CVE-2019-4238
published 2019-04-25CVE-2019-4238: IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript…
PriorityP425medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
0.67%
47.8th percentile
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 159464.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | infosphere_information_server | — | — |
| ibm | infosphere_information_server | — | — |
| ibm | infosphere_information_server | — | — |
| ibm | infosphere_information_server_on_cloud | — | — |
| ibm | infosphere_information_server_on_cloud | — | — |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv3.05.4MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-13734 sqlite: fts3: improve shadow table corruption detection
bugzilla·2019-12-11·CVSS 8.8
CVE-2019-13734 [HIGH] CVE-2019-13734 sqlite: fts3: improve shadow table corruption detection
CVE-2019-13734 sqlite: fts3: improve shadow table corruption detection
An out of bounds write flaw was found in the SQLite component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1025466
External References:
https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1782013]
Affects: fedora-all [bug 1782012]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2019:4238 https://access.redhat.com/errata/RHSA-2019:4238
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-201
Bugzilla
CVE-2019-13751 sqlite: fts3: improve detection of corrupted records
bugzilla·2019-12-11·CVSS 6.5
CVE-2019-13751 [MEDIUM] CVE-2019-13751 sqlite: fts3: improve detection of corrupted records
CVE-2019-13751 sqlite: fts3: improve detection of corrupted records
An uninitialized use flaw was found in the SQLite component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1025465
External References:
https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1782013]
Affects: fedora-all [bug 1782012]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2019:4238 https://access.redhat.com/errata/RHSA-2019:4238
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-137
Bugzilla
CVE-2019-13742 chromium-browser: Incorrect security UI in Omnibox
bugzilla·2019-12-11·CVSS 6.5
CVE-2019-13742 [MEDIUM] CVE-2019-13742 chromium-browser: Incorrect security UI in Omnibox
CVE-2019-13742 chromium-browser: Incorrect security UI in Omnibox
An incorrect security ui flaw was found in the Omnibox component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=101756
External References:
https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1782013]
Affects: fedora-all [bug 1782012]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2019:4238 https://access.redhat.com/errata/RHSA-2019:4238
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-1
Bugzilla
CVE-2019-13764 chromium-browser: Type Confusion in V8
bugzilla·2019-12-11·CVSS 8.8
CVE-2019-13764 [HIGH] CVE-2019-13764 chromium-browser: Type Confusion in V8
CVE-2019-13764 chromium-browser: Type Confusion in V8
A type confusion flaw was found in the V8 component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=102886
External References:
https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2019:4238 https://access.redhat.com/errata/RHSA-2019:4238
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-13764
Bugzilla
CVE-2019-13726 chromium-browser: Heap buffer overflow in password manager
bugzilla·2019-12-11·CVSS 8.8
CVE-2019-13726 [HIGH] CVE-2019-13726 chromium-browser: Heap buffer overflow in password manager
CVE-2019-13726 chromium-browser: Heap buffer overflow in password manager
A heap buffer overflow flaw was found in the password manager component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=102715
External References:
https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1782013]
Affects: fedora-all [bug 1782012]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2019:4238 https://access.redhat.com/errata/RHSA-2019:4238
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security
Bugzilla
CVE-2019-13740 chromium-browser: Incorrect security UI in sharing
bugzilla·2019-12-11·CVSS 6.5
CVE-2019-13740 [MEDIUM] CVE-2019-13740 chromium-browser: Incorrect security UI in sharing
CVE-2019-13740 chromium-browser: Incorrect security UI in sharing
An incorrect security ui flaw was found in the sharing component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=100559
External References:
https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1782013]
Affects: fedora-all [bug 1782012]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2019:4238 https://access.redhat.com/errata/RHSA-2019:4238
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-1
Bugzilla
CVE-2019-13745 chromium-browser: Insufficient policy enforcement in audio
bugzilla·2019-12-11·CVSS 6.5
CVE-2019-13745 [MEDIUM] CVE-2019-13745 chromium-browser: Insufficient policy enforcement in audio
CVE-2019-13745 chromium-browser: Insufficient policy enforcement in audio
An insufficient policy enforcement flaw was found in the audio component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=990867
External References:
https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1782013]
Affects: fedora-all [bug 1782012]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2019:4238 https://access.redhat.com/errata/RHSA-2019:4238
