Google Security Advisories · December 2019 — Google Security Advisories
195 advisories 124 CVEs 3 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2019-12. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 3 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2019-1458

GoogleExploitedCISA KEV listedCRITICAL2019-12-10

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'.

CVEs:CVE-2019-1458

Affected products

ProductStatusVendorPackageEcosystem
windows_10_1507 affected microsoft
windows_10_1607 affected microsoft
windows_7 affected microsoft
windows_8.1 affected microsoft
windows_rt_8.1 affected microsoft
windows_server_2008 affected microsoft
windows_server_2012 affected microsoft
windows_server_2016 affected microsoft
Upstream advisory

CVE-2019-1458

Project ZeroExploitedCISA KEV listed2019-12-10

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'.

CVEs:CVE-2019-1458

Upstream advisory

DEBIAN-CVE-2019-19926

Open SourcePoC exploitCRITICAL2019-12-23

DEBIAN-CVE-2019-19926

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2019-19880

Open SourcePoC exploitCRITICAL2019-12-18

DEBIAN-CVE-2019-19880

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
chromium affected Debian:11 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
sqlite3 affected Debian:11 sqlite3
sqlite3 affected Debian:12 sqlite3
sqlite3 affected Debian:14 sqlite3
sqlite3 affected Debian:13 sqlite3
Upstream advisory

DEBIAN-CVE-2019-19925

Open SourcePoC exploitCRITICAL2019-12-24

DEBIAN-CVE-2019-19925

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:13 chromium
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:14 chromium
sqlite3 affected Debian:11 sqlite3
sqlite3 affected Debian:12 sqlite3
sqlite3 affected Debian:13 sqlite3
sqlite3 affected Debian:14 sqlite3
Upstream advisory

DEBIAN-CVE-2019-19923

Open SourcePoC exploitCRITICAL2019-12-24

DEBIAN-CVE-2019-19923

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
sqlite3 affected Debian:11 sqlite3
sqlite3 affected Debian:12 sqlite3
sqlite3 affected Debian:13 sqlite3
sqlite3 affected Debian:14 sqlite3
Upstream advisory

openSUSE-SU-2019:2694-1

Open SourcePoC exploitCRITICAL2019-12-18

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP1 chromium
Upstream advisory

openSUSE-SU-2019:2692-1

Open SourcePoC exploitCRITICAL2019-12-16

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected openSUSE:Leap 15.1 chromium
chromium affected SUSE:Package Hub 12 SP3 chromium
chromium affected SUSE:Package Hub 15 chromium
Upstream advisory

DEBIAN-CVE-2019-13764

Open SourcePoC exploitHIGH2019-12-10

DEBIAN-CVE-2019-13764

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2019-13764

GooglePoC exploitHIGH2019-12-10

Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2019-13764

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
fedora affected fedoraproject
package_hub affected suse
Upstream advisory

DEBIAN-CVE-2019-13734

Open SourcePoC exploitCRITICAL2019-12-10

DEBIAN-CVE-2019-13734

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2019-5815

Open SourcePoC exploitHIGH2019-12-11

DEBIAN-CVE-2019-5815

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
libxslt affected Debian:11 libxslt
libxslt affected Debian:12 libxslt
libxslt affected Debian:13 libxslt
libxslt affected Debian:14 libxslt
Upstream advisory

CVE-2019-2225

Open SourcePoC exploitHIGH2019-12-03

When pairing with a Bluetooth device, it may be possible to pair a malicious device without any confirmation from the user, and that device may be able to interact with the phone. This could lead to remote escalation of privilege with no additional exe...

CVEs:CVE-2019-2225

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9465

Open SourcePoC exploitMEDIUM2019-12-03

In the Titan M handling of cryptographic operations, there is a possible information disclosure due to an unusual root cause. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed...

CVEs:CVE-2019-9465

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

openSUSE-SU-2019:2712-1

Open SourceCoalition ESS < 30%CRITICAL2019-12-30

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 12 SP3 chromium
chromium affected SUSE:Package Hub 15 SP1 chromium
chromium affected openSUSE:Leap 15.1 chromium
Upstream advisory

CVE-2019-13767

GoogleCoalition ESS < 30%CRITICAL2019-12-18

Use after free in media picker in Google Chrome prior to 79.0.3945.88 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2019-13767

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2019-13750

Open SourceCoalition ESS < 30%CRITICAL2019-12-10

DEBIAN-CVE-2019-13750

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2019-13750

GoogleCoalition ESS < 30%CRITICAL2019-12-10

Insufficient data validation in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to bypass defense-in-depth measures via a crafted HTML page.

