Google Security Advisories · September 2019 — Google Security Advisories
215 advisories 115 CVEs 4 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2019-09. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 4 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

MGASA-2019-0283

Open SourceExploitedCISA KEV listedCRITICAL2019-09-21

Updated chromium-browser-stable packages fix security vulnerabilities

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:7 chromium-browser-stable
Upstream advisory

CVE-2019-1367

GoogleExploitedCISA KEV listedCRITICAL2019-09-23

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1221.

CVEs:CVE-2019-1367

Affected products

ProductStatusVendorPackageEcosystem
internet_explorer affected microsoft
Upstream advisory

CVE-2019-1367

Project ZeroExploitedCISA KEV listed2019-09-23

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1221.

CVEs:CVE-2019-1367

Upstream advisory

CVE-2018-9581

Open SourceWeaponized exploitHIGH2019-09-27

In WiFi, the RSSI value and SSID information is broadcast as part of android.net.wifi.RSSI_CHANGE and android.net.wifi.STATE_CHANGE intents. This could lead to local information disclosure with no additional execution privileges needed. User interactio...

CVEs:CVE-2018-9581

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

MGASA-2019-0251

Open SourcePoC exploitHIGH2019-09-06

Updated golang packages fix security vulnerabilities

Affected products

ProductStatusVendorPackageEcosystem
golang affected Mageia:6 golang
golang affected Mageia:7 golang
Upstream advisory

CVE-2019-16276

GooglePoC exploitHIGH2019-09-30

Go before 1.12.10 and 1.13.x before 1.13.1 allow HTTP Request Smuggling.

CVEs:CVE-2019-16276

Affected products

ProductStatusVendorPackageEcosystem
cloud_insights_telegraf_agent affected netapp
debian_linux affected debian
developer_tools affected redhat
enterprise_linux affected redhat
enterprise_linux_eus affected redhat
fedora affected fedoraproject
go affected golang
leap affected opensuse
openshift_container_platform affected redhat
Upstream advisory

DSA-4534-1

Open SourcePoC exploit2019-09-27

golang-1.11 - security update

Affected products

ProductStatusVendorPackageEcosystem
golang-1.11 affected Debian:10 golang-1.11
Upstream advisory

CVE-2019-2181

Open SourcePoC exploitHIGH2019-09-05

In binder_transaction of binder.c in the Android kernel, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for...

CVEs:CVE-2019-2181

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9454

Open SourcePoC exploitHIGH2019-09-06

In the Android kernel in i2c driver there is a possible out of bounds write due to memory corruption. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2019-9454

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9458

Open SourcePoC exploitHIGH2019-09-06

In the Android kernel in the video driver there is a use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2019-9458

Affected products

ProductStatusVendorPackageEcosystem
android affected google
leap affected opensuse
Upstream advisory

DEBIAN-CVE-2019-16884

Open SourceCoalition ESS < 30%HIGH2019-09-25

DEBIAN-CVE-2019-16884

Affected products

ProductStatusVendorPackageEcosystem
golang-github-opencontainers-selinux affected Debian
golang-github-opencontainers-selinux affected Debian:11 golang-github-opencontainers-selinux
golang-github-opencontainers-selinux affected Debian:12 golang-github-opencontainers-selinux
golang-github-opencontainers-selinux affected Debian:13 golang-github-opencontainers-selinux
golang-github-opencontainers-selinux affected Debian:14 golang-github-opencontainers-selinux
runc affected Debian:12 runc
runc affected Debian:13 runc
runc affected Debian:14 runc
runc affected Debian:11 runc
Upstream advisory

CVE-2019-8075

GoogleCoalition ESS < 30%HIGH2019-09-27

Adobe Flash Player version 32.0.0.192 and earlier versions have a Same Origin Policy Bypass vulnerability. Successful exploitation could lead to Information Disclosure in the context of the current user.

CVEs:CVE-2019-8075

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
flash_player affected adobe
flash_player_desktop_runtime affected adobe
Upstream advisory

DLA-1920-1

Open SourceCoalition ESS < 30%2019-09-13

golang-go.crypto - security update

Affected products

ProductStatusVendorPackageEcosystem
golang-go.crypto affected Debian:8 golang-go.crypto
Upstream advisory

CVE-2019-9461

Open SourceCoalition ESS < 30%MEDIUM2019-09-06

In the Android kernel in VPN routing there is a possible information disclosure. This could lead to remote information disclosure by an adjacent network attacker with no additional execution privileges needed. User interaction is not needed for exploit...

