CVE-2020-0005
published 2020-02-13CVE-2020-0005: In btm_read_remote_ext_features_complete of btm_acl.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local…
PriorityP428medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
0.18%
7.8th percentile
In btm_read_remote_ext_features_complete of btm_acl.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-141552859
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — |
CVSS provenance
nvdv3.16.7MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware Workstation, Fusion, VMware Remote Console and Horizon Client updates address privilege escalation and denial-of-service vulnerabilities (CVE-2020-3950, CVE-2020-3951)
vendor_vmware·2020-03-17·CVSS 7.8
CVE-2020-3950 [HIGH] VMware Workstation, Fusion, VMware Remote Console and Horizon Client updates address privilege escalation and denial-of-service vulnerabilities (CVE-2020-3950, CVE-2020-3951)
VMSA-2020-0005: VMware Workstation, Fusion, VMware Remote Console and Horizon Client updates address privilege escalation and denial-of-service vulnerabilities (CVE-2020-3950, CVE-2020-3951)
VMware Fusion, VMRC for Mac and Horizon Client for Mac contain a privilege escalation vulnerability due to improper use of setuid binaries. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 7.3.
CVEs: CVE-2020-3950, CVE-2020-3951
Affected products: ESXi, Fusion Pro, Horizon Client, VMware Fusion, VMware Horizon, VMware Workstation, VMware vSphere, Workstation Player, Workstation Pro
Android
CVE-2020-0005: Android Security Bulletin 2020-02-01
CVE: CVE-2020-0005
Severity: HIGH
Type: EOP
Affected AOSP versions: 8
vendor_android·2020-02-01·CVSS 6.7
CVE-2020-0005 [MEDIUM] CVE-2020-0005: Android Security Bulletin 2020-02-01
CVE: CVE-2020-0005
Severity: HIGH
Type: EOP
Affected AOSP versions: 8
Android Security Bulletin 2020-02-01
CVE: CVE-2020-0005
Severity: HIGH
Type: EOP
Affected AOSP versions: 8.0, 8.1, 9, 10
References: A-141552859
GHSA
GHSA-q2xg-2rjr-jqv2: In btm_read_remote_ext_features_complete of btm_acl
ghsa_unreviewed·2022-05-24
CVE-2020-0005 [HIGH] GHSA-q2xg-2rjr-jqv2: In btm_read_remote_ext_features_complete of btm_acl
In btm_read_remote_ext_features_complete of btm_acl.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-141552859
No detection rules found.
Exploit-DB
Mitel MiCollab AWV 8.1.2.4 and 9.1.3 - Directory Traversal and LFI
exploitdb·2023-04-06·CVSS 5.3
CVE-2020-11798 [MEDIUM] Mitel MiCollab AWV 8.1.2.4 and 9.1.3 - Directory Traversal and LFI
Mitel MiCollab AWV 8.1.2.4 and 9.1.3 - Directory Traversal and LFI
---
# Exploit Title: Mitel MiCollab AWV 8.1.2.4 and 9.1.3 - Directory Traversal and LFI
# Date: 2022-10-14
# Fix Date: 2020-05
# Exploit Author: Kahvi-0
# Github: https://github.com/Kahvi-0
# Vendor Homepage: https://www.mitel.com/
# Vendor Security Advisory: https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-20-0005
# Version: before 8.1.2.4 and 9.x before 9.1.3
# CVE: CVE-2020-11798
# CVE Reported By: Tri Bui
Description:
A Directory Traversal vulnerability in the web conference component of Mitel MiCollab AWV before 8.1.2.4 and 9.x before 9.1.3 could allow an attacker to access arbitrary files from restricted directories of the server via a crafted URL, due to insufficient access valid
Exploit-DB
VMware Fusion 11.5.2 - Privilege Escalation
exploitdb·2020-03-20·CVSS 7.8
CVE-2020-3950 [HIGH] VMware Fusion 11.5.2 - Privilege Escalation
VMware Fusion 11.5.2 - Privilege Escalation
---
# Exploit Title: VMware Fusion 11.5.2 - Privilege Escalation
# Date: 2020-03-17
# Exploit Author: Rich Mirch
# Vendor Homepage: https://www.vmware.com/products/fusion.html
# Vendor Advisory: https://www.vmware.com/security/advisories/VMSA-2020-0005.html
# Software Link: https://download3.vmware.com/software/fusion/file/VMware-Fusion-11.5.1-15018442.dmg
# Versions:
# VMware Fusion Professional 11.5.1 (15018442)
# VMware Fusion Professional 11.5.2 (15794494)
#
# Tested on: macOS 10.14.6
# CVE : CVE-2020-3950
# Source PoC: https://raw.githubusercontent.com/mirchr/security-research/master/vulnerabilities/CVE-2020-3950.sh
#
#
#!/bin/bash
echo "CVE-2020-3950 VMware Fusion EoP PoC by @0xm1rch"
mkdir -p ~/a/b/c
mkdir -p ~/Contents/Library/services
Bugzilla
CVE-2019-8768 webkitgtk: Browsing history could not be deleted
bugzilla·2020-09-07·CVSS 5.3
CVE-2019-8768 [MEDIUM] CVE-2019-8768 webkitgtk: Browsing history could not be deleted
CVE-2019-8768 webkitgtk: Browsing history could not be deleted
WebKitGTK Security Advisory WSA-2019-0005 describes the following issue:
CVE-2019-8768
Impact: A user may be unable to delete browsing history items. Description: “Clear History and Website Data” did not clear the history. The issue was addressed with improved data deletion.
