CVE-2019-5783
|
Missing URI encoding of untrusted input in DevTools in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to perform a Dangling Markup Injection attack via a crafted HTML page.
Published:
February 19, 2019; 12:29:02 PM -05:00
|
V3: 8.8 HIGH
V2: 6.8 MEDIUM
|
CVE-2019-5782
|
Incorrect optimization assumptions in V8 in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
Published:
February 19, 2019; 12:29:02 PM -05:00
|
V3: 8.8 HIGH
V2: 6.8 MEDIUM
|
CVE-2019-5781
|
Incorrect handling of a confusable character in Omnibox in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.
Published:
February 19, 2019; 12:29:02 PM -05:00
|
V3: 6.5 MEDIUM
V2: 4.3 MEDIUM
|
CVE-2019-5780
|
Insufficient restrictions on what can be done with Apple Events in Google Chrome on macOS prior to 72.0.3626.81 allowed a local attacker to execute JavaScript via Apple Events.
Published:
February 19, 2019; 12:29:02 PM -05:00
|
V3: 7.8 HIGH
V2: 4.6 MEDIUM
|
CVE-2019-5779
|
Insufficient policy validation in ServiceWorker in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
Published:
February 19, 2019; 12:29:01 PM -05:00
|
V3: 4.3 MEDIUM
V2: 4.3 MEDIUM
|
CVE-2019-5778
|
A missing case for handling special schemes in permission request checks in Extensions in Google Chrome prior to 72.0.3626.81 allowed an attacker who convinced a user to install a malicious extension to bypass extension permission checks for privileged pages via a crafted Chrome Extension.
Published:
February 19, 2019; 12:29:01 PM -05:00
|
V3: 6.5 MEDIUM
V2: 4.3 MEDIUM
|
CVE-2019-5777
|
Incorrect handling of a confusable character in Omnibox in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.
Published:
February 19, 2019; 12:29:01 PM -05:00
|
V3: 6.5 MEDIUM
V2: 4.3 MEDIUM
|
CVE-2019-5776
|
Incorrect handling of a confusable character in Omnibox in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.
Published:
February 19, 2019; 12:29:01 PM -05:00
|
V3: 6.5 MEDIUM
V2: 4.3 MEDIUM
|
CVE-2019-5775
|
Incorrect handling of a confusable character in Omnibox in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.
Published:
February 19, 2019; 12:29:01 PM -05:00
|
V3: 6.5 MEDIUM
V2: 4.3 MEDIUM
|
CVE-2019-5774
|
Omission of the .desktop filetype from the Safe Browsing checklist in SafeBrowsing in Google Chrome on Linux prior to 72.0.3626.81 allowed an attacker who convinced a user to download a .desktop file to execute arbitrary code via a downloaded .desktop file.
Published:
February 19, 2019; 12:29:01 PM -05:00
|
V3: 8.8 HIGH
V2: 6.8 MEDIUM
|
CVE-2019-5773
|
Insufficient origin validation in IndexedDB in Google Chrome prior to 72.0.3626.81 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page.
Published:
February 19, 2019; 12:29:01 PM -05:00
|
V3: 6.5 MEDIUM
V2: 4.3 MEDIUM
|
CVE-2019-5772
|
Sharing of objects over calls into JavaScript runtime in PDFium in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
Published:
February 19, 2019; 12:29:01 PM -05:00
|
V3: 8.8 HIGH
V2: 6.8 MEDIUM
|
CVE-2019-5771
|
An incorrect JIT of GLSL shaders in SwiftShader in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to execute arbitrary code via a crafted HTML page.
Published:
February 19, 2019; 12:29:01 PM -05:00
|
V3: 8.8 HIGH
V2: 6.8 MEDIUM
|
CVE-2019-5770
|
Insufficient input validation in WebGL in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
Published:
February 19, 2019; 12:29:01 PM -05:00
|
V3: 8.8 HIGH
V2: 6.8 MEDIUM
|
CVE-2019-5769
|
Incorrect handling of invalid end character position when front rendering in Blink in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published:
February 19, 2019; 12:29:01 PM -05:00
|
V3: 8.8 HIGH
V2: 6.8 MEDIUM
|
CVE-2019-5768
|
DevTools API not correctly gating on extension capability in DevTools in Google Chrome prior to 72.0.3626.81 allowed an attacker who convinced a user to install a malicious extension to read local files via a crafted Chrome Extension.
Published:
February 19, 2019; 12:29:01 PM -05:00
|
V3: 6.5 MEDIUM
V2: 4.3 MEDIUM
|
CVE-2019-5767
|
Insufficient protection of permission UI in WebAPKs in Google Chrome on Android prior to 72.0.3626.81 allowed an attacker who convinced the user to install a malicious application to access privacy/security sensitive web APIs via a crafted APK.
Published:
February 19, 2019; 12:29:01 PM -05:00
|
V3: 6.5 MEDIUM
V2: 4.3 MEDIUM
|
CVE-2019-5766
|
Incorrect handling of origin taint checking in Canvas in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Published:
February 19, 2019; 12:29:01 PM -05:00
|
V3: 6.5 MEDIUM
V2: 4.3 MEDIUM
|
CVE-2019-5765
|
An exposed debugging endpoint in the browser in Google Chrome on Android prior to 72.0.3626.81 allowed a local attacker to obtain potentially sensitive information from process memory via a crafted Intent.
Published:
February 19, 2019; 12:29:00 PM -05:00
|
V3: 5.5 MEDIUM
V2: 4.3 MEDIUM
|
CVE-2019-5764
|
Incorrect pointer management in WebRTC in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published:
February 19, 2019; 12:29:00 PM -05:00
|
V3: 8.8 HIGH
V2: 6.8 MEDIUM
|