CVEs:CVE-2019-9461

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

openSUSE-SU-2019:2156-1

Open SourceCoalition ESS < 30%HIGH2019-09-20

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP1 chromium
Upstream advisory

openSUSE-SU-2019:2155-1

Open SourceCoalition ESS < 30%HIGH2019-09-20

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 chromium
Upstream advisory

openSUSE-SU-2019:2153-1

Open SourceCoalition ESS < 30%HIGH2019-09-19

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected openSUSE:Leap 15.0 chromium
Upstream advisory

openSUSE-SU-2019:2152-1

Open SourceCoalition ESS < 30%HIGH2019-09-19

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected openSUSE:Leap 15.1 chromium
Upstream advisory

CVE-2019-5870

GoogleCoalition ESS < 30%CRITICAL2019-09-11

Use after free in media in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.

CVEs:CVE-2019-5870

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2019-5849

GoogleCoalition ESS < 30%HIGH2019-09-04

Out of bounds read in Skia in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

CVEs:CVE-2019-5849

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2019-10417

Open SourceCoalition ESS < 30%CRITICAL2019-09-25

Jenkins Kubernetes :: Pipeline :: Kubernetes Steps Plugin provides a custom whitelist for script security that allowed attackers to invoke arbitrary methods, bypassing typical sandbox protection.

CVEs:CVE-2019-10417

Affected products

ProductStatusVendorPackageEcosystem
kubernetes_pipeline affected jenkins
Upstream advisory

CVE-2019-10417

Open SourceCoalition ESS < 30%CRITICAL2019-09-25

Incorrect Authorization in Jenkins Kubernetes :: Pipeline :: Kubernetes Steps Plugin

CVEs:CVE-2019-10417

Affected products

ProductStatusVendorPackageEcosystem
io.fabric8.pipeline:kubernetes-pipeline-steps affected Maven io.fabric8.pipeline:kubernetes-pipeline-steps
Upstream advisory

CVE-2019-10418

Open SourceCoalition ESS < 30%CRITICAL2019-09-25

Jenkins Kubernetes :: Pipeline :: Arquillian Steps Plugin provides a custom whitelist for script security that allowed attackers to invoke arbitrary methods, bypassing typical sandbox protection.

CVEs:CVE-2019-10418

Affected products

ProductStatusVendorPackageEcosystem
kubernetes_pipeline affected jenkins
Upstream advisory

CVE-2019-10418

Open SourceCoalition ESS < 30%CRITICAL2019-09-25

Incorrect Authorization in Jenkins Kubernetes :: Pipeline :: Arquillian Steps Plugin

CVEs:CVE-2019-10418

Affected products

ProductStatusVendorPackageEcosystem
io.fabric8.pipeline:kubernetes-pipeline-arquillian-steps affected Maven io.fabric8.pipeline:kubernetes-pipeline-arquillian-steps
Upstream advisory

CVE-2019-2108

Open SourceCoalition ESS < 30%HIGH2019-09-05

In ihevcd_ref_list of ihevcd_ref_list.c in Android 10, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploi...

CVEs:CVE-2019-2108

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2176

Open SourceCoalition ESS < 30%HIGH2019-09-05

In ihevcd_parse_buffering_period_sei of ihevcd_parse_headers.c in Android 8.0, 8.1 and 9, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. Us...

CVEs:CVE-2019-2176

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-5881

GoogleCoalition ESS < 30%HIGH2019-09-11

Out of bounds read in SwiftShader in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

CVEs:CVE-2019-5881

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2019-5877

GoogleCoalition ESS < 30%HIGH2019-09-11

Out of bounds memory access in JavaScript in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2019-5877

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2019-10425

GoogleCoalition ESS < 30%MEDIUM2019-09-25

Jenkins Google Calendar Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.

