ALT-BU-2019-3497-1
Branch sisyphus update bulletin.
Closed bugs
Lost socket connection
Closed vulnerabilities
BDU:2019-00904
Уязвимость модуля отображения Blink веб-браузера Google Chrome, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2019-00905
Уязвимость набора инструментов DevTools веб-браузера Google Chrome, позволяющая нарушителю получить несанкционированный доступ к информации
BDU:2019-00906
Уязвимость пользовательского интерфейса в WebAPK веб-браузера Google Chrome, позволяющая нарушителю получить несанкционированный доступ к информации
BDU:2019-00907
Уязвимость механизма проверки происхождения источника для Canvas веб-браузера Google Chrome, позволяющая нарушителю получить несанкционированный доступ к информации
BDU:2019-00908
Уязвимость компонента для отображения веб-страниц WebView и браузера Google Chrome, позволяющая нарушителю получить несанкционированный доступ к информации
BDU:2019-00909
Уязвимость реализации технологии WebRTC веб-браузера Google Chrome, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2019-00910
Уязвимость обработчика JavaScript-сценариев V8 веб-браузера Google Chrome, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2019-00911
Уязвимость обработчика PDF-содержимого PDFium веб-браузера Google Chrome, позволяющая нарушителю выполнить произвольный код
BDU:2019-00912
Уязвимость реализации технологии WebRTC веб-браузера Google Chrome, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2019-00913
Уязвимость веб-браузера Google Chrome, связанная с ошибками при обработке жизненного цикла элементов HTML select, позволяющая нарушителю выйти из изолированной программной среды браузера
BDU:2019-00914
Уязвимость модуля отображения Blink веб-браузера Google Chrome, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2019-00915
Уязвимость механизма обработки SVG-объектов веб-браузера Google Chrome, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2019-00916
Уязвимость обработчика PDF-содержимого PDFium веб-браузера Google Chrome, позволяющая нарушителю выполнить произвольный код
BDU:2019-00917
Уязвимость обработчика JavaScript-сценариев V8 веб-браузера Google Chrome, позволяющая нарушителю выполнить произвольный код
BDU:2019-00918
Уязвимость веб-браузера Google Chrome, связанная с ошибками реализации сетевого протокола QUIC, позволяющая нарушителю получить несанкционированный доступ к информации
BDU:2019-00955
Уязвимость компонента Omnibox веб-браузера Google Chrome, позволяющая нарушителю подделать содержимое адресной строки
BDU:2019-00956
Уязвимость компонента Omnibox веб-браузера Google Chrome, позволяющая нарушителю подделать содержимое адресной строки
BDU:2019-00957
Уязвимость компонента Omnibox веб-браузера Google Chrome, позволяющая нарушителю подделать содержимое адресной строки
BDU:2019-00958
Уязвимость компонента Omnibox веб-браузера Google Chrome, позволяющая нарушителю подделать содержимое адресной строки
BDU:2019-01049
Уязвимость компонента WebGL веб-браузера Chrome, позволяющая нарушителю переписывать произвольные файлы в целевом каталоге
BDU:2019-01050
Уязвимость компонента SwiftShader веб-браузера Chrome, позволяющая нарушителю получить несанкционированный доступ к данным
BDU:2019-01051
Уязвимость компонента IndexedDB веб-браузера Chrome, позволяющая нарушителю получить несанкционированный доступ к данным
BDU:2019-01162
Уязвимость библиотеки SwiftShader веб-браузера Google Chrome, позволяющая нарушителю выполнить произвольный код
BDU:2019-01308
Уязвимость механизма рендеринга PDFium браузера Google Chrome, связанная с использованием памяти после освобождения, позволяющая нарушителю оказать воздействие на целостность защищаемой информации
BDU:2019-01309
Уязвимость браузера Google Chrome, связанная с некорректной проверкой ввода данных, позволяющая нарушителю загрузить .desktop файл для выполнения произвольного кода
BDU:2019-01310
Уязвимость браузера Google Chrome, связанная с некорректной нейтрализацией ввода при генерации веб-страницы, позволяющая нарушителю обойти существующие ограничения доступа для привилегированных страниц
BDU:2019-01311
Уязвимость браузера Google Chrome, связанная с недостаточной проверкой политик Service Worker, позволяющая нарушителю обойти ограничения навигации
BDU:2019-01312
Уязвимость браузера Google Chrome, связанная с некорректной проверкой ввода данных, позволяющая нарушителю выполнить произвольный JavaScript-код
BDU:2019-01313
Уязвимость браузера Google Chrome, связанная с некорректной проверкой ввода данных, позволяющая нарушителю выполнить произвольный код
BDU:2019-01314
Уязвимость компонента DevTools браузера Google Chrome, позволяющая нарушителю вызвать отказ в обслуживании, нарушить конфиденциальность и целостность защищаемых данных
BDU:2019-01571
Уязвимость библиотеки Skia используемой веб-браузеров Firefox, Firefox ESR и программы для работы с электронной почтой Thunderbird, связанная с целочисленным переполнением, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2018-20073
Use of extended attributes in downloads in Google Chrome prior to 72.0.3626.81 allowed a local attacker to read download URLs via the filesystem.