Versions affected: WebKitGTK before 2.24.0 and WPE WebKit before 2.24.0.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2019-0005.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/secu
Bugzilla
CVE-2020-3900 webkitgtk: Memory corruption triggered by a malicious web content
bugzilla·2020-09-07·CVSS 8.8
CVE-2020-3900 [HIGH] CVE-2020-3900 webkitgtk: Memory corruption triggered by a malicious web content
CVE-2020-3900 webkitgtk: Memory corruption triggered by a malicious web content
WebKitGTK Security Advisory WSA-2020-0005 describes the following issue:
CVE-2020-3900
Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Description: A memory corruption issue was addressed with improved memory handling
Versions affected: WebKitGTK before 2.28.0 and WPE WebKit before 2.28.0.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2020-0005.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/secu
Bugzilla
CVE-2019-8763 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
bugzilla·2020-09-07·CVSS 8.8
CVE-2019-8763 [HIGH] CVE-2019-8763 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
CVE-2019-8763 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
WebKitGTK Security Advisory WSA-2019-0005 describes the following issue:
CVE-2019-8763
Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Description: Multiple memory corruption issues were addressed with improved memory handling.
Versions affected: WebKitGTK before 2.24.4 and WPE WebKit before 2.24.3.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2019-0005.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https
Bugzilla
CVE-2020-3897 webkitgtk: Type confusion leading to arbitrary code execution
bugzilla·2020-09-07·CVSS 8.8
CVE-2020-3897 [HIGH] CVE-2020-3897 webkitgtk: Type confusion leading to arbitrary code execution
CVE-2020-3897 webkitgtk: Type confusion leading to arbitrary code execution
WebKitGTK Security Advisory WSA-2020-0005 describes the following issue:
CVE-2020-3897
Impact: A remote attacker may be able to cause arbitrary code execution. Description: A type confusion issue was addressed with improved memory handling.
Versions affected: WebKitGTK before 2.28.0 and WPE WebKit before 2.28.0.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2020-0005.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-3897
Bugzilla
CVE-2019-8719 webkitgtk: Incorrect state management leading to universal cross-site scripting
bugzilla·2020-09-07·CVSS 6.1
CVE-2019-8719 [MEDIUM] CVE-2019-8719 webkitgtk: Incorrect state management leading to universal cross-site scripting
CVE-2019-8719 webkitgtk: Incorrect state management leading to universal cross-site scripting
WebKitGTK Security Advisory WSA-2019-0005 describes the following issue:
CVE-2019-8719
Impact: Processing maliciously crafted web content may lead to universal cross site scripting. Description: A logic issue was addressed with improved state management.
Versions affected: WebKitGTK before 2.24.4 and WPE WebKit before 2.24.3.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2019-0005.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redha
Bugzilla
CVE-2019-8735 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
bugzilla·2020-09-07·CVSS 8.8
CVE-2019-8735 [HIGH] CVE-2019-8735 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
CVE-2019-8735 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
WebKitGTK Security Advisory WSA-2019-0005 describes the following issue:
CVE-2019-8735
Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Description: Multiple memory corruption issues were addressed with improved memory handling.
Versions affected: WebKitGTK before 2.24.2 and WPE WebKit before 2.24.2.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2019-0005.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https
Bugzilla
CVE-2020-3894 webkitgtk: Race condition allows reading of restricted memory
bugzilla·2020-09-07·CVSS 3.1
CVE-2020-3894 [LOW] CVE-2020-3894 webkitgtk: Race condition allows reading of restricted memory
CVE-2020-3894 webkitgtk: Race condition allows reading of restricted memory
WebKitGTK Security Advisory WSA-2020-0005 describes the following issue:
CVE-2020-3894
Impact: An application may be able to read restricted memory. Description: A race condition was addressed with additional validation.
