Advisories
GoogleExploitedCISA KEV listedCRITICAL2019-12-10
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'.
CVEs:CVE-2019-1458
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| windows_10_1507 |
affected |
microsoft |
— |
— |
| windows_10_1607 |
affected |
microsoft |
— |
— |
| windows_7 |
affected |
microsoft |
— |
— |
| windows_8.1 |
affected |
microsoft |
— |
— |
| windows_rt_8.1 |
affected |
microsoft |
— |
— |
| windows_server_2008 |
affected |
microsoft |
— |
— |
| windows_server_2012 |
affected |
microsoft |
— |
— |
| windows_server_2016 |
affected |
microsoft |
— |
— |
GoogleExploitedCISA KEV listedHIGH2019-12-10
CVEs:CVE-2019-1458
Project ZeroExploitedCISA KEV listed2019-12-10
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'.
CVEs:CVE-2019-1458
Open SourcePoC exploitCRITICAL2019-12-23
DEBIAN-CVE-2019-19926
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourcePoC exploitCRITICAL2019-12-18
DEBIAN-CVE-2019-19880
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
| sqlite3 |
affected |
Debian:11 |
sqlite3 |
— |
| sqlite3 |
affected |
Debian:12 |
sqlite3 |
— |
| sqlite3 |
affected |
Debian:14 |
sqlite3 |
— |
| sqlite3 |
affected |
Debian:13 |
sqlite3 |
— |
Open SourcePoC exploitCRITICAL2019-12-24
DEBIAN-CVE-2019-19925
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
| sqlite3 |
affected |
Debian:11 |
sqlite3 |
— |
| sqlite3 |
affected |
Debian:12 |
sqlite3 |
— |
| sqlite3 |
affected |
Debian:13 |
sqlite3 |
— |
| sqlite3 |
affected |
Debian:14 |
sqlite3 |
— |
Open SourcePoC exploitCRITICAL2019-12-24
DEBIAN-CVE-2019-19923
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
| sqlite3 |
affected |
Debian:11 |
sqlite3 |
— |
| sqlite3 |
affected |
Debian:12 |
sqlite3 |
— |
| sqlite3 |
affected |
Debian:13 |
sqlite3 |
— |
| sqlite3 |
affected |
Debian:14 |
sqlite3 |
— |
Open SourcePoC exploitCRITICAL2019-12-18
Security update for chromium
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
SUSE:Package Hub 15 SP1 |
chromium |
— |
Open SourcePoC exploitCRITICAL2019-12-16
Security update for chromium
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
openSUSE:Leap 15.1 |
chromium |
— |
| chromium |
affected |
SUSE:Package Hub 12 SP3 |
chromium |
— |
| chromium |
affected |
SUSE:Package Hub 15 |
chromium |
— |
Open SourcePoC exploitHIGH2019-12-10
DEBIAN-CVE-2019-13764
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GooglePoC exploitHIGH2019-12-10
Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2019-13764
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| backports_sle |
affected |
opensuse |
— |
— |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| package_hub |
affected |
suse |
— |
— |
GooglePoC exploitHIGH2019-12-10
CVEs:CVE-2019-13764
Open SourcePoC exploitCRITICAL2019-12-10
DEBIAN-CVE-2019-13734
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourcePoC exploitHIGH2019-12-11
DEBIAN-CVE-2019-5815
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
| libxslt |
affected |
Debian:11 |
libxslt |
— |
| libxslt |
affected |
Debian:12 |
libxslt |
— |
| libxslt |
affected |
Debian:13 |
libxslt |
— |
| libxslt |
affected |
Debian:14 |
libxslt |
— |
GooglePoC exploit2019-12-03
CVEs:CVE-2019-2225
Open SourcePoC exploitHIGH2019-12-03
When pairing with a Bluetooth device, it may be possible to pair a malicious device without any confirmation from the user, and that device may be able to interact with the phone. This could lead to remote escalation of privilege with no additional exe...
CVEs:CVE-2019-2225
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitLOW2019-12-03
CVEs:CVE-2019-9465
Open SourcePoC exploitMEDIUM2019-12-03
In the Titan M handling of cryptographic operations, there is a possible information disclosure due to an unusual root cause. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed...
