CVE-2019-3770
published 2020-03-13CVE-2019-3770: Dell Wyse Management Suite versions prior to 1.4.1 contain a stored cross-site scripting vulnerability when unregistering a device. A remote authenticated…
PriorityP431medium6.4CVSS 3.1
AVNACLPRLUINSCCLILAN
EPSS
0.67%
47.7th percentile
Dell Wyse Management Suite versions prior to 1.4.1 contain a stored cross-site scripting vulnerability when unregistering a device. A remote authenticated malicious user with low privileges could exploit this vulnerability to store malicious HTML or JavaScript code. When victim users access the submitted data through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable application.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| dell | wyse_management_suite | < 1.4.1 | 1.4.1 |
| dell | wyse_management_suite | >= unspecified < WMS 1.4.1 | WMS 1.4.1 |
CVSS provenance
nvdv3.16.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
nvdv3.06.4MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hpwv-4p77-xcc5: Dell Wyse Management Suite versions prior to 1
ghsa_unreviewed·2022-05-24
CVE-2019-3770 [LOW] GHSA-hpwv-4p77-xcc5: Dell Wyse Management Suite versions prior to 1
Dell Wyse Management Suite versions prior to 1.4.1 contain a stored cross-site scripting vulnerability when unregistering a device. A remote authenticated malicious user with low privileges could exploit this vulnerability to store malicious HTML or JavaScript code. When victim users access the submitted data through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable application.
Red Hat
Mozilla: Out-of-bounds read in Skia
vendor_redhat·2019-09-03·CVSS 8.1
CVE-2019-5849 [HIGH] CWE-125 Mozilla: Out-of-bounds read in Skia
Mozilla: Out-of-bounds read in Skia
Out of bounds read in Skia in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
Package: firefox (Red Hat Enterprise Linux 5) - Out of support scope
Package: firefox (Red Hat Enterprise Linux 6) - Will not fix
Package: firefox (Red Hat Enterprise Linux 7) - Will not fix
Package: firefox (Red Hat Enterprise Linux 8) - Will not fix
Red Hat
chromium-browser: V8 sealed/frozen elements cause crash
vendor_redhat·2019-07-15·CVSS 6.5
CVE-2019-5847 [MEDIUM] chromium-browser: V8 sealed/frozen elements cause crash
chromium-browser: V8 sealed/frozen elements cause crash
Inappropriate implementation in JavaScript in Google Chrome prior to 75.0.3770.142 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Red Hat
chromium-browser: Font sizes may expose sensitive information
vendor_redhat·2019-07-15·CVSS 6.5
CVE-2019-5848 [MEDIUM] chromium-browser: Font sizes may expose sensitive information
chromium-browser: Font sizes may expose sensitive information
Incorrect font handling in autofill in Google Chrome prior to 75.0.3770.142 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
Red Hat
chromium-browser: Use-after-free in Blink
vendor_redhat·2019-06-13·CVSS 6.5
CVE-2019-5842 [MEDIUM] chromium-browser: Use-after-free in Blink
chromium-browser: Use-after-free in Blink
Use after free in Blink in Google Chrome prior to 75.0.3770.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Red Hat
chromium-browser: Use after free in Download Manager
vendor_redhat·2019-06-04·CVSS 8.8
CVE-2019-5829 [HIGH] chromium-browser: Use after free in Download Manager
chromium-browser: Use after free in Download Manager
Integer overflow in download manager in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
Red Hat
chromium-browser: Popup blocker bypass
vendor_redhat·2019-06-04·CVSS 4.3
CVE-2019-5840 [MEDIUM] chromium-browser: Popup blocker bypass
chromium-browser: Popup blocker bypass
Incorrect security UI in popup blocker in Google Chrome on iOS prior to 75.0.3770.80 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
Red Hat
chromium-browser: Out of bounds read in Swiftshader
vendor_redhat·2019-06-04·CVSS 6.5
CVE-2019-5835 [MEDIUM] chromium-browser: Out of bounds read in Swiftshader
chromium-browser: Out of bounds read in Swiftshader
Object lifecycle issue in SwiftShader in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
Red Hat
chromium-browser: Incorrectly credentialed requests in CORS
vendor_redhat·2019-06-04·CVSS 6.5
CVE-2019-5830 [MEDIUM] chromium-browser: Incorrectly credentialed requests in CORS
chromium-browser: Incorrectly credentialed requests in CORS
Insufficient policy enforcement in CORS in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Red Hat
chromium-browser: Incorrect handling of certain code points in Blink
vendor_redhat·2019-06-04·CVSS 4.3
CVE-2019-5839 [MEDIUM] chromium-browser: Incorrect handling of certain code points in Blink
chromium-browser: Incorrect handling of certain code points in Blink
Excessive data validation in URL parser in Google Chrome prior to 75.0.3770.80 allowed a remote attacker who convinced a user to input a URL to bypass website URL validation via a crafted URL.