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/securit
Bugzilla
CVE-2019-13739 chromium-browser: Incorrect security UI in Omnibox
bugzilla·2019-12-11·CVSS 6.5
CVE-2019-13739 [MEDIUM] CVE-2019-13739 chromium-browser: Incorrect security UI in Omnibox
CVE-2019-13739 chromium-browser: Incorrect security UI in Omnibox
An incorrect security ui flaw was found in the Omnibox component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=824715
External References:
https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1782013]
Affects: fedora-all [bug 1782012]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2019:4238 https://access.redhat.com/errata/RHSA-2019:4238
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-1
Bugzilla
CVE-2019-13750 sqlite: dropping of shadow tables not restricted in defensive mode
bugzilla·2019-12-11·CVSS 6.5
CVE-2019-13750 [MEDIUM] CVE-2019-13750 sqlite: dropping of shadow tables not restricted in defensive mode
CVE-2019-13750 sqlite: dropping of shadow tables not restricted in defensive mode
An insufficient data validation flaw was found in the SQLite component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1025464
External References:
https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1782013]
Affects: fedora-all [bug 1782012]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2019:4238 https://access.redhat.com/errata/RHSA-2019:4238
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/
Bugzilla
CVE-2019-13746 chromium-browser: Insufficient policy enforcement in Omnibox
bugzilla·2019-12-11·CVSS 6.5
CVE-2019-13746 [MEDIUM] CVE-2019-13746 chromium-browser: Insufficient policy enforcement in Omnibox
CVE-2019-13746 chromium-browser: Insufficient policy enforcement in Omnibox
An insufficient policy enforcement flaw was found in the Omnibox component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=999932
External References:
https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1782013]
Affects: fedora-all [bug 1782012]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2019:4238 https://access.redhat.com/errata/RHSA-2019:4238
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/sec
Bugzilla
CVE-2019-13738 chromium-browser: Insufficient policy enforcement in navigation
bugzilla·2019-12-11·CVSS 6.5
CVE-2019-13738 [MEDIUM] CVE-2019-13738 chromium-browser: Insufficient policy enforcement in navigation
CVE-2019-13738 chromium-browser: Insufficient policy enforcement in navigation
An insufficient policy enforcement flaw was found in the navigation component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=101744
External References:
https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1782013]
Affects: fedora-all [bug 1782012]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2019:4238 https://access.redhat.com/errata/RHSA-2019:4238
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.c
Bugzilla
CVE-2019-13758 chromium-browser: Insufficient policy enforcement in navigation
bugzilla·2019-12-11·CVSS 4.3
CVE-2019-13758 [MEDIUM] CVE-2019-13758 chromium-browser: Insufficient policy enforcement in navigation
CVE-2019-13758 chromium-browser: Insufficient policy enforcement in navigation
An insufficient policy enforcement flaw was found in the navigation component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=979442
External References:
https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1782019]
Affects: fedora-all [bug 1782018]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2019:4238 https://access.redhat.com/errata/RHSA-2019:4238
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.c
Bugzilla
CVE-2019-13737 chromium-browser: Insufficient policy enforcement in autocomplete
bugzilla·2019-12-11·CVSS 6.5
CVE-2019-13737 [MEDIUM] CVE-2019-13737 chromium-browser: Insufficient policy enforcement in autocomplete
CVE-2019-13737 chromium-browser: Insufficient policy enforcement in autocomplete
An insufficient policy enforcement flaw was found in the autocomplete component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=101388
External References:
https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1782013]
Affects: fedora-all [bug 1782012]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2019:4238 https://access.redhat.com/errata/RHSA-2019:4238
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redh
Bugzilla
CVE-2019-13756 chromium-browser: Incorrect security UI in printing
bugzilla·2019-12-11·CVSS 4.3
CVE-2019-13756 [MEDIUM] CVE-2019-13756 chromium-browser: Incorrect security UI in printing
CVE-2019-13756 chromium-browser: Incorrect security UI in printing
An incorrect security ui flaw was found in the printing component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=708595
External References:
https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1782013]
Affects: fedora-all [bug 1782012]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2019:4238 https://access.redhat.com/errata/RHSA-2019:4238
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019
Bugzilla
CVE-2019-13741 chromium-browser: Insufficient validation of untrusted input in Blink
bugzilla·2019-12-11·CVSS 8.8
