6.5
CVE-2019-13750
- EPSS 2.21%
- Veröffentlicht 10.12.2019 22:15:14
- Zuletzt bearbeitet 21.11.2024 04:25:38
- Erkennungen
Insufficient data validation in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to bypass defense-in-depth measures via a crafted HTML page.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Debian ≫ Debian Linux Version 9.0
Debian ≫ Debian Linux Version 10.0
Fedoraproject ≫ Fedora Version 30
Fedoraproject ≫ Fedora Version 31
Redhat ≫ Enterprise Linux Desktop Version 6.0 HwPlatform x64
Redhat ≫ Enterprise Linux Desktop Version 6.0 HwPlatform x86
Redhat ≫ Enterprise Linux For Scientific Computing Version 6.0 HwPlatform x64
Redhat ≫ Enterprise Linux For Scientific Computing Version 6.0 HwPlatform x86
Redhat ≫ Enterprise Linux Server Version 6.0 HwPlatform x64
Redhat ≫ Enterprise Linux Server Version 6.0 HwPlatform x86
Redhat ≫ Enterprise Linux Workstation Version 6.0 HwPlatform x64
Redhat ≫ Enterprise Linux Workstation Version 6.0 HwPlatform x86
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 19.10
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.21% | 0.803 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
|
| NIST | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:P/I:N/A:N
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
https://security.gentoo.org/glsa/202003-08
http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00032.html
http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00036.html
https://access.redhat.com/errata/RHSA-2019:4238
https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2Z5M4FPUMDNX2LDPHJKN5ZV5GIS2AKNU/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N5CIQCVS6E3ULJCNU7YJXJPO2BLQZDTK/
https://seclists.org/bugtraq/2020/Jan/27
https://www.debian.org/security/2020/dsa-4606
https://usn.ubuntu.com/4298-1/
https://usn.ubuntu.com/4298-2/
https://crbug.com/1025464