Red Hat
chromium-browser: Cross-origin resources size disclosure in Appcache
vendor_redhat·2019-06-04·CVSS 6.5
CVE-2019-5837 [MEDIUM] chromium-browser: Cross-origin resources size disclosure in Appcache
chromium-browser: Cross-origin resources size disclosure in Appcache
Resource size information leakage in Blink in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Red Hat
chromium-browser: Heap buffer overflow in Angle
vendor_redhat·2019-06-04·CVSS 8.8
CVE-2019-5836 [HIGH] chromium-browser: Heap buffer overflow in Angle
chromium-browser: Heap buffer overflow in Angle
Heap buffer overflow in ANGLE in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Red Hat
chromium-browser: Incorrect CORS handling in XHR
vendor_redhat·2019-06-04·CVSS 6.5
CVE-2019-5832 [MEDIUM] chromium-browser: Incorrect CORS handling in XHR
chromium-browser: Incorrect CORS handling in XHR
Insufficient policy enforcement in XMLHttpRequest in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Red Hat
chromium-browser: Overly permissive tab access in Extensions
vendor_redhat·2019-06-04·CVSS 4.3
CVE-2019-5838 [MEDIUM] chromium-browser: Overly permissive tab access in Extensions
chromium-browser: Overly permissive tab access in Extensions
Insufficient policy enforcement in extensions API in Google Chrome prior to 75.0.3770.80 allowed an attacker who convinced a user to install a malicious extension to bypass restrictions on file URIs via a crafted Chrome Extension.
Red Hat
chromium-browser: Use after free in ServiceWorker
vendor_redhat·2019-06-04·CVSS 8.8
CVE-2019-5828 [HIGH] chromium-browser: Use after free in ServiceWorker
chromium-browser: Use after free in ServiceWorker
Object lifecycle issue in ServiceWorker in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
Red Hat
chromium-browser: Inconsistent security UI placement
vendor_redhat·2019-06-04·CVSS 4.3
CVE-2019-5833 [MEDIUM] chromium-browser: Inconsistent security UI placement
chromium-browser: Inconsistent security UI placement
Incorrect dialog box scoping in browser in Google Chrome on Android prior to 75.0.3770.80 allowed a remote attacker to display misleading security UI via a crafted HTML page.
Red Hat
chromium-browser: URL spoof in Omnibox on iOS
vendor_redhat·2019-06-04·CVSS 6.5
CVE-2019-5834 [MEDIUM] chromium-browser: URL spoof in Omnibox on iOS
chromium-browser: URL spoof in Omnibox on iOS
Insufficient data validation in Blink in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
Package: chromium-browser (Red Hat Enterprise Linux 6) - Not affected
Red Hat
chromium-browser: Incorrect map processing in V8
vendor_redhat·2019-06-04·CVSS 8.8
CVE-2019-5831 [HIGH] chromium-browser: Incorrect map processing in V8
chromium-browser: Incorrect map processing in V8
Object lifecycle issue in V8 in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-03-13
Published