CVE-2019-13741 [HIGH] CVE-2019-13741 chromium-browser: Insufficient validation of untrusted input in Blink
CVE-2019-13741 chromium-browser: Insufficient validation of untrusted input in Blink
An insufficient validation of untrusted input flaw was found in the Blink component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=101195
External References:
https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1782013]
Affects: fedora-all [bug 1782012]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2019:4238 https://access.redhat.com/errata/RHSA-2019:4238
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://acc
Bugzilla
CVE-2019-13754 chromium-browser: Insufficient policy enforcement in extensions
bugzilla·2019-12-11·CVSS 4.3
CVE-2019-13754 [MEDIUM] CVE-2019-13754 chromium-browser: Insufficient policy enforcement in extensions
CVE-2019-13754 chromium-browser: Insufficient policy enforcement in extensions
An insufficient policy enforcement flaw was found in the extensions component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=442579
External References:
https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1782013]
Affects: fedora-all [bug 1782012]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2019:4238 https://access.redhat.com/errata/RHSA-2019:4238
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.c
Bugzilla
CVE-2019-13749 chromium-browser: Incorrect security UI in Omnibox
bugzilla·2019-12-11·CVSS 6.5
CVE-2019-13749 [MEDIUM] CVE-2019-13749 chromium-browser: Incorrect security UI in Omnibox
CVE-2019-13749 chromium-browser: Incorrect security UI in Omnibox
An incorrect security ui flaw was found in the Omnibox component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=101076
External References:
https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1782013]
Affects: fedora-all [bug 1782012]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2019:4238 https://access.redhat.com/errata/RHSA-2019:4238
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-1
Bugzilla
CVE-2019-13759 chromium-browser: Incorrect security UI in interstitials
bugzilla·2019-12-11·CVSS 4.3
CVE-2019-13759 [MEDIUM] CVE-2019-13759 chromium-browser: Incorrect security UI in interstitials
CVE-2019-13759 chromium-browser: Incorrect security UI in interstitials
An incorrect security ui flaw was found in the interstitials component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=901789
External References:
https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2019:4238 https://access.redhat.com/errata/RHSA-2019:4238
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-13759
Bugzilla
CVE-2019-13725 chromium-browser: Use after free in Bluetooth
bugzilla·2019-12-11·CVSS 8.8
CVE-2019-13725 [HIGH] CVE-2019-13725 chromium-browser: Use after free in Bluetooth
CVE-2019-13725 chromium-browser: Use after free in Bluetooth
An use after free flaw was found in the Bluetooth component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=102506
External References:
https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1782013]
Affects: fedora-all [bug 1782012]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2019:4238 https://access.redhat.com/errata/RHSA-2019:4238
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-13725
Bugzilla
CVE-2019-13735 chromium-browser: Out of bounds write in V8
bugzilla·2019-12-11·CVSS 8.8
CVE-2019-13735 [HIGH] CVE-2019-13735 chromium-browser: Out of bounds write in V8
CVE-2019-13735 chromium-browser: Out of bounds write in V8
An out of bounds write flaw was found in the V8 component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=102546
External References:
https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1782013]
Affects: fedora-all [bug 1782012]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2019:4238 https://access.redhat.com/errata/RHSA-2019:4238
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-13735
Bugzilla
CVE-2019-13752 sqlite: fts3: improve shadow table corruption detection
bugzilla·2019-12-11·CVSS 6.5
CVE-2019-13752 [MEDIUM] CVE-2019-13752 sqlite: fts3: improve shadow table corruption detection
CVE-2019-13752 sqlite: fts3: improve shadow table corruption detection
An out of bounds read flaw was found in the SQLite component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1025470
External References:
https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1782013]
Affects: fedora-all [bug 1782012]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2019:4238 https://access.redhat.com/errata/RHSA-2019:4238
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019
Bugzilla
CVE-2019-13748 chromium-browser: Insufficient policy enforcement in developer tools
bugzilla·2019-12-11·CVSS 6.5
CVE-2019-13748 [MEDIUM] CVE-2019-13748 chromium-browser: Insufficient policy enforcement in developer tools
CVE-2019-13748 chromium-browser: Insufficient policy enforcement in developer tools
An insufficient policy enforcement flaw was found in the developer tools component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=993706
External References:
https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1782013]