CVEs:CVE-2019-13750

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_for_scientific_computing affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
fedora affected fedoraproject
ubuntu_linux affected canonical
Upstream advisory

DEBIAN-CVE-2019-13726

Open SourceCoalition ESS < 30%CRITICAL2019-12-10

DEBIAN-CVE-2019-13726

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2019-13726

GoogleCoalition ESS < 30%CRITICAL2019-12-10

Buffer overflow in password manager in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to execute arbitrary code via a crafted HTML page.

CVEs:CVE-2019-13726

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_for_scientific_computing affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2019-19794

Open SourceCoalition ESS < 30%MEDIUM2019-12-13

DEBIAN-CVE-2019-19794

Affected products

ProductStatusVendorPackageEcosystem
golang-github-miekg-dns affected Debian:11 golang-github-miekg-dns
golang-github-miekg-dns affected Debian:12 golang-github-miekg-dns
golang-github-miekg-dns affected Debian:13 golang-github-miekg-dns
golang-github-miekg-dns affected Debian:14 golang-github-miekg-dns
Upstream advisory

DEBIAN-CVE-2019-13751

Open SourceCoalition ESS < 30%CRITICAL2019-12-10

DEBIAN-CVE-2019-13751

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2019-13751

GoogleCoalition ESS < 30%CRITICAL2019-12-10

Uninitialized data in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

CVEs:CVE-2019-13751

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_for_scientific_computing affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
fedora affected fedoraproject
ubuntu_linux affected canonical
Upstream advisory

DEBIAN-CVE-2019-13725

Open SourceCoalition ESS < 30%CRITICAL2019-12-10

DEBIAN-CVE-2019-13725

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2019-13725

GoogleCoalition ESS < 30%CRITICAL2019-12-10

Use-after-free in Bluetooth in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to execute arbitrary code via a crafted HTML page.

CVEs:CVE-2019-13725

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_for_scientific_computing affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
fedora affected fedoraproject
Upstream advisory

CVE-2019-11255

GoogleCoalition ESS < 30%MEDIUM2019-12-05

Improper input validation in Kubernetes CSI sidecar containers for external-provisioner (<v0.4.3, <v1.0.2, v1.1, <v1.2.2, <v1.3.1), external-snapshotter (<v0.4.2, <v1.0.2, v1.1, <1.2.2), and external-resizer (v0.1, v0.2) could result in unauthorized Pe...

CVEs:CVE-2019-11255

Affected products

ProductStatusVendorPackageEcosystem
external-provisioner affected kubernetes
external-resizer affected kubernetes
external-snapshotter affected kubernetes
openshift_container_platform affected redhat
Upstream advisory

CVE-2019-11255

Open SourceCoalition ESS < 30%MEDIUM2019-12-05

Kubernetes CSI Sidecar Containers Can Allow Unauthorized Data Access

CVEs:CVE-2019-11255

Affected products

ProductStatusVendorPackageEcosystem
kubernetes-csi/external-provisioner affected github.com github.com/kubernetes-csi/external-provisioner
kubernetes-csi/external-resizer affected github.com github.com/kubernetes-csi/external-resizer
kubernetes-csi/external-snapshotter/v6 affected github.com github.com/kubernetes-csi/external-snapshotter/v6
Upstream advisory

DEBIAN-CVE-2019-13730

Open SourceCoalition ESS < 30%HIGH2019-12-10

DEBIAN-CVE-2019-13730

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2019-13730

GoogleCoalition ESS < 30%HIGH2019-12-10

Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2019-13730

Affected products

ProductStatusVendorPackageEcosystem
backports affected opensuse
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_for_scientific_computing affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
fedora affected fedoraproject
suse_package_hub_for_suse_linux_enterprise affected novell
Upstream advisory