CVEs:CVE-2019-10425

Affected products

ProductStatusVendorPackageEcosystem
google_calendar affected jenkins
Upstream advisory

CVE-2019-10425

GoogleCoalition ESS < 30%MEDIUM2019-09-25

Jenkins Google Calendar Plugin has Insufficiently Protected Credentials

CVEs:CVE-2019-10425

Affected products

ProductStatusVendorPackageEcosystem
org.jenkins-ci.plugins:gcal affected Maven org.jenkins-ci.plugins:gcal
Upstream advisory

CVE-2019-13670

GoogleCoalition ESS < 30%MEDIUM2019-09-11

Insufficient data validation in JavaScript in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2019-13670

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

MGASA-2019-0289

Open SourceCoalition ESS < 30%CRITICAL2019-09-27

Updated chromium-browser-stable packages fix security vulnerabilities

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:7 chromium-browser-stable
Upstream advisory

openSUSE-SU-2019:2186-1

Open SourceCoalition ESS < 30%CRITICAL2019-09-25

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected openSUSE:Leap 15.0 chromium
chromium affected openSUSE:Leap 15.1 chromium
Upstream advisory

CVE-2019-13687

GoogleCoalition ESS < 30%CRITICAL2019-09-19

Use after free in Blink in Google Chrome prior to 77.0.3865.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2019-13687

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2019-13688

GoogleCoalition ESS < 30%CRITICAL2019-09-19

Use after free in Blink in Google Chrome prior to 77.0.3865.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2019-13688

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2019-5876

GoogleCoalition ESS < 30%CRITICAL2019-09-11

Use after free in media in Google Chrome on Android prior to 77.0.3865.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2019-5876

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2019-13685

GoogleCoalition ESS < 30%CRITICAL2019-09-19

Use after free in sharing view in Google Chrome prior to 77.0.3865.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2019-13685

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2019-13686

GoogleCoalition ESS < 30%CRITICAL2019-09-19

Use after free in offline mode in Google Chrome prior to 77.0.3865.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2019-13686

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2019-5874

GoogleCoalition ESS < 30%HIGH2019-09-11

Insufficient filtering in URI schemes in Google Chrome on Windows prior to 77.0.3865.75 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

CVEs:CVE-2019-5874

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2019-2177

Open SourceCoalition ESS < 30%HIGH2019-09-05

In isPreferred of HidProfile.java in Android 7.1.1, 7.1.2, 8.0, 8.1 and 9, there is a possible device type confusion due to a permissions bypass. This could lead to remote code execution with no additional execution privileges needed. User interaction ...

CVEs:CVE-2019-2177

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-5878

GoogleCoalition ESS < 30%CRITICAL2019-09-11

Use after free in V8 in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2019-5878

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2019-13666

GoogleCoalition ESS < 30%HIGH2019-09-11

Information leak in storage in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVEs:CVE-2019-13666

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2019-13683

GoogleCoalition ESS < 30%CRITICAL2019-09-11

Insufficient policy enforcement in developer tools in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVEs:CVE-2019-13683

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2019-5880

GoogleCoalition ESS < 30%CRITICAL2019-09-11

Insufficient policy enforcement in Blink in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVEs:CVE-2019-5880

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2019-13668

GoogleCoalition ESS < 30%CRITICAL2019-09-11

Insufficient policy enforcement in developer tools in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVEs:CVE-2019-13668

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2019-13677

GoogleCoalition ESS < 30%CRITICAL2019-09-11

Insufficient policy enforcement in site isolation in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to bypass site isolation via a crafted HTML page.

CVEs:CVE-2019-13677

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2019-5871

GoogleCoalition ESS < 30%CRITICAL2019-09-11

Heap buffer overflow in Skia in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2019-5871

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2019-9462

Open SourceCoalition ESS < 30%HIGH2019-09-27

In Bluetooth, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions...

CVEs:CVE-2019-9462

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

openSUSE-SU-2019:2094-1

Open SourceCoalition ESS < 30%CRITICAL2019-09-08

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP1 chromium
Upstream advisory

openSUSE-SU-2019:2081-1

Open SourceCoalition ESS < 30%CRITICAL2019-09-07

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected openSUSE:Leap 15.0 chromium
Upstream advisory

openSUSE-SU-2019:2080-1

Open SourceCoalition ESS < 30%CRITICAL2019-09-07

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected openSUSE:Leap 15.1 chromium
Upstream advisory

CVE-2019-13660

GoogleCoalition ESS < 30%MEDIUM2019-09-11

UI spoofing in Chromium in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to spoof notifications via a crafted HTML page.

CVEs:CVE-2019-13660

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2019-13682

GoogleCoalition ESS < 30%CRITICAL2019-09-11

Insufficient policy enforcement in external protocol handling in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to bypass same origin policy via a crafted HTML page.

