8.8
CVE-2019-13726
- EPSS 2.19%
- Veröffentlicht 10.12.2019 22:15:12
- Zuletzt bearbeitet 21.11.2024 04:25:35
- Erkennungen
Buffer overflow in password manager in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to execute arbitrary code via a crafted HTML page.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Debian ≫ Debian Linux Version 9.0
Debian ≫ Debian Linux Version 10.0
Fedoraproject ≫ Fedora Version 30
Fedoraproject ≫ Fedora Version 31
Redhat ≫ Enterprise Linux Desktop Version 6.0 HwPlatform x64
Redhat ≫ Enterprise Linux Desktop Version 6.0 HwPlatform x86
Redhat ≫ Enterprise Linux For Scientific Computing Version 6.0 HwPlatform x64
Redhat ≫ Enterprise Linux For Scientific Computing Version 6.0 HwPlatform x86
Redhat ≫ Enterprise Linux Server Version 6.0 HwPlatform x64
Redhat ≫ Enterprise Linux Server Version 6.0 HwPlatform x86
Redhat ≫ Enterprise Linux Workstation Version 6.0 HwPlatform x64
Redhat ≫ Enterprise Linux Workstation Version 6.0 HwPlatform x86
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.19% | 0.801 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
| NIST | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
https://security.gentoo.org/glsa/202003-08
http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00032.html
http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00036.html
https://access.redhat.com/errata/RHSA-2019:4238
https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2Z5M4FPUMDNX2LDPHJKN5ZV5GIS2AKNU/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N5CIQCVS6E3ULJCNU7YJXJPO2BLQZDTK/
https://seclists.org/bugtraq/2020/Jan/27
https://www.debian.org/security/2020/dsa-4606
https://crbug.com/1027152