CVE-2019-13700Out-of-bounds Write in Google Chrome

CWE-787Out-of-bounds Write10 documents8 sources
Severity
8.8HIGHNVD
EPSS
0.7%
top 29.12%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 25
Latest updateMay 24

Description

Out of bounds memory access in the gamepad API in Google Chrome prior to 78.0.3904.70 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages4 packages

CVEListV5google/chromeunspecified78.0.3904.70
NVDgoogle/chrome< 78.0.3904.70
Debianchromium/chromium< 78.0.3904.87-1+3

🔴Vulnerability Details

3
GHSA
GHSA-29g2-j2qf-h8qw: Out of bounds memory access in the gamepad API in Google Chrome prior to 782022-05-24
OSV
CVE-2019-13700: Out of bounds memory access in the gamepad API in Google Chrome prior to 782019-11-25
CVEList
CVE-2019-13700: Out of bounds memory access in the gamepad API in Google Chrome prior to 782019-11-25

📋Vendor Advisories

3
Red Hat
chromium-browser: Buffer overrun in Blink2019-10-22
Chrome
Stable Channel Update for Desktop: CVE-2019-136992019-10-22
Debian
CVE-2019-13700: chromium - Out of bounds memory access in the gamepad API in Google Chrome prior to 78.0.39...2019

💬Community

3
Bugzilla
CVE-2019-13699 CVE-2019-13700 CVE-2019-13701 CVE-2019-13702 CVE-2019-13703 CVE-2019-13704 CVE-2019-13705 CVE-2019-13706 CVE-2019-13707 CVE-2019-13708 CVE-2019-13709 CVE-2019-13710 CVE-2019-13711 CVE-22019-10-23
Bugzilla
CVE-2019-13699 CVE-2019-13700 CVE-2019-13701 CVE-2019-13702 CVE-2019-13703 CVE-2019-13704 CVE-2019-13705 CVE-2019-13706 CVE-2019-13707 CVE-2019-13708 CVE-2019-13709 CVE-2019-13710 CVE-2019-13711 CVE-22019-10-23
Bugzilla
CVE-2019-13700 chromium-browser: Buffer overrun in Blink2019-10-23
CVE-2019-13700 — Out-of-bounds Write in Google Chrome | cvebase