CVEs:CVE-2019-13682

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2019-13673

GoogleCoalition ESS < 30%HIGH2019-09-11

Insufficient data validation in developer tools in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVEs:CVE-2019-13673

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2019-13662

GoogleCoalition ESS < 30%CRITICAL2019-09-11

Insufficient policy enforcement in navigations in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to bypass content security policy via a crafted HTML page.

CVEs:CVE-2019-13662

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2019-13678

GoogleCoalition ESS < 30%MEDIUM2019-09-11

Incorrect data validation in downloads in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to perform domain spoofing via a crafted HTML page.

CVEs:CVE-2019-13678

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2019-13665

GoogleCoalition ESS < 30%MEDIUM2019-09-11

Insufficient filtering in Blink in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to bypass multiple file download protection via a crafted HTML page.

CVEs:CVE-2019-13665

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2019-13667

GoogleCoalition ESS < 30%MEDIUM2019-09-11

Inappropriate implementation in Omnibox in Google Chrome on iOS prior to 77.0.3865.75 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

CVEs:CVE-2019-13667

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2019-5873

GoogleCoalition ESS < 30%MEDIUM2019-09-11

Insufficient policy validation in navigation in Google Chrome on iOS prior to 77.0.3865.75 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

CVEs:CVE-2019-5873

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2019-13661

GoogleCoalition ESS < 30%MEDIUM2019-09-11

UI spoofing in Chromium in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to spoof notifications via a crafted HTML page.

CVEs:CVE-2019-13661

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2019-5872

GoogleCoalition ESS < 30%CRITICAL2019-09-11

Use after free in Mojo in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2019-5872

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2019-13674

GoogleCoalition ESS < 30%MEDIUM2019-09-11

IDN spoofing in Omnibox in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.

CVEs:CVE-2019-13674

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2019-13669

GoogleCoalition ESS < 30%MEDIUM2019-09-11

Incorrect data validation in navigation in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

CVEs:CVE-2019-13669

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2019-13675

GoogleCoalition ESS < 30%MEDIUM2019-09-11

Insufficient data validation in extensions in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to disable extensions via a crafted HTML page.

CVEs:CVE-2019-13675

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2019-13659

GoogleCoalition ESS < 30%MEDIUM2019-09-11

IDN spoofing in Omnibox in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.

CVEs:CVE-2019-13659

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2019-13663

GoogleCoalition ESS < 30%MEDIUM2019-09-11

IDN spoofing in Omnibox in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.

CVEs:CVE-2019-13663

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2019-13681

GoogleCoalition ESS < 30%MEDIUM2019-09-11

Insufficient data validation in downloads in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to bypass download restrictions via a crafted HTML page.

CVEs:CVE-2019-13681

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2019-13680

GoogleCoalition ESS < 30%MEDIUM2019-09-11

Inappropriate implementation in TLS in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to spoof client IP address to websites via crafted TLS connections.

CVEs:CVE-2019-13680

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2019-13676

GoogleCoalition ESS < 30%CRITICAL2019-09-11

Insufficient policy enforcement in Chromium in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to perform domain spoofing via a crafted HTML page.

CVEs:CVE-2019-13676

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2019-5875

GoogleCoalition ESS < 30%MEDIUM2019-09-11

Insufficient data validation in downloads in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

CVEs:CVE-2019-5875

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2019-13671

GoogleCoalition ESS < 30%MEDIUM2019-09-11

UI spoofing in Blink in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to spoof security UI via a crafted HTML page.

CVEs:CVE-2019-13671

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2019-5879

GoogleCoalition ESS < 30%CRITICAL2019-09-11

Insufficient policy enforcement in extensions in Google Chrome prior to 77.0.3865.75 allowed an attacker who convinced a user to install a malicious extension to read local files via a crafted Chrome Extension.