Versions affected: WebKitGTK before 2.28.0 and WPE WebKit before 2.28.0.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2020-0005.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-3894
---
This issue ha
Bugzilla
CVE-2019-8674 webkitgtk: Incorrect state management leading to universal cross-site scripting
bugzilla·2020-09-07·CVSS 6.1
CVE-2019-8674 [MEDIUM] CVE-2019-8674 webkitgtk: Incorrect state management leading to universal cross-site scripting
CVE-2019-8674 webkitgtk: Incorrect state management leading to universal cross-site scripting
WebKitGTK Security Advisory WSA-2019-0005 describes the following issue:
CVE-2019-8674
Impact: Processing maliciously crafted web content may lead to universal cross site scripting. Description: A logic issue was addressed with improved state management.
Versions affected: WebKitGTK before 2.24.4 and WPE WebKit before 2.24.3.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2019-0005.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redha
Bugzilla
CVE-2019-8720 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
bugzilla·2020-09-07·CVSS 8.8
CVE-2019-8720 [HIGH] CVE-2019-8720 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
CVE-2019-8720 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
WebKitGTK Security Advisory WSA-2019-0005 describes the following issue:
CVE-2019-8720
Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Description: Multiple memory corruption issues were addressed with improved memory handling.
Versions affected: WebKitGTK before 2.26.0 and WPE WebKit before 2.26.0.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2019-0005.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https
Bugzilla
CVE-2020-3901 webkitgtk: Type confusion leading to arbitrary code execution
bugzilla·2020-09-07·CVSS 8.8
CVE-2020-3901 [HIGH] CVE-2020-3901 webkitgtk: Type confusion leading to arbitrary code execution
CVE-2020-3901 webkitgtk: Type confusion leading to arbitrary code execution
WebKitGTK Security Advisory WSA-2020-0005 describes the following issue:
CVE-2020-3901
Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Description: A type confusion issue was addressed with improved memory handling.
Versions affected: WebKitGTK before 2.28.0 and WPE WebKit before 2.28.0.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2020-0005.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/c
Bugzilla
CVE-2020-3899 webkitgtk: Memory consumption issue leading to arbitrary code execution
bugzilla·2020-09-07·CVSS 8.8
CVE-2020-3899 [HIGH] CVE-2020-3899 webkitgtk: Memory consumption issue leading to arbitrary code execution
CVE-2020-3899 webkitgtk: Memory consumption issue leading to arbitrary code execution
WebKitGTK Security Advisory WSA-2020-0005 describes the following issue:
CVE-2020-3899
Impact: A remote attacker may be able to cause arbitrary code execution. Description: A memory consumption issue was addressed with improved memory handling.
Versions affected: WebKitGTK before 2.28.2 and WPE WebKit before 2.28.2.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2020-0005.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve
Bugzilla
CVE-2020-3902 webkitgtk: Input validation issue leading to cross-site script attack
bugzilla·2020-09-07·CVSS 6.1
CVE-2020-3902 [MEDIUM] CVE-2020-3902 webkitgtk: Input validation issue leading to cross-site script attack
CVE-2020-3902 webkitgtk: Input validation issue leading to cross-site script attack
WebKitGTK Security Advisory WSA-2020-0005 describes the following issue:
CVE-2020-3902
Impact: Processing maliciously crafted web content may lead to a cross site scripting attack. Description: An input validation issue was addressed with improved input validation.
Versions affected: WebKitGTK before 2.28.0 and WPE WebKit before 2.28.0.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2020-0005.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redh
Bugzilla
CVE-2020-3885 webkitgtk: Incorrect processing of file URLs
bugzilla·2020-09-07·CVSS 4.3
CVE-2020-3885 [MEDIUM] CVE-2020-3885 webkitgtk: Incorrect processing of file URLs
CVE-2020-3885 webkitgtk: Incorrect processing of file URLs
WebKitGTK Security Advisory WSA-2020-0005 describes the following issue:
CVE-2020-3885
Impact: A file URL may be incorrectly processed. Description: A logic issue was addressed with improved restrictions.
Versions affected: WebKitGTK before 2.28.0 and WPE WebKit before 2.28.0.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2020-0005.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-3885
---
This issue has been addressed in the following
Bugzilla
CVE-2020-3895 webkitgtk: Memory corruption triggered by a malicious web content
bugzilla·2020-09-07·CVSS 8.8
CVE-2020-3895 [HIGH] CVE-2020-3895 webkitgtk: Memory corruption triggered by a malicious web content
CVE-2020-3895 webkitgtk: Memory corruption triggered by a malicious web content
WebKitGTK Security Advisory WSA-2020-0005 describes the following issue:
CVE-2020-3895
Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Description: A memory corruption issue was addressed with improved memory handling.