Affects: fedora-all [bug 1782012]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2019:4238 https://access.redhat.com/errata/RHSA-2019:4238
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://acces
Bugzilla
CVE-2019-13743 chromium-browser: Incorrect security UI in external protocol handling
bugzilla·2019-12-11·CVSS 6.5
CVE-2019-13743 [MEDIUM] CVE-2019-13743 chromium-browser: Incorrect security UI in external protocol handling
CVE-2019-13743 chromium-browser: Incorrect security UI in external protocol handling
An incorrect security ui flaw was found in the external protocol handling component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=754304
External References:
https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1782013]
Affects: fedora-all [bug 1782012]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2019:4238 https://access.redhat.com/errata/RHSA-2019:4238
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://acc
Bugzilla
CVE-2019-13763 chromium-browser: Insufficient policy enforcement in payments
bugzilla·2019-12-11·CVSS 4.3
CVE-2019-13763 [MEDIUM] CVE-2019-13763 chromium-browser: Insufficient policy enforcement in payments
CVE-2019-13763 chromium-browser: Insufficient policy enforcement in payments
An insufficient policy enforcement flaw was found in the payments component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=101160
External References:
https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1782013]
Affects: fedora-all [bug 1782012]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2019:4238 https://access.redhat.com/errata/RHSA-2019:4238
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/s
Bugzilla
CVE-2019-13755 chromium-browser: Insufficient policy enforcement in extensions
bugzilla·2019-12-11·CVSS 4.3
CVE-2019-13755 [MEDIUM] CVE-2019-13755 chromium-browser: Insufficient policy enforcement in extensions
CVE-2019-13755 chromium-browser: Insufficient policy enforcement in extensions
An insufficient policy enforcement flaw was found in the extensions component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=696208
External References:
https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1782013]
Affects: fedora-all [bug 1782012]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2019:4238 https://access.redhat.com/errata/RHSA-2019:4238
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.c
Bugzilla
CVE-2019-13757 chromium-browser: Incorrect security UI in Omnibox
bugzilla·2019-12-11·CVSS 4.3
CVE-2019-13757 [MEDIUM] CVE-2019-13757 chromium-browser: Incorrect security UI in Omnibox
CVE-2019-13757 chromium-browser: Incorrect security UI in Omnibox
An incorrect security ui flaw was found in the Omnibox component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=884693
External References:
https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1782013]
Affects: fedora-all [bug 1782012]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2019:4238 https://access.redhat.com/errata/RHSA-2019:4238
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-1
Bugzilla
CVE-2019-13736 chromium-browser: Integer overflow in PDFium
bugzilla·2019-12-11·CVSS 8.8
CVE-2019-13736 [HIGH] CVE-2019-13736 chromium-browser: Integer overflow in PDFium
CVE-2019-13736 chromium-browser: Integer overflow in PDFium
An integer overflow flaw was found in the PDFium component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=102089
External References:
https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1782013]
Affects: fedora-all [bug 1782012]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2019:4238 https://access.redhat.com/errata/RHSA-2019:4238
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-13736
Bugzilla
CVE-2019-13761 chromium-browser: Incorrect security UI in Omnibox
bugzilla·2019-12-11·CVSS 4.3
CVE-2019-13761 [MEDIUM] CVE-2019-13761 chromium-browser: Incorrect security UI in Omnibox
CVE-2019-13761 chromium-browser: Incorrect security UI in Omnibox
An incorrect security ui flaw was found in the Omnibox component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=100268
External References:
https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1782013]
Affects: fedora-all [bug 1782012]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2019:4238 https://access.redhat.com/errata/RHSA-2019:4238
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-1
Bugzilla
CVE-2019-13732 chromium-browser: Use after free in WebAudio
bugzilla·2019-12-11·CVSS 8.8
CVE-2019-13732 [HIGH] CVE-2019-13732 chromium-browser: Use after free in WebAudio
CVE-2019-13732 chromium-browser: Use after free in WebAudio
An use after free flaw was found in the WebAudio component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=102381
External References:
https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1782013]
Affects: fedora-all [bug 1782012]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2019:4238 https://access.redhat.com/errata/RHSA-2019:4238
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-13732
Bugzilla
CVE-2019-13729 chromium-browser: Use after free in WebSockets
bugzilla·2019-12-11·CVSS 8.8
CVE-2019-13729 [HIGH] CVE-2019-13729 chromium-browser: Use after free in WebSockets
CVE-2019-13729 chromium-browser: Use after free in WebSockets