CVEs:CVE-2019-5879

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

SUSE-SU-2019:2317-1

Open SourceCoalition ESS < 30%HIGH2019-09-06

Security update for SUSE Manager Client Tools

Affected products

ProductStatusVendorPackageEcosystem
golang-github-prometheus-alertmanager affected SUSE:Manager Client Tools 15 golang-github-prometheus-alertmanager
golang-github-prometheus-prometheus affected SUSE:Manager Client Tools 15 golang-github-prometheus-prometheus
mgr-cfg affected SUSE:Manager Client Tools 15 mgr-cfg
mgr-daemon affected SUSE:Manager Client Tools 15 mgr-daemon
mgr-osad affected SUSE:Manager Client Tools 15 mgr-osad
mgr-virtualization affected SUSE:Manager Client Tools 15 mgr-virtualization
rhnlib affected SUSE:Manager Client Tools 15 rhnlib
spacecmd affected SUSE:Manager Client Tools 15 spacecmd
spacewalk-backend affected SUSE:Manager Client Tools 15 spacewalk-backend
spacewalk-remote-utils affected SUSE:Manager Client Tools 15 spacewalk-remote-utils
Upstream advisory

SUSE-SU-2019:2312-1

Open SourceCoalition ESS < 30%HIGH2019-09-05

Security update for SUSE Manager Client Tools

Affected products

ProductStatusVendorPackageEcosystem
golang-github-prometheus-prometheus affected SUSE:Manager Client Tools 12 golang-github-prometheus-prometheus
kiwi-desc-saltboot affected SUSE:Manager Client Tools 12 kiwi-desc-saltboot
mgr-cfg affected SUSE:Manager Client Tools 12 mgr-cfg
mgr-daemon affected SUSE:Manager Client Tools 12 mgr-daemon
mgr-osad affected SUSE:Manager Client Tools 12 mgr-osad
mgr-virtualization affected SUSE:Manager Client Tools 12 mgr-virtualization
rhnlib affected SUSE:Manager Client Tools 12 rhnlib
spacecmd affected SUSE:Manager Client Tools 12 spacecmd
spacewalk-backend affected SUSE:Manager Client Tools 12 spacewalk-backend
spacewalk-remote-utils affected SUSE:Manager Client Tools 12 spacewalk-remote-utils
Upstream advisory

CVE-2019-13679

GoogleCoalition ESS < 30%CRITICAL2019-09-11

Insufficient policy enforcement in PDFium in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to show print dialogs via a crafted PDF file.

CVEs:CVE-2019-13679

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2019-13664

GoogleCoalition ESS < 30%CRITICAL2019-09-11

Insufficient policy enforcement in Blink in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to bypass content security policy via a crafted HTML page.

CVEs:CVE-2019-13664

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2019-2179

Open SourceCoalition ESS < 30%HIGH2019-09-05

In NDEF_MsgValidate of ndef_utils in Android 7.1.1, 7.1.2, 8.0, 8.1 and 9, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interacti...

CVEs:CVE-2019-2179

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9254

Open SourceCoalition ESS < 30%HIGH2019-09-05

In readArgumentList of zygote.java in Android 10, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed fo...

CVEs:CVE-2019-9254

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9275

Open SourceCoalition ESS < 30%HIGH2019-09-06

In the Android kernel in the mnh driver there is a use after free due to improper locking. This could lead to escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2019-9275

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9445

Open SourceCoalition ESS < 30%MEDIUM2019-09-06

In the Android kernel in F2FS driver there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with system execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2019-9445

Affected products

ProductStatusVendorPackageEcosystem
android affected google
debian_linux affected debian
ubuntu_linux affected canonical
Upstream advisory

CVE-2019-2115

Open SourceCoalition ESS < 30%HIGH2019-09-05

In GateKeeper::MintAuthToken of gatekeeper.cpp in Android 7.1.1, 7.1.2, 8.0, 8.1 and 9, there is possible memory corruption due to a double free. This could lead to local escalation of privilege with System execution privileges needed. User interaction...

CVEs:CVE-2019-2115

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2182

Open SourceCoalition ESS < 30%HIGH2019-09-06

In the Android kernel in the kernel MMU code there is a possible execution path leaving some kernel text and rodata pages writable. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not...

CVEs:CVE-2019-2182

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9345

Open SourceCoalition ESS < 30%HIGH2019-09-06

In the Android kernel in sdcardfs there is a possible violation of the separation of data between profiles due to shared mapping of obb files. This could lead to local escalation of privilege with User execution privileges needed. User interaction is n...