CVEs:CVE-2019-9465
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2019-12-30
Security update for chromium
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
SUSE:Package Hub 12 SP3 |
chromium |
— |
| chromium |
affected |
SUSE:Package Hub 15 SP1 |
chromium |
— |
| chromium |
affected |
openSUSE:Leap 15.1 |
chromium |
— |
GoogleCoalition ESS < 30%CRITICAL2019-12-18
Use after free in media picker in Google Chrome prior to 79.0.3945.88 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2019-13767
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| backports_sle |
affected |
opensuse |
— |
— |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleCoalition ESS < 30%HIGH2019-12-18
CVEs:CVE-2019-13767
Open SourceCoalition ESS < 30%CRITICAL2019-12-10
DEBIAN-CVE-2019-13750
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%CRITICAL2019-12-10
Insufficient data validation in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to bypass defense-in-depth measures via a crafted HTML page.
CVEs:CVE-2019-13750
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_for_scientific_computing |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| ubuntu_linux |
affected |
canonical |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2019-12-10
CVEs:CVE-2019-13750
Open SourceCoalition ESS < 30%CRITICAL2019-12-10
DEBIAN-CVE-2019-13726
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%CRITICAL2019-12-10
Buffer overflow in password manager in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to execute arbitrary code via a crafted HTML page.
CVEs:CVE-2019-13726
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_for_scientific_computing |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleCoalition ESS < 30%HIGH2019-12-10
CVEs:CVE-2019-13726
Open SourceCoalition ESS < 30%MEDIUM2019-12-13
DEBIAN-CVE-2019-19794
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-github-miekg-dns |
affected |
Debian:11 |
golang-github-miekg-dns |
— |
| golang-github-miekg-dns |
affected |
Debian:12 |
golang-github-miekg-dns |
— |
| golang-github-miekg-dns |
affected |
Debian:13 |
golang-github-miekg-dns |
— |
| golang-github-miekg-dns |
affected |
Debian:14 |
golang-github-miekg-dns |
— |
Open SourceCoalition ESS < 30%CRITICAL2019-12-10
DEBIAN-CVE-2019-13751
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%MEDIUM2019-12-10
CVEs:CVE-2019-13751
GoogleCoalition ESS < 30%CRITICAL2019-12-10
Uninitialized data in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
CVEs:CVE-2019-13751
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_for_scientific_computing |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| ubuntu_linux |
affected |
canonical |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2019-12-10
DEBIAN-CVE-2019-13725
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%HIGH2019-12-10
CVEs:CVE-2019-13725
GoogleCoalition ESS < 30%CRITICAL2019-12-10
Use-after-free in Bluetooth in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to execute arbitrary code via a crafted HTML page.
CVEs:CVE-2019-13725
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_for_scientific_computing |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2019-12-05
Improper input validation in Kubernetes CSI sidecar containers for external-provisioner (<v0.4.3, <v1.0.2, v1.1, <v1.2.2, <v1.3.1), external-snapshotter (<v0.4.2, <v1.0.2, v1.1, <1.2.2), and external-resizer (v0.1, v0.2) could result in unauthorized Pe...
