CVE-2019-13765
published 2020-01-03CVE-2019-13765: Use-after-free in content delivery manager in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to potentially exploit heap corruption via a…
PriorityP428medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
0.72%
49.6th percentile
Use-after-free in content delivery manager in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chromium | chromium | >= 0 < 78.0.3904.87-1 | 78.0.3904.87-1 |
| chromium | chromium | >= 0 < 78.0.3904.87-1 | 78.0.3904.87-1 |
| chromium | chromium | >= 0 < 78.0.3904.87-1 | 78.0.3904.87-1 |
| chromium | chromium | >= 0 < 78.0.3904.87-1 | 78.0.3904.87-1 |
| debian | chromium | < chromium 78.0.3904.87-1 (bookworm) | chromium 78.0.3904.87-1 (bookworm) |
| chrome | < 78.0.3904.70 | 78.0.3904.70 | |
| chrome | >= unspecified < 78.0.3904.70 | 78.0.3904.70 | |
| chrome_chrome | — | — | |
| qemu | qemu | >= 0 < 1:4.2-3ubuntu6.30 | 1:4.2-3ubuntu6.30 |
| qemu | qemu | >= 0 < 1:6.2+dfsg-2ubuntu6.24 | 1:6.2+dfsg-2ubuntu6.24 |
| qemu | qemu | >= 0 < 1:8.2.2+ds-0ubuntu1.4 | 1:8.2.2+ds-0ubuntu1.4 |
| qemu | qemu | >= 0 < 2.0.0+dfsg-2ubuntu1.47+esm4 | 2.0.0+dfsg-2ubuntu1.47+esm4 |
| qemu | qemu | >= 0 < 1:2.5+dfsg-5ubuntu10.51+esm3 | 1:2.5+dfsg-5ubuntu10.51+esm3 |
| qemu | qemu | >= 0 < 1:2.11+dfsg-1ubuntu7.42+esm2 | 1:2.11+dfsg-1ubuntu7.42+esm2 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Chrome
Stable Channel Update for Desktop: CVE-2019-13701
vendor_chrome·2019-10-22·CVSS 4.3
CVE-2019-13701 [HIGH] Stable Channel Update for Desktop: CVE-2019-13701
Stable Channel Update for Desktop
CVE-2019-13701: URL spoof in navigation. Reported by David Erceg on 2019-08-27
[$5000][ 1007194 ] High CVE-2019-13765: Use-after-free in content delivery manager
Reported by Guang Gong of Alpha Team, Qihoo 360 on 2019-09-24
Severity: high
Debian
CVE-2019-13765: chromium - Use-after-free in content delivery manager in Google Chrome prior to 78.0.3904.7...
vendor_debian·2019·CVSS 6.5
CVE-2019-13765 [MEDIUM] CVE-2019-13765: chromium - Use-after-free in content delivery manager in Google Chrome prior to 78.0.3904.7...
Use-after-free in content delivery manager in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 78.0.3904.87-1)
bullseye: resolved (fixed in 78.0.3904.87-1)
forky: resolved (fixed in 78.0.3904.87-1)
sid: resolved (fixed in 78.0.3904.87-1)
trixie: resolved (fixed in 78.0.3904.87-1)
OSV
qemu vulnerabilities
osv·2024-11-08·CVSS 3.5
CVE-2019-20382 qemu vulnerabilities
qemu vulnerabilities
It was discovered that QEMU incorrectly handled memory during certain VNC
operations. A remote attacker could possibly use this issue to cause QEMU
to consume resources, resulting in a denial of service. This issue only
affected Ubuntu 14.04 LTS. (CVE-2019-20382)
It was discovered that QEMU incorrectly handled certain memory copy
operations when loading ROM contents. If a user were tricked into running
an untrusted kernel image, a remote attacker could possibly use this issue
to run arbitrary code. This issue only affected Ubuntu 14.04 LTS.
(CVE-2020-13765)
Aviv Sasson discovered that QEMU incorrectly handled Slirp networking. A
remote attacker could use this issue to cause QEMU to crash, resulting in a
denial of service, or possibly execute arbitrary code. This iss
GHSA
GHSA-9fcr-543v-f4c7: Use-after-free in content delivery manager in Google Chrome prior to 78
ghsa_unreviewed·2022-05-24
CVE-2019-13765 [MEDIUM] GHSA-9fcr-543v-f4c7: Use-after-free in content delivery manager in Google Chrome prior to 78
Use-after-free in content delivery manager in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
OSV
CVE-2019-13765: Use-after-free in content delivery manager in Google Chrome prior to 78
osv·2020-01-03·CVSS 6.5
CVE-2019-13765 [MEDIUM] CVE-2019-13765: Use-after-free in content delivery manager in Google Chrome prior to 78
Use-after-free in content delivery manager in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-01-03
Published