CVEs:CVE-2019-9345

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9456

Open SourceCoalition ESS < 30%MEDIUM2019-09-06

In the Android kernel in Pixel C USB monitor driver there is a possible OOB write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2019-9456

Affected products

ProductStatusVendorPackageEcosystem
android affected google
leap affected opensuse
Upstream advisory

CVE-2019-9444

Open SourceCoalition ESS < 30%MEDIUM2019-09-06

In the Android kernel in sync debug fs driver there is a kernel pointer leak due to the usage of printf with %p. This could lead to local information disclosure with system execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2019-9444

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9441

Open SourceCoalition ESS < 30%HIGH2019-09-06

In the Android kernel in the mnh driver there is a possible out of bounds write due to improper input validation. This could lead to escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2019-9441

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2178

Open SourceCoalition ESS < 30%HIGH2019-09-05

In rw_t4t_sm_read_ndef of rw_t4t in Android 7.1.1, 7.1.2, 8.0, 8.1 and 9, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege in the NFC service with no additional execution privileges...

CVEs:CVE-2019-2178

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9448

Open SourceCoalition ESS < 30%HIGH2019-09-06

In the Android kernel in the FingerTipS touchscreen driver there is a possible out of bounds write due to a missing bounds check. This could lead to a local escalation of privilege with System execution privileges needed. User interaction is not needed...

CVEs:CVE-2019-9448

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9449

Open SourceCoalition ESS < 30%MEDIUM2019-09-06

In the Android kernel in FingerTipS touchscreen driver there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with system execution privileges needed. User interaction is not needed for exp...

CVEs:CVE-2019-9449

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9245

Open SourceCoalition ESS < 30%MEDIUM2019-09-06

In the Android kernel in the f2fs driver there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2019-9245

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9446

Open SourceCoalition ESS < 30%HIGH2019-09-06

In the Android kernel in the FingerTipS touchscreen driver there is a possible out of bounds write due to improper input validation. This could lead to a local escalation of privilege with System execution privileges needed. User interaction is not nee...

CVEs:CVE-2019-9446

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9276

Open SourceCoalition ESS < 30%HIGH2019-09-06

In the Android kernel in the synaptics_dsx_htc touchscreen driver there is a possible out of bounds write due to a use after free. This could lead to a local escalation of privilege with System execution privileges needed. User interaction is not neede...

CVEs:CVE-2019-9276

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-6240

Open SourceCoalition ESS < 30%HIGH2019-09-05

NVIDIA Tegra contains a vulnerability in BootRom where a user with kernel level privileges can write an arbitrary value to an arbitrary physical address

CVEs:CVE-2018-6240

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9451

Open SourceCoalition ESS < 30%HIGH2019-09-06

In the Android kernel in the touchscreen driver there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploita...

CVEs:CVE-2019-9451

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9248

Open SourceCoalition ESS < 30%HIGH2019-09-06

In the Android kernel in the FingerTipS touchscreen driver there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed f...

CVEs:CVE-2019-9248

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2180

Open SourceCoalition ESS < 30%MEDIUM2019-09-05

In ippSetValueTag of ipp.c in Android 8.0, 8.1 and 9, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure from the printer service with no additional execution privileges needed. User...

CVEs:CVE-2019-2180

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9452

Open SourceCoalition ESS < 30%MEDIUM2019-09-06

In the Android kernel in SEC_TS touch driver there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2019-9452

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9453

Open SourceCoalition ESS < 30%MEDIUM2019-09-06

In the Android kernel in F2FS touch driver there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with system execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2019-9453

Affected products

ProductStatusVendorPackageEcosystem
android affected google
ubuntu_linux affected canonical
Upstream advisory

CVE-2019-9455

Open SourceCoalition ESS < 30%MEDIUM2019-09-06

In the Android kernel in the video driver there is a kernel pointer leak due to a WARN_ON statement. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2019-9455

Affected products

ProductStatusVendorPackageEcosystem
android affected google
leap affected opensuse
Upstream advisory

CVE-2019-9270

Open SourceCoalition ESS < 30%HIGH2019-09-06

In the Android kernel in unifi and r8180 WiFi drivers there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed...

CVEs:CVE-2019-9270

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2175

Open SourceCoalition ESS < 30%HIGH2019-09-05

In checkAccess of SliceManagerService.java in Android 9, there is a possible permissions check bypass due to incorrect order of arguments. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction...

CVEs:CVE-2019-2175

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9463

Open SourceCoalition ESS < 30%HIGH2019-09-27

In Platform, there is a possible bypass of user interaction requirements due to background app interception. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. P...