CVEs:CVE-2019-11255
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| external-provisioner |
affected |
kubernetes |
— |
— |
| external-resizer |
affected |
kubernetes |
— |
— |
| external-snapshotter |
affected |
kubernetes |
— |
— |
| openshift_container_platform |
affected |
redhat |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2019-12-05
Kubernetes CSI Sidecar Containers Can Allow Unauthorized Data Access
CVEs:CVE-2019-11255
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes-csi/external-provisioner |
affected |
github.com |
github.com/kubernetes-csi/external-provisioner |
— |
| kubernetes-csi/external-resizer |
affected |
github.com |
github.com/kubernetes-csi/external-resizer |
— |
| kubernetes-csi/external-snapshotter/v6 |
affected |
github.com |
github.com/kubernetes-csi/external-snapshotter/v6 |
— |
Open SourceCoalition ESS < 30%HIGH2019-12-10
DEBIAN-CVE-2019-13730
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%2019-12-10
CVEs:CVE-2019-13730
GoogleCoalition ESS < 30%HIGH2019-12-10
Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2019-13730
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| backports |
affected |
opensuse |
— |
— |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_for_scientific_computing |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| suse_package_hub_for_suse_linux_enterprise |
affected |
novell |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2019-12-10
DEBIAN-CVE-2019-13735
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%HIGH2019-12-10
CVEs:CVE-2019-13735
GoogleCoalition ESS < 30%CRITICAL2019-12-10
Out of bounds write in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
CVEs:CVE-2019-13735
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_for_scientific_computing |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2019-12-10
DEBIAN-CVE-2019-13753
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2019-12-10
DEBIAN-CVE-2019-13752
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%MEDIUM2019-12-10
CVEs:CVE-2019-13753
GoogleCoalition ESS < 30%CRITICAL2019-12-10
Out of bounds read in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
CVEs:CVE-2019-13753
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_for_scientific_computing |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| ubuntu_linux |
affected |
canonical |
— |
— |
GoogleCoalition ESS < 30%CRITICAL2019-12-10
Out of bounds read in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
CVEs:CVE-2019-13752
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_for_scientific_computing |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| ubuntu_linux |
affected |
canonical |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2019-12-10
CVEs:CVE-2019-13752
Open SourceCoalition ESS < 30%CRITICAL2019-12-10
DEBIAN-CVE-2019-13754
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%CRITICAL2019-12-10
Insufficient policy enforcement in extensions in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
CVEs:CVE-2019-13754
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_for_scientific_computing |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2019-12-10
CVEs:CVE-2019-13754
Open SourceCoalition ESS < 30%CRITICAL2019-12-10
DEBIAN-CVE-2019-13728
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
GoogleCoalition ESS < 30%CRITICAL2019-12-10
Out of bounds write in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2019-13728
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_for_scientific_computing |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleCoalition ESS < 30%HIGH2019-12-10
CVEs:CVE-2019-13728
Open SourceCoalition ESS < 30%MEDIUM2019-12-10
DEBIAN-CVE-2019-13749
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%MEDIUM2019-12-10
Incorrect security UI in Omnibox in Google Chrome on iOS prior to 79.0.3945.79 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
CVEs:CVE-2019-13749
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_for_scientific_computing |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2019-12-10
CVEs:CVE-2019-13749
Open SourceCoalition ESS < 30%CRITICAL2019-12-10
DEBIAN-CVE-2019-13736
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%CRITICAL2019-12-10
Integer overflow in PDFium in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
CVEs:CVE-2019-13736
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_for_scientific_computing |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleCoalition ESS < 30%HIGH2019-12-10
CVEs:CVE-2019-13736
Open SourceCoalition ESS < 30%CRITICAL2019-12-10
DEBIAN-CVE-2019-13745
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%CRITICAL2019-12-10
Insufficient policy enforcement in audio in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
CVEs:CVE-2019-13745
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| backports_sle |
affected |
opensuse |
— |
— |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| package_hub |
affected |
suse |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2019-12-10
CVEs:CVE-2019-13745
Open SourceCoalition ESS < 30%CRITICAL2019-12-18
Security update for chromium
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
SUSE:Package Hub 15 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2019-12-10
DEBIAN-CVE-2019-13729
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%CRITICAL2019-12-10
Use-after-free in WebSockets in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2019-13729
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_for_scientific_computing |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleCoalition ESS < 30%HIGH2019-12-10
CVEs:CVE-2019-13729
Open SourceCoalition ESS < 30%CRITICAL2019-12-10
DEBIAN-CVE-2019-13727
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%HIGH2019-12-10
CVEs:CVE-2019-13727
GoogleCoalition ESS < 30%CRITICAL2019-12-10
Insufficient policy enforcement in WebSockets in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to bypass same origin policy via a crafted HTML page.
