CVE-2019-0774
published 2019-04-09CVE-2019-0774: An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information…
PriorityP333medium6.5CVSS 3.0
AVNACLPRNUIRSUCHINAN
EPSS
6.99%
93.5th percentile
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0614.
Affected
48 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_server | — | — |
| microsoft | windows_server | — | — |
| microsoft | windows_server | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_msrc4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Windows GDI Information Disclosure Vulnerability
vendor_msrc·2019-03-12·CVSS 4.7
CVE-2019-0774 [MEDIUM] Windows GDI Information Disclosure Vulnerability
Windows GDI Information Disclosure Vulnerability
Description: An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.
There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user to visit an untrusted webpage.
The security update addresses the vulnerability by correcting how the Windows GDI component handles objects in memory.
FAQ: What type of information could be disclosed by this vulnerability?
The type of information that could be disclosed if an attacker successfully exploited this vulnerability
GHSA
GHSA-m36c-vhpq-pppr: An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Inform
ghsa_unreviewed·2022-05-13·CVSS 6.5
CVE-2019-0774 [MEDIUM] GHSA-m36c-vhpq-pppr: An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Inform
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0614.
GHSA
GHSA-5h35-x5pv-99jf: An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Inform
ghsa_unreviewed·2022-05-13·CVSS 6.5
CVE-2019-0614 [MEDIUM] GHSA-5h35-x5pv-99jf: An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Inform
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0774.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-2602 OpenJDK: Slow conversion of BigDecimal to long (Libraries, 8211936)
bugzilla·2019-04-16·CVSS 7.5
CVE-2019-2602 [HIGH] CVE-2019-2602 OpenJDK: Slow conversion of BigDecimal to long (Libraries, 8211936)
CVE-2019-2602 OpenJDK: Slow conversion of BigDecimal to long (Libraries, 8211936)
A flaw was found in the BigDecimal implementation in the Libraries component of OpenJDK. An untrusted numeric value parsed by a Java application could the application to use an excessive amount of CPU time.
Discussion:
Public now via Oracle CPU April 2019:
https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html#AppendixJAVA
Fixed in Oracle Java 12.0.1, 11.0.3, 8u211, and 7u221.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2019:0774 https://access.redhat.com/errata/RHSA-2019:0774
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2019:0775 https://access.redhat.com/errata/RHSA-201
Bugzilla
CVE-2019-2698 OpenJDK: Font layout engine out of bounds access setCurrGlyphID() (2D, 8219022)
bugzilla·2019-04-16·CVSS 8.1
CVE-2019-2698 [HIGH] CVE-2019-2698 OpenJDK: Font layout engine out of bounds access setCurrGlyphID() (2D, 8219022)
CVE-2019-2698 OpenJDK: Font layout engine out of bounds access setCurrGlyphID() (2D, 8219022)
A out of bounds access flaw was found in the font layout engine in the 2D component of OpenJDK. Missing validation of the position value in GlyphIterator::setCurrGlyphID could lead to memory corruption, triggered by a specially crafted font file. An untrusted Java application or applet could possibly use this flaw to bypass Java sandbox restrictions.
Discussion:
Public now via Oracle CPU April 2019:
https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html#AppendixJAVA
Fixed in Oracle Java 8u211 and 7u221.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2019:0774 https://access.redhat.com/errata/RHSA-2019:0774
---
This
Bugzilla
CVE-2019-7125 Adobe Reader: Out-of-bounds memory access due to incorrect integer size promotion leads to arbitrary code execution
bugzilla·2019-04-10·CVSS 8.8
CVE-2019-7125 [HIGH] CVE-2019-7125 Adobe Reader: Out-of-bounds memory access due to incorrect integer size promotion leads to arbitrary code execution
CVE-2019-7125 Adobe Reader: Out-of-bounds memory access due to incorrect integer size promotion leads to arbitrary code execution
A specific JavaScript code embedded in a PDF file can lead to a heap corruption when opening a PDF document in Adobe Acrobat Reader DC 2019.8.20071. With careful memory manipulation, this can lead to arbitrary code execution. In order to trigger this vulnerability, the victim would need to open the malicious file or access a malicious web page.
External Reference:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-7125
https://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0774
Discussion:
Closed NOTABUG.
2019-04-09
Published