DEBIAN-CVE-2019-13735

Open SourceCoalition ESS < 30%CRITICAL2019-12-10

DEBIAN-CVE-2019-13735

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2019-13735

GoogleCoalition ESS < 30%CRITICAL2019-12-10

Out of bounds write in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

CVEs:CVE-2019-13735

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_for_scientific_computing affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2019-13753

Open SourceCoalition ESS < 30%CRITICAL2019-12-10

DEBIAN-CVE-2019-13753

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2019-13752

Open SourceCoalition ESS < 30%CRITICAL2019-12-10

DEBIAN-CVE-2019-13752

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2019-13753

GoogleCoalition ESS < 30%CRITICAL2019-12-10

Out of bounds read in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

CVEs:CVE-2019-13753

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_for_scientific_computing affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
fedora affected fedoraproject
ubuntu_linux affected canonical
Upstream advisory

CVE-2019-13752

GoogleCoalition ESS < 30%CRITICAL2019-12-10

Out of bounds read in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

CVEs:CVE-2019-13752

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_for_scientific_computing affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
fedora affected fedoraproject
ubuntu_linux affected canonical
Upstream advisory

DEBIAN-CVE-2019-13754

Open SourceCoalition ESS < 30%CRITICAL2019-12-10

DEBIAN-CVE-2019-13754

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2019-13754

GoogleCoalition ESS < 30%CRITICAL2019-12-10

Insufficient policy enforcement in extensions in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

CVEs:CVE-2019-13754

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_for_scientific_computing affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2019-13728

Open SourceCoalition ESS < 30%CRITICAL2019-12-10

DEBIAN-CVE-2019-13728

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
Upstream advisory

CVE-2019-13728

GoogleCoalition ESS < 30%CRITICAL2019-12-10

Out of bounds write in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2019-13728

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_for_scientific_computing affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2019-13749

Open SourceCoalition ESS < 30%MEDIUM2019-12-10

DEBIAN-CVE-2019-13749

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2019-13749

GoogleCoalition ESS < 30%MEDIUM2019-12-10

Incorrect security UI in Omnibox in Google Chrome on iOS prior to 79.0.3945.79 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

CVEs:CVE-2019-13749

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_for_scientific_computing affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2019-13736

Open SourceCoalition ESS < 30%CRITICAL2019-12-10

DEBIAN-CVE-2019-13736

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2019-13736

GoogleCoalition ESS < 30%CRITICAL2019-12-10

Integer overflow in PDFium in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.

CVEs:CVE-2019-13736

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_for_scientific_computing affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2019-13745

Open SourceCoalition ESS < 30%CRITICAL2019-12-10

DEBIAN-CVE-2019-13745

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2019-13745

GoogleCoalition ESS < 30%CRITICAL2019-12-10

Insufficient policy enforcement in audio in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVEs:CVE-2019-13745

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
fedora affected fedoraproject
package_hub affected suse
Upstream advisory

openSUSE-SU-2019:2693-1

Open SourceCoalition ESS < 30%CRITICAL2019-12-18

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 chromium
Upstream advisory

DEBIAN-CVE-2019-13729

Open SourceCoalition ESS < 30%CRITICAL2019-12-10

DEBIAN-CVE-2019-13729

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2019-13729

GoogleCoalition ESS < 30%CRITICAL2019-12-10

Use-after-free in WebSockets in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2019-13729

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_for_scientific_computing affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2019-13727

Open SourceCoalition ESS < 30%CRITICAL2019-12-10

DEBIAN-CVE-2019-13727

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:11 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2019-13727

GoogleCoalition ESS < 30%CRITICAL2019-12-10

Insufficient policy enforcement in WebSockets in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to bypass same origin policy via a crafted HTML page.

CVEs:CVE-2019-13727

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_for_scientific_computing affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2019-13744

Open SourceCoalition ESS < 30%CRITICAL2019-12-10

DEBIAN-CVE-2019-13744

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2019-13744

GoogleCoalition ESS < 30%CRITICAL2019-12-10

Insufficient policy enforcement in cookies in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVEs:CVE-2019-13744

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_for_scientific_computing affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2019-13737

Open SourceCoalition ESS < 30%CRITICAL2019-12-10

DEBIAN-CVE-2019-13737

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
chromium affected Debian:11 chromium
Upstream advisory