CVEs:CVE-2019-9463

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9274

Open SourceCoalition ESS < 30%HIGH2019-09-06

In the Android kernel in the mnh driver there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2019-9274

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9436

Open SourceCoalition ESS < 30%MEDIUM2019-09-06

In the Android kernel in the bootloader there is a possible secure boot bypass. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation.

CVEs:CVE-2019-9436

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9426

Open SourceCoalition ESS < 30%HIGH2019-09-06

In the Android kernel in Bluetooth there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2019-9426

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9443

Open SourceCoalition ESS < 30%HIGH2019-09-06

In the Android kernel in the vl53L0 driver there is a possible out of bounds write due to a permissions bypass. This could lead to local escalation of privilege due to a set_fs() call without restoring the previous limit with System execution privilege...

CVEs:CVE-2019-9443

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2123

Open SourceCoalition ESS < 30%HIGH2019-09-05

In execTransact of Binder.java in Android 7.1.1, 7.1.2, 8.0, 8.1, and 9, there is a possible local execution of arbitrary code in a privileged process due to a memory overwrite. This could lead to local escalation of privilege with no additional execut...

CVEs:CVE-2019-2123

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2103

Open SourceCoalition ESS < 30%MEDIUM2019-09-05

In Google Assistant in Android 9, there is a possible permissions bypass that allows the Assistant to take a screenshot of apps with FLAG_SECURE. This could lead to local information disclosure with no additional execution privileges needed. User inter...

CVEs:CVE-2019-2103

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9447

Open SourceCoalition ESS < 30%HIGH2019-09-06

In the Android kernel in the FingerTipS touchscreen driver there is a possible use-after-free due to improper locking. This could lead to a local escalation of privilege with System execution privileges needed. User interaction is not needed for exploi...

CVEs:CVE-2019-9447

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9442

Open SourceCoalition ESS < 30%HIGH2019-09-06

In the Android kernel in the mnh driver there is possible memory corruption due to a use after free. This could lead to local escalation of privilege with System privileges required. User interaction is not needed for exploitation.

CVEs:CVE-2019-9442

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2190

Open SourceCoalition ESS < 30%MEDIUM2019-09-27

In LG's LAF component, there is a possible leak of information in a protected disk partition due to a missing bounds check. This could lead to local information disclosure via USB with User execution privileges needed. User interaction is not required ...

CVEs:CVE-2019-2190

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2191

Open SourceCoalition ESS < 30%MEDIUM2019-09-27

In LG's LAF component, there is a possible leak of information in a protected disk partition due to a missing bounds check. This could lead to local information disclosure via USB with User execution privileges needed. User interaction is not required ...

CVEs:CVE-2019-2191

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2124

Open SourceCoalition ESS < 30%HIGH2019-09-05

In ComposeActivityEmailExternal of ComposeActivityEmailExternal.java in Android 7.1.1, 7.1.2, 8.0, 8.1 and 9, there is a possible way to silently attach files to an email due to a confused deputy. This could lead to local information disclosure.

CVEs:CVE-2019-2124

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2174

Open SourceCoalition ESS < 30%HIGH2019-09-05

In SensorManager::assertStateLocked of SensorManager.cpp in Android 7.1.1, 7.1.2, 8.0, 8.1, and 9, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with no additional execution privileges need...

CVEs:CVE-2019-2174

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9273

Open SourceCoalition ESS < 30%HIGH2019-09-06

In the Android kernel in the synaptics_dsx_htc touchscreen driver there is a possible use after free due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for e...

CVEs:CVE-2019-9273

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9271

Open SourceCoalition ESS < 30%HIGH2019-09-06

In the Android kernel in the mnh driver there is a race condition due to insufficient locking. This could lead to a use-after-free which could lead to escalation of privilege with System execution privileges needed. User interaction is not needed for e...

CVEs:CVE-2019-9271

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9450

Open SourceCoalition ESS < 30%HIGH2019-09-06

In the Android kernel in the FingerTipS touchscreen driver there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for explo...

CVEs:CVE-2019-9450

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2188

Open SourceCoalition ESS < 30%HIGH2019-09-27

In the Easel driver, there is possible memory corruption due to race conditions. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android...

CVEs:CVE-2019-2188

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2189

Open SourceCoalition ESS < 30%HIGH2019-09-27

In the Easel driver, there is possible memory corruption due to race conditions. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android...

CVEs:CVE-2019-2189

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.