CVE-2019-5802
published 2019-05-23CVE-2019-5802: Incorrect handling of download origins in Navigation in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to perform domain spoofing via a crafted…
medium6.5CVSS 3.1
AVNACLPRNUIRSUCNIHAN
Incorrect handling of download origins in Navigation in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chromium | chromium | >= 0 < 73.0.3683.75-1 | 73.0.3683.75-1 |
| chromium | chromium | >= 0 < 73.0.3683.75-1 | 73.0.3683.75-1 |
| chromium | chromium | >= 0 < 73.0.3683.75-1 | 73.0.3683.75-1 |
| chromium | chromium | >= 0 < 73.0.3683.75-1 | 73.0.3683.75-1 |
| debian | chromium | < chromium 73.0.3683.75-1 (bookworm) | chromium 73.0.3683.75-1 (bookworm) |
| chrome | < 73.0.3683.75 | 73.0.3683.75 | |
| chrome | — | — | |
| opensuse | backports_sle | — | — |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
osv6.5MEDIUM