CVE-2019-13737

GoogleCoalition ESS < 30%CRITICAL2019-12-10

Insufficient policy enforcement in autocomplete in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

CVEs:CVE-2019-13737

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_for_scientific_computing affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2019-13746

Open SourceCoalition ESS < 30%CRITICAL2019-12-10

DEBIAN-CVE-2019-13746

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2019-13746

GoogleCoalition ESS < 30%CRITICAL2019-12-10

Insufficient policy enforcement in Omnibox in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

CVEs:CVE-2019-13746

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_for_scientific_computing affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2019-13732

Open SourceCoalition ESS < 30%CRITICAL2019-12-10

DEBIAN-CVE-2019-13732

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2019-13732

GoogleCoalition ESS < 30%CRITICAL2019-12-10

Use-after-free in WebAudio in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2019-13732

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_for_scientific_computing affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2019-13742

Open SourceCoalition ESS < 30%MEDIUM2019-12-10

DEBIAN-CVE-2019-13742

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:13 chromium
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2019-13742

GoogleCoalition ESS < 30%MEDIUM2019-12-10

Incorrect security UI in Omnibox in Google Chrome on iOS prior to 79.0.3945.79 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.

CVEs:CVE-2019-13742

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_for_scientific_computing affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2019-13747

Open SourceCoalition ESS < 30%HIGH2019-12-10

DEBIAN-CVE-2019-13747

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2019-13738

Open SourceCoalition ESS < 30%CRITICAL2019-12-10

DEBIAN-CVE-2019-13738

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2019-13747

GoogleCoalition ESS < 30%HIGH2019-12-10

Uninitialized data in rendering in Google Chrome on Android prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2019-13747

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_for_scientific_computing affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
fedora affected fedoraproject
Upstream advisory

CVE-2019-13738

GoogleCoalition ESS < 30%CRITICAL2019-12-10

Insufficient policy enforcement in navigation in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to bypass site isolation via a crafted HTML page.

CVEs:CVE-2019-13738

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_for_scientific_computing affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2019-13759

Open SourceCoalition ESS < 30%MEDIUM2019-12-10

DEBIAN-CVE-2019-13759

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2019-13759

GoogleCoalition ESS < 30%MEDIUM2019-12-10

Incorrect security UI in interstitials in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via a crafted HTML page.

CVEs:CVE-2019-13759

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_for_scientific_computing affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2019-13739

Open SourceCoalition ESS < 30%CRITICAL2019-12-10

DEBIAN-CVE-2019-13739

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2019-13739

GoogleCoalition ESS < 30%CRITICAL2019-12-10

Insufficient policy enforcement in Omnibox in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.

CVEs:CVE-2019-13739

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_for_scientific_computing affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2019-13756

Open SourceCoalition ESS < 30%MEDIUM2019-12-10

DEBIAN-CVE-2019-13756

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:14 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
Upstream advisory

CVE-2019-13756

GoogleCoalition ESS < 30%MEDIUM2019-12-10

Incorrect security UI in printing in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via a crafted HTML page.

CVEs:CVE-2019-13756

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_for_scientific_computing affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2019-13743

Open SourceCoalition ESS < 30%MEDIUM2019-12-10

DEBIAN-CVE-2019-13743

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2019-13743

GoogleCoalition ESS < 30%MEDIUM2019-12-10

Incorrect security UI in external protocol handling in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to spoof security UI via a crafted HTML page.

CVEs:CVE-2019-13743

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_for_scientific_computing affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2019-13758

Open SourceCoalition ESS < 30%CRITICAL2019-12-10

DEBIAN-CVE-2019-13758

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2019-13758

GoogleCoalition ESS < 30%CRITICAL2019-12-10

Insufficient policy enforcement in navigation in Google Chrome on Android prior to 79.0.3945.79 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

CVEs:CVE-2019-13758

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_for_scientific_computing affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2019-13763

Open SourceCoalition ESS < 30%CRITICAL2019-12-10

DEBIAN-CVE-2019-13763

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:13 chromium
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2019-13763

GoogleCoalition ESS < 30%CRITICAL2019-12-10

Insufficient policy enforcement in payments in Google Chrome prior to 79.0.3945.79 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page.