CVEs:CVE-2019-13727
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_for_scientific_computing |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2019-12-10
DEBIAN-CVE-2019-13744
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%MEDIUM2019-12-10
CVEs:CVE-2019-13744
GoogleCoalition ESS < 30%CRITICAL2019-12-10
Insufficient policy enforcement in cookies in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
CVEs:CVE-2019-13744
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_for_scientific_computing |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2019-12-10
DEBIAN-CVE-2019-13737
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
GoogleCoalition ESS < 30%CRITICAL2019-12-10
Insufficient policy enforcement in autocomplete in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
CVEs:CVE-2019-13737
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_for_scientific_computing |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2019-12-10
CVEs:CVE-2019-13737
Open SourceCoalition ESS < 30%CRITICAL2019-12-10
DEBIAN-CVE-2019-13746
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%CRITICAL2019-12-10
Insufficient policy enforcement in Omnibox in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
CVEs:CVE-2019-13746
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_for_scientific_computing |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2019-12-10
CVEs:CVE-2019-13746
Open SourceCoalition ESS < 30%CRITICAL2019-12-10
DEBIAN-CVE-2019-13732
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%HIGH2019-12-10
CVEs:CVE-2019-13732
GoogleCoalition ESS < 30%CRITICAL2019-12-10
Use-after-free in WebAudio in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2019-13732
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_for_scientific_computing |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2019-12-10
DEBIAN-CVE-2019-13742
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%MEDIUM2019-12-10
CVEs:CVE-2019-13742
GoogleCoalition ESS < 30%MEDIUM2019-12-10
Incorrect security UI in Omnibox in Google Chrome on iOS prior to 79.0.3945.79 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.
CVEs:CVE-2019-13742
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_for_scientific_computing |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
Open SourceCoalition ESS < 30%HIGH2019-12-10
DEBIAN-CVE-2019-13747
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2019-12-10
DEBIAN-CVE-2019-13738
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%HIGH2019-12-10
CVEs:CVE-2019-13747
GoogleCoalition ESS < 30%HIGH2019-12-10
Uninitialized data in rendering in Google Chrome on Android prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2019-13747
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_for_scientific_computing |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleCoalition ESS < 30%CRITICAL2019-12-10
Insufficient policy enforcement in navigation in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to bypass site isolation via a crafted HTML page.
CVEs:CVE-2019-13738
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_for_scientific_computing |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2019-12-10
CVEs:CVE-2019-13738
Open SourceCoalition ESS < 30%MEDIUM2019-12-10
DEBIAN-CVE-2019-13759
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%MEDIUM2019-12-10
CVEs:CVE-2019-13759
GoogleCoalition ESS < 30%MEDIUM2019-12-10
Incorrect security UI in interstitials in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
CVEs:CVE-2019-13759
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_for_scientific_computing |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2019-12-10
DEBIAN-CVE-2019-13739
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%CRITICAL2019-12-10
Insufficient policy enforcement in Omnibox in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
CVEs:CVE-2019-13739
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_for_scientific_computing |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2019-12-10
CVEs:CVE-2019-13739
Open SourceCoalition ESS < 30%MEDIUM2019-12-10
DEBIAN-CVE-2019-13756
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
GoogleCoalition ESS < 30%MEDIUM2019-12-10
CVEs:CVE-2019-13756
GoogleCoalition ESS < 30%MEDIUM2019-12-10
Incorrect security UI in printing in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
CVEs:CVE-2019-13756
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_for_scientific_computing |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2019-12-10
DEBIAN-CVE-2019-13743
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%MEDIUM2019-12-10
CVEs:CVE-2019-13743
GoogleCoalition ESS < 30%MEDIUM2019-12-10
Incorrect security UI in external protocol handling in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to spoof security UI via a crafted HTML page.
CVEs:CVE-2019-13743
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_for_scientific_computing |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2019-12-10
DEBIAN-CVE-2019-13758
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%CRITICAL2019-12-10
Insufficient policy enforcement in navigation in Google Chrome on Android prior to 79.0.3945.79 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
CVEs:CVE-2019-13758
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_for_scientific_computing |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2019-12-10
CVEs:CVE-2019-13758
Open SourceCoalition ESS < 30%CRITICAL2019-12-10
DEBIAN-CVE-2019-13763
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%MEDIUM2019-12-10
CVEs:CVE-2019-13763
GoogleCoalition ESS < 30%CRITICAL2019-12-10
Insufficient policy enforcement in payments in Google Chrome prior to 79.0.3945.79 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page.
