CVE-2019-13719 – chromium-browser: Notification obscured
https://notcve.org/view.php?id=CVE-2019-13719
07 Nov 2019 — Incorrect security UI in full screen mode in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to hide security UI via a crafted HTML page. Una interfaz de usuario de seguridad incorrecta en full screen mode en Google Chrome versiones anteriores a 78.0.3904.70, permitió a un atacante remoto ocultar la Interfaz de Usuario de seguridad por medio de una página HTML diseñada. Chromium is an open-source web browser, powered by WebKit. This update upgrades Chromium to version 78.0.3904.70. Issues addr... • http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00008.html • CWE-922: Insecure Storage of Sensitive Information •
CVE-2019-13720 – Google Chrome WebAudio Use-After-Free Vulnerability
https://notcve.org/view.php?id=CVE-2019-13720
07 Nov 2019 — Use after free in WebAudio in Google Chrome prior to 78.0.3904.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Un uso de la memoria previamente liberada en WebAudio en Google Chrome versiones anteriores a 78.0.3904.87, permitió a un atacante remoto explotar potencialmente una corrupción de la pila por medio de una página HTML diseñada. Chromium is an open-source web browser, powered by WebKit. This update upgrades Chromium to version 78.0.3904.87. Issues addresse... • https://packetstorm.news/files/id/167066 • CWE-416: Use After Free •
CVE-2019-13721 – chromium-browser: use-after-free in PDFium
https://notcve.org/view.php?id=CVE-2019-13721
07 Nov 2019 — Use after free in PDFium in Google Chrome prior to 78.0.3904.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Un uso de la memoria previamente liberada en PDFium en Google Chrome versiones anteriores a 78.0.3904.87, permitió a un atacante remoto explotar potencialmente una corrupción de la pila por medio de una página HTML diseñada. Multiple vulnerabilities have been found in Chromium and Google Chrome, the worst of which could result in the arbitrary execution of... • http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00022.html • CWE-416: Use After Free CWE-787: Out-of-bounds Write •
CVE-2019-13665 – chromium-browser: Multiple file download protection bypass
https://notcve.org/view.php?id=CVE-2019-13665
29 Oct 2019 — Insufficient filtering in Blink in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to bypass multiple file download protection via a crafted HTML page. Un filtrado insuficiente en Blink en Google Chrome versiones anteriores a 77.0.3865.75, permitió a un atacante remoto omitir la protección de descarga de múltiples archivos por medio de una página HTML diseñada. Chromium is an open-source web browser, powered by WebKit. This update upgrades Chromium to version 77.0.3865.120. Issues addressed in... • https://chromereleases.googleblog.com/2019/09/stable-channel-update-for-desktop.html • CWE-732: Incorrect Permission Assignment for Critical Resource •
CVE-2019-13666 – chromium-browser: Side channel using storage size estimate
https://notcve.org/view.php?id=CVE-2019-13666
29 Oct 2019 — Information leak in storage in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to leak cross-origin data via a crafted HTML page. Una fuga de información en storage en Google Chrome versiones anteriores a 77.0.3865.75, permitió a un atacante remoto filtrar datos de origen cruzado por medio de una página HTML diseñada. Chromium is an open-source web browser, powered by WebKit. This update upgrades Chromium to version 77.0.3865.120. Issues addressed include bypass, cross site request forgery, fi... • https://chromereleases.googleblog.com/2019/09/stable-channel-update-for-desktop.html • CWE-203: Observable Discrepancy •
CVE-2019-13667 – chromium-browser: URI bar spoof when using external app URIs
https://notcve.org/view.php?id=CVE-2019-13667
29 Oct 2019 — Inappropriate implementation in Omnibox in Google Chrome on iOS prior to 77.0.3865.75 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. Una implementación inapropiada en Omnibox en Google Chrome en iOS versiones anteriores a 77.0.3865.75, permitió a un atacante remoto falsificar el contenido del Omnibox (barra de URL) por medio de una página HTML diseñada. Chromium is an open-source web browser, powered by WebKit. This update upgrades Chromium to version 77.0.... • https://chromereleases.googleblog.com/2019/09/stable-channel-update-for-desktop.html •
CVE-2019-13668 – chromium-browser: Global window leak via console
https://notcve.org/view.php?id=CVE-2019-13668
29 Oct 2019 — Insufficient policy enforcement in developer tools in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to leak cross-origin data via a crafted HTML page. Una aplicación de política insuficiente en developer tools en Google Chrome versiones anteriores a 77.0.3865.75, permitió a un atacante remoto filtrar datos de origen cruzado por medio de una página HTML diseñada. Chromium is an open-source web browser, powered by WebKit. This update upgrades Chromium to version 77.0.3865.120. Issues addressed... • https://chromereleases.googleblog.com/2019/09/stable-channel-update-for-desktop.html • CWE-281: Improper Preservation of Permissions •
CVE-2019-13669 – chromium-browser: HTTP authentication spoof
https://notcve.org/view.php?id=CVE-2019-13669
29 Oct 2019 — Incorrect data validation in navigation in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. Una comprobación de datos incorrecta en navigation en Google Chrome versiones anteriores a 77.0.3865.75, permitió a un atacante remoto falsificar el contenido del Omnibox (barra de URL) por medio de una página HTML diseñada. Chromium is an open-source web browser, powered by WebKit. This update upgrades Chromium to version 77.0.3865.... • https://chromereleases.googleblog.com/2019/09/stable-channel-update-for-desktop.html •
CVE-2019-13670 – chromium-browser: V8 memory corruption in regex
https://notcve.org/view.php?id=CVE-2019-13670
29 Oct 2019 — Insufficient data validation in JavaScript in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Una comprobación de datos insuficiente en JavaScript en Google Chrome versiones anteriores a 77.0.3865.75, permitió a un atacante remoto explotar potencialmente una corrupción de la pila por medio de una página HTML diseñada. Chromium is an open-source web browser, powered by WebKit. This update upgrades Chromium to version 77.0.3865.120.... • https://chromereleases.googleblog.com/2019/09/stable-channel-update-for-desktop.html • CWE-787: Out-of-bounds Write •
CVE-2019-13671 – chromium-browser: Dialog box fails to show origin
https://notcve.org/view.php?id=CVE-2019-13671
29 Oct 2019 — UI spoofing in Blink in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to spoof security UI via a crafted HTML page. Una suplantación de la Interfaz de Usuario en Blink en Google Chrome versiones anteriores a 77.0.3865.75, permitió a un atacante remoto suplantar la Interfaz de Usuario de seguridad por medio de una página HTML diseñada. Chromium is an open-source web browser, powered by WebKit. This update upgrades Chromium to version 77.0.3865.120. Issues addressed include bypass, cross site ... • https://chromereleases.googleblog.com/2019/09/stable-channel-update-for-desktop.html •