CVEs:CVE-2019-13763

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_for_scientific_computing affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2019-13755

Open SourceCoalition ESS < 30%CRITICAL2019-12-10

DEBIAN-CVE-2019-13755

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2019-13755

GoogleCoalition ESS < 30%CRITICAL2019-12-10

Insufficient policy enforcement in extensions in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to disable extensions via a crafted HTML page.

CVEs:CVE-2019-13755

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_for_scientific_computing affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2019-13757

Open SourceCoalition ESS < 30%MEDIUM2019-12-10

DEBIAN-CVE-2019-13757

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:13 chromium
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2019-13757

GoogleCoalition ESS < 30%MEDIUM2019-12-10

Incorrect security UI in Omnibox in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.

CVEs:CVE-2019-13757

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_for_scientific_computing affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2019-13761

Open SourceCoalition ESS < 30%MEDIUM2019-12-10

DEBIAN-CVE-2019-13761

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2019-13761

GoogleCoalition ESS < 30%MEDIUM2019-12-10

Incorrect security UI in Omnibox in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.

CVEs:CVE-2019-13761

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_for_scientific_computing affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2019-13741

Open SourceCoalition ESS < 30%HIGH2019-12-10

DEBIAN-CVE-2019-13741

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2019-13741

GoogleCoalition ESS < 30%HIGH2019-12-10

Insufficient validation of untrusted input in Blink in Google Chrome prior to 79.0.3945.79 allowed a local attacker to bypass same origin policy via crafted clipboard content.

CVEs:CVE-2019-13741

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_for_scientific_computing affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2019-13748

Open SourceCoalition ESS < 30%HIGH2019-12-10

DEBIAN-CVE-2019-13748

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2019-13748

GoogleCoalition ESS < 30%HIGH2019-12-10

Insufficient policy enforcement in developer tools in Google Chrome prior to 79.0.3945.79 allowed a local attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

CVEs:CVE-2019-13748

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_for_scientific_computing affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
fedora affected fedoraproject
Upstream advisory

CVE-2019-2232

Open SourceCoalition ESS < 30%HIGH2019-12-03

In handleRun of TextLine.java, there is a possible application crash due to improper input validation. This could lead to remote denial of service when processing Unicode with no additional execution privileges needed. User interaction is not needed fo...

CVEs:CVE-2019-2232

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-13722

GoogleCoalition ESS < 30%MEDIUM2019-12-03

Inappropriate implementation in WebRTC in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2019-13722

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2019-16575

Open SourceCoalition ESS < 30%HIGH2019-12-17

Cross-Site Request Forgery in Jenkins Alauda Kubernetes Suport Plugin

CVEs:CVE-2019-16575

Affected products

ProductStatusVendorPackageEcosystem
io.alauda.jenkins.plugins:alauda-kubernetes-support affected Maven io.alauda.jenkins.plugins:alauda-kubernetes-support
Upstream advisory

CVE-2019-16575

Open SourceCoalition ESS < 30%HIGH2019-12-17

A cross-site request forgery vulnerability in Jenkins Alauda Kubernetes Suport Plugin 2.3.0 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing the Kub...

CVEs:CVE-2019-16575

Affected products

ProductStatusVendorPackageEcosystem
alauda_kubernetes_support affected jenkins
Upstream advisory

CVE-2019-16576

Open SourceCoalition ESS < 30%MEDIUM2019-12-17

Improper Authorization in Jenkins Alauda Kubernetes Suport Plugin

CVEs:CVE-2019-16576

Affected products

ProductStatusVendorPackageEcosystem
io.alauda.jenkins.plugins:alauda-kubernetes-support affected Maven io.alauda.jenkins.plugins:alauda-kubernetes-support
Upstream advisory

CVE-2019-16576

Open SourceCoalition ESS < 30%MEDIUM2019-12-17

A missing permission check in Jenkins Alauda Kubernetes Suport Plugin 2.3.0 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capt...

CVEs:CVE-2019-16576

Affected products

ProductStatusVendorPackageEcosystem
alauda_kubernetes_support affected jenkins
Upstream advisory

DEBIAN-CVE-2019-13740

Open SourceCoalition ESS < 30%MEDIUM2019-12-10

DEBIAN-CVE-2019-13740

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2019-13740

GoogleCoalition ESS < 30%MEDIUM2019-12-10

Incorrect security UI in sharing in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via a crafted HTML page.