CVEs:CVE-2019-13763
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_for_scientific_computing |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2019-12-10
DEBIAN-CVE-2019-13755
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%MEDIUM2019-12-10
CVEs:CVE-2019-13755
GoogleCoalition ESS < 30%CRITICAL2019-12-10
Insufficient policy enforcement in extensions in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to disable extensions via a crafted HTML page.
CVEs:CVE-2019-13755
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_for_scientific_computing |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2019-12-10
DEBIAN-CVE-2019-13757
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%MEDIUM2019-12-10
Incorrect security UI in Omnibox in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
CVEs:CVE-2019-13757
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_for_scientific_computing |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2019-12-10
CVEs:CVE-2019-13757
Open SourceCoalition ESS < 30%MEDIUM2019-12-10
DEBIAN-CVE-2019-13761
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%MEDIUM2019-12-10
CVEs:CVE-2019-13761
GoogleCoalition ESS < 30%MEDIUM2019-12-10
Incorrect security UI in Omnibox in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
CVEs:CVE-2019-13761
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_for_scientific_computing |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
Open SourceCoalition ESS < 30%HIGH2019-12-10
DEBIAN-CVE-2019-13741
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%HIGH2019-12-10
CVEs:CVE-2019-13741
GoogleCoalition ESS < 30%HIGH2019-12-10
Insufficient validation of untrusted input in Blink in Google Chrome prior to 79.0.3945.79 allowed a local attacker to bypass same origin policy via crafted clipboard content.
CVEs:CVE-2019-13741
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_for_scientific_computing |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
Open SourceCoalition ESS < 30%HIGH2019-12-10
DEBIAN-CVE-2019-13748
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%HIGH2019-12-10
Insufficient policy enforcement in developer tools in Google Chrome prior to 79.0.3945.79 allowed a local attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
CVEs:CVE-2019-13748
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_for_scientific_computing |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2019-12-10
CVEs:CVE-2019-13748
Open SourceCoalition ESS < 30%HIGH2019-12-03
In handleRun of TextLine.java, there is a possible application crash due to improper input validation. This could lead to remote denial of service when processing Unicode with no additional execution privileges needed. User interaction is not needed fo...
CVEs:CVE-2019-2232
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2019-12-03
CVEs:CVE-2019-2232
GoogleCoalition ESS < 30%MEDIUM2019-12-03
Inappropriate implementation in WebRTC in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2019-13722
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2019-12-03
CVEs:CVE-2019-13722
Open SourceCoalition ESS < 30%HIGH2019-12-17
Cross-Site Request Forgery in Jenkins Alauda Kubernetes Suport Plugin
CVEs:CVE-2019-16575
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| io.alauda.jenkins.plugins:alauda-kubernetes-support |
affected |
Maven |
io.alauda.jenkins.plugins:alauda-kubernetes-support |
— |
Open SourceCoalition ESS < 30%HIGH2019-12-17
A cross-site request forgery vulnerability in Jenkins Alauda Kubernetes Suport Plugin 2.3.0 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing the Kub...
CVEs:CVE-2019-16575
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| alauda_kubernetes_support |
affected |
jenkins |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2019-12-17
Improper Authorization in Jenkins Alauda Kubernetes Suport Plugin
CVEs:CVE-2019-16576
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| io.alauda.jenkins.plugins:alauda-kubernetes-support |
affected |
Maven |
io.alauda.jenkins.plugins:alauda-kubernetes-support |
— |
Open SourceCoalition ESS < 30%MEDIUM2019-12-17
A missing permission check in Jenkins Alauda Kubernetes Suport Plugin 2.3.0 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capt...
CVEs:CVE-2019-16576
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| alauda_kubernetes_support |
affected |
jenkins |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2019-12-10
DEBIAN-CVE-2019-13740
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%MEDIUM2019-12-10
Incorrect security UI in sharing in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
CVEs:CVE-2019-13740
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_for_scientific_computing |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2019-12-10
CVEs:CVE-2019-13740
Open SourceCoalition ESS < 30%HIGH2019-12-10
DEBIAN-CVE-2019-5843
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%2019-12-10
CVEs:CVE-2019-5843
GoogleCoalition ESS < 30%HIGH2019-12-10
Out of bounds memory access in JavaScript in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2019-5843
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2019-12-10
DEBIAN-CVE-2019-5841
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%2019-12-10
CVEs:CVE-2019-5841
GoogleCoalition ESS < 30%HIGH2019-12-10
Out of bounds memory access in JavaScript in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2019-5841
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2019-12-03
In nfcManager_routeAid and nfcManager_unrouteAid of NativeNfcManager.cpp, there is possible memory reuse due to a use after free. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not n...
