Google Chrome prior to 76.0.3809.87 allowed an attacker who convinced a user to install a malicious extension to bypass content security policy via a crafted Chrome Extension.

CVEs:CVE-2019-5864

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2019-1020014

Open SourceCoalition ESS < 30%CRITICAL2019-07-29

DEBIAN-CVE-2019-1020014

Affected products

ProductStatusVendorPackageEcosystem
golang-github-docker-docker-credential-helpers affected Debian:11 golang-github-docker-docker-credential-helpers
golang-github-docker-docker-credential-helpers affected Debian:12 golang-github-docker-docker-credential-helpers
golang-github-docker-docker-credential-helpers affected Debian:13 golang-github-docker-docker-credential-helpers
golang-github-docker-docker-credential-helpers affected Debian:14 golang-github-docker-docker-credential-helpers
Upstream advisory

CVE-2019-10365

Open SourceCoalition ESS < 30%MEDIUM2019-07-31

Jenkins Google Kubernetes Engine Plugin vulnerable to Exposure of Resource to Wrong Sphere

CVEs:CVE-2019-10365

Affected products

ProductStatusVendorPackageEcosystem
org.jenkins-ci.plugins:google-kubernetes-engine affected Maven org.jenkins-ci.plugins:google-kubernetes-engine
Upstream advisory

CVE-2019-10365

Open SourceCoalition ESS < 30%MEDIUM2019-07-31

Jenkins Google Kubernetes Engine Plugin 0.6.2 and earlier created a temporary file containing a temporary access token in the project workspace, where it could be accessed by users with Job/Read permission.

CVEs:CVE-2019-10365

Affected products

ProductStatusVendorPackageEcosystem
kubernetes_engine affected google
Upstream advisory

CVE-2019-2118

Open SourceCoalition ESS < 30%HIGH2019-07-02

In various functions of Parcel.cpp, there are uninitialized or partially initialized stack variables. These could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Prod...

CVEs:CVE-2019-2118

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2104

Open SourceCoalition ESS < 30%MEDIUM2019-07-02

In HIDL, safe_union, and other C++ structs/unions being sent to application processes, there are uninitialized fields. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for ex...

CVEs:CVE-2019-2104

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2112

Open SourceCoalition ESS < 30%HIGH2019-07-02

In several functions of alarm.cc, there is possible memory corruption due to a use after free. This could lead to local code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Ve...

CVEs:CVE-2019-2112

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2117

Open SourceCoalition ESS < 30%MEDIUM2019-07-02

In checkQueryPermission of TelephonyProvider.java, there is a possible disclosure of secure data due to a missing permission check. This could lead to local information disclosure about carrier systems with no additional execution privileges needed. Us...

CVEs:CVE-2019-2117

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2113

Open SourceCoalition ESS < 30%MEDIUM2019-07-02

In setup wizard there is a bypass of some checks when wifi connection is skipped. This could lead to factory reset protection bypass with no additional privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Andr...

CVEs:CVE-2019-2113

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2119

Open SourceCoalition ESS < 30%MEDIUM2019-07-02

In multiple functions of key_store_service.cpp, there is a possible Information Disclosure due to improper locking. This could lead to local information disclosure of protected data with no additional execution privileges needed. User interaction is no...

CVEs:CVE-2019-2119

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.