CVEs:CVE-2019-13740

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_for_scientific_computing affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2019-5843

Open SourceCoalition ESS < 30%HIGH2019-12-10

DEBIAN-CVE-2019-5843

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2019-5843

GoogleCoalition ESS < 30%HIGH2019-12-10

Out of bounds memory access in JavaScript in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2019-5843

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2019-5841

Open SourceCoalition ESS < 30%HIGH2019-12-10

DEBIAN-CVE-2019-5841

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2019-5841

GoogleCoalition ESS < 30%HIGH2019-12-10

Out of bounds memory access in JavaScript in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2019-5841

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2019-2230

Open SourceCoalition ESS < 30%HIGH2019-12-03

In nfcManager_routeAid and nfcManager_unrouteAid of NativeNfcManager.cpp, there is possible memory reuse due to a use after free. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not n...

CVEs:CVE-2019-2230

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PYSEC-2019-209

Open SourceCoalition ESS < 30%CRITICAL2019-12-16

PYSEC-2019-209

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2019-227

Open SourceCoalition ESS < 30%CRITICAL2019-12-16

PYSEC-2019-227

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2019-234

Open SourceCoalition ESS < 30%CRITICAL2019-12-16

PYSEC-2019-234

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-844w-j86r-4x2j

Open SourceCoalition ESS < 30%CRITICAL2019-12-16

Heap buffer overflow in `UnsortedSegmentSum` in TensorFlow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-844w-j86r-4x2j

Open SourceCoalition ESS < 30%CRITICAL2019-12-16

Heap buffer overflow in `UnsortedSegmentSum` in TensorFlow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2019-16778

Open SourceCoalition ESS < 30%CRITICAL2019-12-16

In TensorFlow before 1.15, a heap buffer overflow in UnsortedSegmentSum can be produced when the Index template argument is int32. In this case data_size and num_segments fields are truncated from int64 to int32 and can produce negative numbers, result...

CVEs:CVE-2019-16778

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2019-16778

Open SourceCoalition ESS < 30%CRITICAL2019-12-16

Heap buffer overflow in `UnsortedSegmentSum` in TensorFlow

CVEs:CVE-2019-16778

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2019-16778

Open SourceCoalition ESS < 30%LOW2019-12-16

PYSEC-2019-234

CVEs:CVE-2019-16778

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

DEBIAN-CVE-2019-13672

Open SourceCoalition ESS < 30%MEDIUM2019-12-10

DEBIAN-CVE-2019-13672

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2019-13672

GoogleCoalition ESS < 30%MEDIUM2019-12-10

Incorrect security UI in Omnibox in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially spoof the contents of the Omnibox (URL bar) via a crafted HTML page on iOS.

CVEs:CVE-2019-13672

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2019-2222

Open SourceCoalition ESS < 30%HIGH2019-12-03

n ihevcd_parse_slice_data of ihevcd_parse_slice.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitati...

CVEs:CVE-2019-2222

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2223

Open SourceCoalition ESS < 30%HIGH2019-12-03

In ihevcd_ref_list of ihevcd_ref_list.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product...

CVEs:CVE-2019-2223

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9464

Open SourceCoalition ESS < 30%MEDIUM2019-12-03

In various functions of RecentLocationApps.java, DevicePolicyManagerService.java, and RecognitionService.java, there is an incorrect warning indicating an app accessed the user's location. This could dissolve the trust in the platform's permission syst...

CVEs:CVE-2019-9464

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2227

Open SourceCoalition ESS < 30%MEDIUM2019-12-03

In DeepCopy of btif_av.cc, there is a possible out of bounds read due to improper casting. This could lead to remote information disclosure over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.P...

CVEs:CVE-2019-2227

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2228

Open SourceCoalition ESS < 30%MEDIUM2019-12-03

In array_find of array.c, there is a possible out-of-bounds read due to an incorrect bounds check. This could lead to local information disclosure in the printer spooler with no additional execution privileges needed. User interaction is not needed for...

CVEs:CVE-2019-2228

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

DEBIAN-CVE-2019-13762

Open SourceCoalition ESS < 30%HIGH2019-12-10

DEBIAN-CVE-2019-13762

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2019-13762

GoogleCoalition ESS < 30%HIGH2019-12-10

Insufficient policy enforcement in downloads in Google Chrome on Windows prior to 79.0.3945.79 allowed a local attacker to spoof downloaded files via local code.