CVEs:CVE-2019-2230
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2019-12-03
CVEs:CVE-2019-2230
Open SourceCoalition ESS < 30%CRITICAL2019-12-16
PYSEC-2019-209
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
Open SourceCoalition ESS < 30%CRITICAL2019-12-16
PYSEC-2019-227
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2019-12-16
PYSEC-2019-234
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2019-12-16
Heap buffer overflow in `UnsortedSegmentSum` in TensorFlow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2019-12-16
Heap buffer overflow in `UnsortedSegmentSum` in TensorFlow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2019-12-16
In TensorFlow before 1.15, a heap buffer overflow in UnsortedSegmentSum can be produced when the Index template argument is int32. In this case data_size and num_segments fields are truncated from int64 to int32 and can produce negative numbers, result...
CVEs:CVE-2019-16778
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2019-12-16
Heap buffer overflow in `UnsortedSegmentSum` in TensorFlow
CVEs:CVE-2019-16778
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%LOW2019-12-16
PYSEC-2019-234
CVEs:CVE-2019-16778
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2019-12-10
DEBIAN-CVE-2019-13672
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%2019-12-10
CVEs:CVE-2019-13672
GoogleCoalition ESS < 30%MEDIUM2019-12-10
Incorrect security UI in Omnibox in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially spoof the contents of the Omnibox (URL bar) via a crafted HTML page on iOS.
CVEs:CVE-2019-13672
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2019-12-03
n ihevcd_parse_slice_data of ihevcd_parse_slice.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitati...
CVEs:CVE-2019-2222
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2019-12-03
CVEs:CVE-2019-2222
Open SourceCoalition ESS < 30%HIGH2019-12-03
In ihevcd_ref_list of ihevcd_ref_list.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product...
CVEs:CVE-2019-2223
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2019-12-03
CVEs:CVE-2019-2223
Open SourceCoalition ESS < 30%MEDIUM2019-12-03
In various functions of RecentLocationApps.java, DevicePolicyManagerService.java, and RecognitionService.java, there is an incorrect warning indicating an app accessed the user's location. This could dissolve the trust in the platform's permission syst...
CVEs:CVE-2019-9464
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2019-12-03
CVEs:CVE-2019-9464
GoogleCoalition ESS < 30%LOW2019-12-03
CVEs:CVE-2019-2227
Open SourceCoalition ESS < 30%MEDIUM2019-12-03
In DeepCopy of btif_av.cc, there is a possible out of bounds read due to improper casting. This could lead to remote information disclosure over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.P...
CVEs:CVE-2019-2227
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2019-12-03
CVEs:CVE-2019-2228
Open SourceCoalition ESS < 30%MEDIUM2019-12-03
In array_find of array.c, there is a possible out-of-bounds read due to an incorrect bounds check. This could lead to local information disclosure in the printer spooler with no additional execution privileges needed. User interaction is not needed for...
CVEs:CVE-2019-2228
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2019-12-10
DEBIAN-CVE-2019-13762
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%HIGH2019-12-10
Insufficient policy enforcement in downloads in Google Chrome on Windows prior to 79.0.3945.79 allowed a local attacker to spoof downloaded files via local code.
CVEs:CVE-2019-13762
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_for_scientific_computing |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleCoalition ESS < 30%LOW2019-12-10
CVEs:CVE-2019-13762
GoogleCoalition ESS < 30%2019-12-03
CVEs:CVE-2019-2221
Open SourceCoalition ESS < 30%HIGH2019-12-03
In hasActivityInVisibleTask of WindowProcessController.java there’s a possible bypass of user interaction requirements due to incorrect handling of top activities in INITIALIZING state. This could lead to local escalation of privilege with no additio...