Modified: 2024-11-21
CVE-2019-13684
Inappropriate implementation in JavaScript in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Modified: 2024-11-21
CVE-2019-13768
Use after free in FileAPI in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chrome security severity: High)
Modified: 2024-11-21
CVE-2019-5754
Implementation error in QUIC Networking in Google Chrome prior to 72.0.3626.81 allowed an attacker running or able to cause use of a proxy server to obtain cleartext of transport encryption via malicious network proxy.
- 106767
- 106767
- RHSA-2019:0309
- RHSA-2019:0309
- https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.html
- https://crbug.com/914497
- https://crbug.com/914497
- FEDORA-2019-05a780936d
- FEDORA-2019-05a780936d
- FEDORA-2019-561eae4626
- FEDORA-2019-561eae4626
- DSA-4395
- DSA-4395
Modified: 2024-11-21
CVE-2019-5755
Incorrect handling of negative zero in V8 in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page.
- 106767
- 106767
- RHSA-2019:0309
- RHSA-2019:0309
- https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.html
- https://crbug.com/913296
- https://crbug.com/913296
- FEDORA-2019-05a780936d
- FEDORA-2019-05a780936d
- FEDORA-2019-561eae4626
- FEDORA-2019-561eae4626
- DSA-4395
- DSA-4395
Modified: 2024-11-21
CVE-2019-5756
Inappropriate memory management when caching in PDFium in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file.
- 106767
- 106767
- RHSA-2019:0309
- RHSA-2019:0309
- https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.html
- https://crbug.com/895152
- https://crbug.com/895152
- FEDORA-2019-05a780936d
- FEDORA-2019-05a780936d
- FEDORA-2019-561eae4626
- FEDORA-2019-561eae4626
- DSA-4395
- DSA-4395
Modified: 2024-11-21
CVE-2019-5757
An incorrect object type assumption in SVG in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page.