CVEs:CVE-2019-13762

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_for_scientific_computing affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
fedora affected fedoraproject
Upstream advisory

CVE-2019-2221

Open SourceCoalition ESS < 30%HIGH2019-12-03

In hasActivityInVisibleTask of WindowProcessController.java there’s a possible bypass of user interaction requirements due to incorrect handling of top activities in INITIALIZING state. This could lead to local escalation of privilege with no additio...

CVEs:CVE-2019-2221

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2217

Open SourceCoalition ESS < 30%HIGH2019-12-03

In setCpuVulkanInUse of GpuStats.cpp, there is possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:...

CVEs:CVE-2019-2217

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2220

Open SourceCoalition ESS < 30%MEDIUM2019-12-03

In checkOperation of AppOpsService.java, there is a possible bypass of user interaction requirements due to mishandling application suspend. This could lead to local information disclosure no additional execution privileges needed. User interaction is ...

CVEs:CVE-2019-2220

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9468

Open SourceCoalition ESS < 30%HIGH2019-12-03

In export_key_der of export_key.cpp, there is possible memory corruption due to a double free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: An...

CVEs:CVE-2019-9468

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9469

Open SourceCoalition ESS < 30%HIGH2019-12-03

In km_compute_shared_hmac of km4.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitati...

CVEs:CVE-2019-9469

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9470

Open SourceCoalition ESS < 30%HIGH2019-12-03

In dma_sblk_start of abc-pcie.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: ...

CVEs:CVE-2019-9470

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9471

Open SourceCoalition ESS < 30%HIGH2019-12-03

In set_outbound_iatu of abc-pcie.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Produc...

CVEs:CVE-2019-9471

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2218

Open SourceCoalition ESS < 30%HIGH2019-12-03

In createSessionInternal of PackageInstallerService.java, there is a possible improper permission grant due to a missing permission check. This could lead to local escalation of privilege by installing malicious packages with User execution privileges ...

CVEs:CVE-2019-2218

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2219

Open SourceCoalition ESS < 30%MEDIUM2019-12-03

In several functions of NotificationManagerService.java and related files, there is a possible way to record audio from the background without notification to the user due to a permission bypass. This could lead to local escalation of privilege with Us...

CVEs:CVE-2019-2219

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2226

Open SourceCoalition ESS < 30%MEDIUM2019-12-03

In device_class_to_int of device_class.cc, there is a possible out of bounds read due to improper casting. This could lead to local information disclosure in the Bluetooth server with User execution privileges needed. User interaction is not needed for...

CVEs:CVE-2019-2226

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9472

Open SourceCoalition ESS < 30%MEDIUM2019-12-03

In DCRYPTO_equals of compare.c, there is a possible timing attack due to improperly used crypto. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: A...

CVEs:CVE-2019-9472

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2229

Open SourceCoalition ESS < 30%MEDIUM2019-12-03

In updateWidget of BaseWidgetProvider.java, there is a possible leak of user data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for expl...

CVEs:CVE-2019-2229

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2231

Open SourceCoalition ESS < 30%MEDIUM2019-12-03

In Blob::Blob of blob.cpp, there is a possible unencrypted master key due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: An...

CVEs:CVE-2019-2231

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

DEBIAN-CVE-2018-1002102

Open SourceEPSS <= 49%LOW2019-12-05

DEBIAN-CVE-2018-1002102

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected Debian:11 kubernetes
kubernetes affected Debian:12 kubernetes
kubernetes affected Debian:13 kubernetes
kubernetes affected Debian:14 kubernetes
Upstream advisory

CVE-2018-1002102

Open SourceEPSS <= 49%LOW2019-12-05

Improper validation of URL redirection in the Kubernetes API server in versions prior to v1.14.0 allows an attacker-controlled Kubelet to redirect API server requests from streaming endpoints to arbitrary hosts. Impacted API servers will follow the red...

CVEs:CVE-2018-1002102

Affected products

ProductStatusVendorPackageEcosystem
fedora affected fedoraproject
kubernetes affected kubernetes
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.