CVEs:CVE-2019-2221
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2019-12-03
In setCpuVulkanInUse of GpuStats.cpp, there is possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:...
CVEs:CVE-2019-2217
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2019-12-03
CVEs:CVE-2019-2217
Open SourceCoalition ESS < 30%MEDIUM2019-12-03
In checkOperation of AppOpsService.java, there is a possible bypass of user interaction requirements due to mishandling application suspend. This could lead to local information disclosure no additional execution privileges needed. User interaction is ...
CVEs:CVE-2019-2220
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2019-12-03
CVEs:CVE-2019-2220
Open SourceCoalition ESS < 30%HIGH2019-12-03
In export_key_der of export_key.cpp, there is possible memory corruption due to a double free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: An...
CVEs:CVE-2019-9468
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2019-12-03
CVEs:CVE-2019-9468
GoogleCoalition ESS < 30%2019-12-03
CVEs:CVE-2019-9469
Open SourceCoalition ESS < 30%HIGH2019-12-03
In km_compute_shared_hmac of km4.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitati...
CVEs:CVE-2019-9469
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2019-12-03
CVEs:CVE-2019-9470
Open SourceCoalition ESS < 30%HIGH2019-12-03
In dma_sblk_start of abc-pcie.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: ...
CVEs:CVE-2019-9470
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2019-12-03
In set_outbound_iatu of abc-pcie.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Produc...
CVEs:CVE-2019-9471
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2019-12-03
CVEs:CVE-2019-9471
GoogleCoalition ESS < 30%HIGH2019-12-03
CVEs:CVE-2019-2218
Open SourceCoalition ESS < 30%HIGH2019-12-03
In createSessionInternal of PackageInstallerService.java, there is a possible improper permission grant due to a missing permission check. This could lead to local escalation of privilege by installing malicious packages with User execution privileges ...
CVEs:CVE-2019-2218
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2019-12-03
In several functions of NotificationManagerService.java and related files, there is a possible way to record audio from the background without notification to the user due to a permission bypass. This could lead to local escalation of privilege with Us...
CVEs:CVE-2019-2219
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2019-12-03
CVEs:CVE-2019-2219
Open SourceCoalition ESS < 30%MEDIUM2019-12-03
In device_class_to_int of device_class.cc, there is a possible out of bounds read due to improper casting. This could lead to local information disclosure in the Bluetooth server with User execution privileges needed. User interaction is not needed for...
CVEs:CVE-2019-2226
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2019-12-03
CVEs:CVE-2019-2226
Open SourceCoalition ESS < 30%MEDIUM2019-12-03
In DCRYPTO_equals of compare.c, there is a possible timing attack due to improperly used crypto. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: A...
CVEs:CVE-2019-9472
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2019-12-03
CVEs:CVE-2019-9472
GoogleCoalition ESS < 30%LOW2019-12-03
CVEs:CVE-2019-2229
Open SourceCoalition ESS < 30%MEDIUM2019-12-03
In updateWidget of BaseWidgetProvider.java, there is a possible leak of user data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for expl...
CVEs:CVE-2019-2229
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2019-12-03
CVEs:CVE-2019-2231
Open SourceCoalition ESS < 30%MEDIUM2019-12-03
In Blob::Blob of blob.cpp, there is a possible unencrypted master key due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: An...
CVEs:CVE-2019-2231
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceEPSS <= 49%LOW2019-12-05
DEBIAN-CVE-2018-1002102
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes |
affected |
Debian:11 |
kubernetes |
— |
| kubernetes |
affected |
Debian:12 |
kubernetes |
— |
| kubernetes |
affected |
Debian:13 |
kubernetes |
— |
| kubernetes |
affected |
Debian:14 |
kubernetes |
— |
Open SourceEPSS <= 49%LOW2019-12-05
Improper validation of URL redirection in the Kubernetes API server in versions prior to v1.14.0 allows an attacker-controlled Kubelet to redirect API server requests from streaming endpoints to arbitrary hosts. Impacted API servers will follow the red...
CVEs:CVE-2018-1002102
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| fedora |
affected |
fedoraproject |
— |
— |
| kubernetes |
affected |
kubernetes |
— |
— |