- 106767
- 106767
- RHSA-2019:0309
- RHSA-2019:0309
- https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.html
- https://crbug.com/915469
- https://crbug.com/915469
- FEDORA-2019-05a780936d
- FEDORA-2019-05a780936d
- FEDORA-2019-561eae4626
- FEDORA-2019-561eae4626
- DSA-4395
- DSA-4395
Modified: 2024-11-21
CVE-2019-5758
Incorrect object lifecycle management in Blink in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- 106767
- 106767
- RHSA-2019:0309
- RHSA-2019:0309
- https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.html
- https://crbug.com/913970
- https://crbug.com/913970
- FEDORA-2019-05a780936d
- FEDORA-2019-05a780936d
- FEDORA-2019-561eae4626
- FEDORA-2019-561eae4626
- DSA-4395
- DSA-4395
Modified: 2024-11-21
CVE-2019-5759
Incorrect lifetime handling in HTML select elements in Google Chrome on Android and Mac prior to 72.0.3626.81 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
- 106767
- 106767
- RHSA-2019:0309
- RHSA-2019:0309
- https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.html
- https://crbug.com/912211
- https://crbug.com/912211
- FEDORA-2019-05a780936d
- FEDORA-2019-05a780936d
- FEDORA-2019-561eae4626
- FEDORA-2019-561eae4626
- DSA-4395
- DSA-4395
Modified: 2024-11-21
CVE-2019-5760
Insufficient checks of pointer validity in WebRTC in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- 106767
- 106767
- RHSA-2019:0309
- RHSA-2019:0309
- https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.html
- https://crbug.com/912074
- https://crbug.com/912074
- FEDORA-2019-05a780936d
- FEDORA-2019-05a780936d
- FEDORA-2019-561eae4626
- FEDORA-2019-561eae4626
- DSA-4395
- DSA-4395
Modified: 2024-11-21
CVE-2019-5761
Incorrect object lifecycle management in SwiftShader in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- 106767
- 106767
- RHSA-2019:0309
- RHSA-2019:0309
- https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.html
- https://crbug.com/904714
- https://crbug.com/904714
- FEDORA-2019-05a780936d
- FEDORA-2019-05a780936d
- FEDORA-2019-561eae4626
- FEDORA-2019-561eae4626
Modified: 2024-11-21
CVE-2019-5762
Inappropriate memory management when caching in PDFium in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file.
- 106767
- 106767
- RHSA-2019:0309
- RHSA-2019:0309
- https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.html
- https://crbug.com/900552
- https://crbug.com/900552
- FEDORA-2019-05a780936d
- FEDORA-2019-05a780936d
- FEDORA-2019-561eae4626
- FEDORA-2019-561eae4626
- DSA-4395
- DSA-4395
Modified: 2024-11-21
CVE-2019-5763
Failure to check error conditions in V8 in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- 106767
- 106767
- RHSA-2019:0309
- RHSA-2019:0309
- https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.html
- https://crbug.com/914731
- https://crbug.com/914731
- FEDORA-2019-05a780936d
- FEDORA-2019-05a780936d
- FEDORA-2019-561eae4626
- FEDORA-2019-561eae4626
- DSA-4395
- DSA-4395
Modified: 2024-11-21
CVE-2019-5764
Incorrect pointer management in WebRTC in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- 106767
- 106767
- RHSA-2019:0309
- RHSA-2019:0309
- https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.html
- https://crbug.com/913246
- https://crbug.com/913246
- FEDORA-2019-05a780936d
- FEDORA-2019-05a780936d
- FEDORA-2019-561eae4626
- FEDORA-2019-561eae4626
- DSA-4395
- DSA-4395
Modified: 2024-11-21
CVE-2019-5765
An exposed debugging endpoint in the browser in Google Chrome on Android prior to 72.0.3626.81 allowed a local attacker to obtain potentially sensitive information from process memory via a crafted Intent.
- 106767
- 106767
- RHSA-2019:0309
- RHSA-2019:0309
- https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.html
- https://crbug.com/922627
- https://crbug.com/922627
- FEDORA-2019-05a780936d
- FEDORA-2019-05a780936d
- FEDORA-2019-561eae4626
- FEDORA-2019-561eae4626
- DSA-4395
- DSA-4395
Modified: 2024-11-21
CVE-2019-5766
Incorrect handling of origin taint checking in Canvas in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
- RHSA-2019:0309
- RHSA-2019:0309
- https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.html
- https://crbug.com/907047
- https://crbug.com/907047
- FEDORA-2019-05a780936d
- FEDORA-2019-05a780936d
- FEDORA-2019-561eae4626
- FEDORA-2019-561eae4626
- DSA-4395
- DSA-4395
Modified: 2024-11-21
CVE-2019-5767
Insufficient protection of permission UI in WebAPKs in Google Chrome on Android prior to 72.0.3626.81 allowed an attacker who convinced the user to install a malicious application to access privacy/security sensitive web APIs via a crafted APK.