An use after free flaw was found in the WebSockets component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=102548
External References:
https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1782013]
Affects: fedora-all [bug 1782012]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2019:4238 https://access.redhat.com/errata/RHSA-2019:4238
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-13729
Bugzilla
CVE-2019-13753 sqlite: fts3: incorrectly removed corruption check
bugzilla·2019-12-11·CVSS 6.5
CVE-2019-13753 [MEDIUM] CVE-2019-13753 sqlite: fts3: incorrectly removed corruption check
CVE-2019-13753 sqlite: fts3: incorrectly removed corruption check
An out of bounds read flaw was found in the SQLite component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1025471
External References:
https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1782013]
Affects: fedora-all [bug 1782012]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2019:4238 https://access.redhat.com/errata/RHSA-2019:4238
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-1375
Bugzilla
CVE-2019-13730 chromium-browser: Type Confusion in V8
bugzilla·2019-12-11·CVSS 8.8
CVE-2019-13730 [HIGH] CVE-2019-13730 chromium-browser: Type Confusion in V8
CVE-2019-13730 chromium-browser: Type Confusion in V8
A type confusion flaw was found in the V8 component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=102886
External References:
https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1782013]
Affects: fedora-all [bug 1782012]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2019:4238 https://access.redhat.com/errata/RHSA-2019:4238
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-13730
Bugzilla
CVE-2019-13747 chromium-browser: Uninitialized Use in rendering
bugzilla·2019-12-11·CVSS 8.8
CVE-2019-13747 [HIGH] CVE-2019-13747 chromium-browser: Uninitialized Use in rendering
CVE-2019-13747 chromium-browser: Uninitialized Use in rendering
An uninitialized use flaw was found in the rendering component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=101852
External References:
https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1782013]
Affects: fedora-all [bug 1782012]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2019:4238 https://access.redhat.com/errata/RHSA-2019:4238
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-13747
Bugzilla
CVE-2019-13728 chromium-browser: Out of bounds write in V8
bugzilla·2019-12-11·CVSS 8.8
CVE-2019-13728 [HIGH] CVE-2019-13728 chromium-browser: Out of bounds write in V8
CVE-2019-13728 chromium-browser: Out of bounds write in V8
An out of bounds write flaw was found in the V8 component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=102475
External References:
https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1782013]
Affects: fedora-all [bug 1782012]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2019:4238 https://access.redhat.com/errata/RHSA-2019:4238
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-13728
Bugzilla
CVE-2019-13762 chromium-browser: Insufficient policy enforcement in downloads
bugzilla·2019-12-11·CVSS 3.3
CVE-2019-13762 [LOW] CVE-2019-13762 chromium-browser: Insufficient policy enforcement in downloads
CVE-2019-13762 chromium-browser: Insufficient policy enforcement in downloads
An insufficient policy enforcement flaw was found in the downloads component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=100421
External References:
https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1782013]
Affects: fedora-all [bug 1782012]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2019:4238 https://access.redhat.com/errata/RHSA-2019:4238
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com
Bugzilla
CVE-2019-13744 chromium-browser: Insufficient policy enforcement in cookies
bugzilla·2019-12-11·CVSS 6.5
CVE-2019-13744 [MEDIUM] CVE-2019-13744 chromium-browser: Insufficient policy enforcement in cookies
CVE-2019-13744 chromium-browser: Insufficient policy enforcement in cookies
An insufficient policy enforcement flaw was found in the cookies component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=853670
External References:
https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1782023]
Affects: fedora-all [bug 1782022]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2019:4238 https://access.redhat.com/errata/RHSA-2019:4238
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/sec
Bugzilla
CVE-2019-13727 chromium-browser: Insufficient policy enforcement in WebSockets
bugzilla·2019-12-11·CVSS 8.8
CVE-2019-13727 [HIGH] CVE-2019-13727 chromium-browser: Insufficient policy enforcement in WebSockets
CVE-2019-13727 chromium-browser: Insufficient policy enforcement in WebSockets
An insufficient policy enforcement flaw was found in the WebSockets component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=944619
External References:
https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1782013]
Affects: fedora-all [bug 1782012]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2019:4238 https://access.redhat.com/errata/RHSA-2019:4238
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.c
2019-04-25
Published