Versions affected: WebKitGTK before 2.28.0 and WPE WebKit before 2.28.0.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2020-0005.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/sec
Bugzilla
CVE-2019-8733 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
bugzilla·2020-09-07·CVSS 8.8
CVE-2019-8733 [HIGH] CVE-2019-8733 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
CVE-2019-8733 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
WebKitGTK Security Advisory WSA-2019-0005 describes the following issue:
CVE-2019-8733
Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Description: Multiple memory corruption issues were addressed with improved memory handling.
Versions affected: WebKitGTK before 2.24.4 and WPE WebKit before 2.24.3.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2019-0005.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https
Bugzilla
CVE-2019-8769 webkitgtk: Websites could reveal browsing history
bugzilla·2020-09-07·CVSS 4.3
CVE-2019-8769 [MEDIUM] CVE-2019-8769 webkitgtk: Websites could reveal browsing history
CVE-2019-8769 webkitgtk: Websites could reveal browsing history
WebKitGTK Security Advisory WSA-2019-0005 describes the following issue:
CVE-2019-8769
Impact: Visiting a maliciously crafted website may reveal browsing history. Description: An issue existed in the drawing of web page elements. The issue was addressed with improved logic.
Versions affected: WebKitGTK before 2.26.0 and WPE WebKit before 2.26.0.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2019-0005.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/secu
Bugzilla
CVE-2019-8771 webkitgtk: Violation of iframe sandboxing policy
bugzilla·2020-09-07·CVSS 6.1
CVE-2019-8771 [MEDIUM] CVE-2019-8771 webkitgtk: Violation of iframe sandboxing policy
CVE-2019-8771 webkitgtk: Violation of iframe sandboxing policy
WebKitGTK Security Advisory WSA-2019-0005 describes the following issue:
CVE-2019-8771
mpact: Maliciously crafted web content may violate iframe sandboxing policy. Description: This issue was addressed with improved iframe sandbox enforcement.
Versions affected: WebKitGTK before 2.26.0 and WPE WebKit before 2.26.0.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2019-0005.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-8771
---
Thi
Bugzilla
CVE-2019-8707 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
bugzilla·2020-09-07·CVSS 8.8
CVE-2019-8707 [HIGH] CVE-2019-8707 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
CVE-2019-8707 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
WebKitGTK Security Advisory WSA-2019-0005 describes the following issue:
CVE-2019-8707
Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Description: Multiple memory corruption issues were addressed with improved memory handling.
Versions affected: WebKitGTK before 2.24.4 and WPE WebKit before 2.24.3.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2019-0005.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https
Bugzilla
CVE-2019-8625 webkitgtk: Incorrect state management leading to universal cross-site scripting
bugzilla·2020-09-07·CVSS 6.1
CVE-2019-8625 [MEDIUM] CVE-2019-8625 webkitgtk: Incorrect state management leading to universal cross-site scripting
CVE-2019-8625 webkitgtk: Incorrect state management leading to universal cross-site scripting
WebKitGTK Security Advisory WSA-2019-0005 describes the following issue:
CVE-2019-8625
Impact: Processing maliciously crafted web content may lead to universal cross site scripting. Description: A logic issue was addressed with improved state management.
Versions affected: WebKitGTK before 2.26.0 and WPE WebKit before 2.26.0.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2019-0005.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redha
Bugzilla
CVE-2019-8726 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
bugzilla·2020-09-07·CVSS 8.8
CVE-2019-8726 [HIGH] CVE-2019-8726 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
CVE-2019-8726 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
WebKitGTK Security Advisory WSA-2019-0005 describes the following issue:
CVE-2019-8726
Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Description: Multiple memory corruption issues were addressed with improved memory handling.
Versions affected: WebKitGTK before 2.24.3 and WPE WebKit before 2.24.3.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2019-0005.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https
Bugzilla
CVE-2019-13767 chromium-browser: Use after free in media picker
bugzilla·2019-12-18·CVSS 8.8
CVE-2019-13767 [HIGH] CVE-2019-13767 chromium-browser: Use after free in media picker
CVE-2019-13767 chromium-browser: Use after free in media picker
An use after free flaw was found in the media picker component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1031653
External References:
https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop_17.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1784993]
Affects: fedora-all [bug 1784992]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:0005 https://access.redhat.com/errata/RHSA-2020:0005
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-1
2020-02-13
Published