- 106767
- 106767
- RHSA-2019:0309
- RHSA-2019:0309
- https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.html
- https://crbug.com/902427
- https://crbug.com/902427
- FEDORA-2019-05a780936d
- FEDORA-2019-05a780936d
- FEDORA-2019-561eae4626
- FEDORA-2019-561eae4626
- DSA-4395
- DSA-4395
Modified: 2024-11-21
CVE-2019-5768
DevTools API not correctly gating on extension capability in DevTools in Google Chrome prior to 72.0.3626.81 allowed an attacker who convinced a user to install a malicious extension to read local files via a crafted Chrome Extension.
- 106767
- 106767
- RHSA-2019:0309
- RHSA-2019:0309
- https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.html
- https://crbug.com/805557
- https://crbug.com/805557
- FEDORA-2019-05a780936d
- FEDORA-2019-05a780936d
- FEDORA-2019-561eae4626
- FEDORA-2019-561eae4626
- DSA-4395
- DSA-4395
Modified: 2024-11-21
CVE-2019-5769
Incorrect handling of invalid end character position when front rendering in Blink in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- RHSA-2019:0309
- RHSA-2019:0309
- https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.html
- https://crbug.com/913975
- https://crbug.com/913975
- FEDORA-2019-05a780936d
- FEDORA-2019-05a780936d
- FEDORA-2019-561eae4626
- FEDORA-2019-561eae4626
- DSA-4395
- DSA-4395
Modified: 2024-11-21
CVE-2019-5770
Insufficient input validation in WebGL in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
- 106767
- 106767
- RHSA-2019:0309
- RHSA-2019:0309
- https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.html
- https://crbug.com/908749
- https://crbug.com/908749
- FEDORA-2019-05a780936d
- FEDORA-2019-05a780936d
- FEDORA-2019-561eae4626
- FEDORA-2019-561eae4626
- DSA-4395
- DSA-4395
Modified: 2024-11-21
CVE-2019-5771
An incorrect JIT of GLSL shaders in SwiftShader in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to execute arbitrary code via a crafted HTML page.
- 106767
- 106767
- RHSA-2019:0309
- RHSA-2019:0309
- https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.html
- https://crbug.com/904265
- https://crbug.com/904265
- FEDORA-2019-05a780936d
- FEDORA-2019-05a780936d
- FEDORA-2019-561eae4626
- FEDORA-2019-561eae4626
Modified: 2024-11-21
CVE-2019-5772
Sharing of objects over calls into JavaScript runtime in PDFium in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
- 106767
- 106767
- RHSA-2019:0309
- RHSA-2019:0309
- https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.html
- https://crbug.com/908292
- https://crbug.com/908292
- FEDORA-2019-05a780936d
- FEDORA-2019-05a780936d
- FEDORA-2019-561eae4626
- FEDORA-2019-561eae4626
- DSA-4395
- DSA-4395
Modified: 2024-11-21
CVE-2019-5773
Insufficient origin validation in IndexedDB in Google Chrome prior to 72.0.3626.81 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page.
- 106767
- 106767
- RHSA-2019:0309
- RHSA-2019:0309
- https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.html
- https://crbug.com/917668
- https://crbug.com/917668
- FEDORA-2019-05a780936d
- FEDORA-2019-05a780936d
- FEDORA-2019-561eae4626
- FEDORA-2019-561eae4626
- DSA-4395
- DSA-4395
Modified: 2024-11-21
CVE-2019-5774
Omission of the .desktop filetype from the Safe Browsing checklist in SafeBrowsing in Google Chrome on Linux prior to 72.0.3626.81 allowed an attacker who convinced a user to download a .desktop file to execute arbitrary code via a downloaded .desktop file.
- 106767
- 106767
- RHSA-2019:0309
- RHSA-2019:0309
- https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.html
- https://crbug.com/904182
- https://crbug.com/904182
- FEDORA-2019-05a780936d
- FEDORA-2019-05a780936d
- FEDORA-2019-561eae4626
- FEDORA-2019-561eae4626
- DSA-4395
- DSA-4395
Modified: 2024-11-21
CVE-2019-5775
Incorrect handling of a confusable character in Omnibox in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.
- 106767
- 106767
- RHSA-2019:0309
- RHSA-2019:0309
- https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.html
- https://crbug.com/896722
- https://crbug.com/896722
- FEDORA-2019-05a780936d
- FEDORA-2019-05a780936d
- FEDORA-2019-561eae4626
- FEDORA-2019-561eae4626
- DSA-4395
- DSA-4395
Modified: 2024-11-21
CVE-2019-5776
Incorrect handling of a confusable character in Omnibox in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.
- 106767
- 106767
- RHSA-2019:0309
- RHSA-2019:0309
- https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.html
- https://crbug.com/863663
- https://crbug.com/863663
- FEDORA-2019-05a780936d
- FEDORA-2019-05a780936d
- FEDORA-2019-561eae4626
- FEDORA-2019-561eae4626
- DSA-4395
- DSA-4395
Modified: 2024-11-21
CVE-2019-5777
Incorrect handling of a confusable character in Omnibox in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.
- 106767
- 106767
- RHSA-2019:0309
- RHSA-2019:0309
- https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.html
- https://crbug.com/849421
- https://crbug.com/849421
- FEDORA-2019-05a780936d
- FEDORA-2019-05a780936d
- FEDORA-2019-561eae4626
- FEDORA-2019-561eae4626
- DSA-4395
- DSA-4395
Modified: 2024-11-21
CVE-2019-5778
A missing case for handling special schemes in permission request checks in Extensions in Google Chrome prior to 72.0.3626.81 allowed an attacker who convinced a user to install a malicious extension to bypass extension permission checks for privileged pages via a crafted Chrome Extension.
- 106767
- 106767
- RHSA-2019:0309
- RHSA-2019:0309
- https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.html
- https://crbug.com/918470
- https://crbug.com/918470
- FEDORA-2019-05a780936d
- FEDORA-2019-05a780936d
- FEDORA-2019-561eae4626
- FEDORA-2019-561eae4626
- DSA-4395
- DSA-4395
Modified: 2024-11-21
CVE-2019-5779
Insufficient policy validation in ServiceWorker in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
- 106767
- 106767
- RHSA-2019:0309
- RHSA-2019:0309
- https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.html
- https://crbug.com/904219
- https://crbug.com/904219
- FEDORA-2019-05a780936d
- FEDORA-2019-05a780936d
- FEDORA-2019-561eae4626
- FEDORA-2019-561eae4626
- DSA-4395
- DSA-4395
Modified: 2024-11-21
CVE-2019-5780
Insufficient restrictions on what can be done with Apple Events in Google Chrome on macOS prior to 72.0.3626.81 allowed a local attacker to execute JavaScript via Apple Events.
- 106767
- 106767
- RHSA-2019:0309
- RHSA-2019:0309
- https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.html
- https://crbug.com/891697
- https://crbug.com/891697
- FEDORA-2019-05a780936d
- FEDORA-2019-05a780936d
- FEDORA-2019-561eae4626
- FEDORA-2019-561eae4626
- DSA-4395
- DSA-4395
Modified: 2024-11-21
CVE-2019-5781
Incorrect handling of a confusable character in Omnibox in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.
- 106767
- 106767
- RHSA-2019:0309
- RHSA-2019:0309
- https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.html
- https://crbug.com/896725
- https://crbug.com/896725
- FEDORA-2019-05a780936d
- FEDORA-2019-05a780936d
- FEDORA-2019-561eae4626
- FEDORA-2019-561eae4626
- DSA-4395
- DSA-4395
Modified: 2024-11-21
CVE-2019-5782
Incorrect optimization assumptions in V8 in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
- 106767
- 106767
- RHSA-2019:0309
- RHSA-2019:0309
- https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.html
- https://crbug.com/906043
- https://crbug.com/906043
- FEDORA-2019-05a780936d
- FEDORA-2019-05a780936d
- FEDORA-2019-561eae4626
- FEDORA-2019-561eae4626
- DSA-4395
- DSA-4395
Modified: 2024-11-21
CVE-2019-5783
Missing URI encoding of untrusted input in DevTools in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to perform a Dangling Markup Injection attack via a crafted HTML page.
Modified: 2024-11-21
CVE-2019-5785
Incorrect convexity calculations in Skia in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page.
Closed bugs
Closed bugs
qgis FTBFS