Kaspersky ID:
KLA11413
Дата обнаружения:
29/01/2019
Обновлено:
22/01/2024

Описание

Multiple vulnerabilities were found in Google Chrome. Malicious users can exploit these vulnerabilities to execute arbitrary code, bypass security restrictions.

Below is a complete list of vulnerabilities:

  1. Inappropriate implementation vulnerability in QUIC Networking component can be exploited to execute arbitrary code;
  2. Inappropriate implementation vulnerability in V8 component can be exploited to execute arbitrary code;
  3. Use after free vulnerability in PDFium component can be exploited remotely to execute arbitrary code;
  4. Type Confusion vulnerability in SVG component can be exploited remotely to execute arbitrary code;
  5. Use after free vulnerability in Blink component can be exploited remotely to execute arbitrary code;
  6. Use after free vulnerability in HTML select elements can be exploited remotely to execute arbitrary code;
  7. Use after free vulnerability in WebRTC component can be exploited remotely to execute arbitrary code;
  8. Use after free vulnerability in SwiftShader component can be exploited remotely to execute arbitrary code;
  9. Insufficient validation vulnerability in V8 component can be exploited remotely to execute arbitrary code;
  10. Insufficient policy enforcement vulnerability in browser can be exploited remotely to execute arbitrary code;
  11. Stack buffer overflow vulnerability in Skia component can be exploited remotely to bypass security restrictions;
  12. Insufficient policy enforcement vulnerability in Canvas component can be exploited remotely to execute arbitrary code;
  13. Incorrect security vulnerability of UI in WebAPKs component can be exploited remotely to execute arbitrary code;
  14. Insufficient policy enforcement vulnerability in DevTools component can be exploited remotely to execute arbitrary code;
  15. Insufficient validation of untrusted input vulnerability in Blink component can be exploited remotely to execute arbitrary code;
  16. Heap buffer overflow vulnerability in WebGL component can be exploited remotely to execute arbitrary code;
  17. Heap buffer overflow vulnerability in SwiftShader component can be exploited remotely to execute arbitrary code;
  18. Insufficient data validation vulnerability in IndexedDB component can be exploited remotely to execute arbitrary code;
  19. Insufficient validation of untrusted input vulnerability in SafeBrowsing component can be exploited remotely to execute arbitrary code;
  20. Insufficient policy enforcement vulnerability in Omnibox component can be exploited remotely to execute arbitrary code;
  21. Insufficient policy enforcement vulnerability in Extensions component can be exploited remotely to execute arbitrary code;
  22. Insufficient policy enforcement vulnerability in ServiceWorker component can be exploited remotely to execute arbitrary code;
  23. Insufficient validation of untrusted input vulnerability in DevTools component can be exploited remotely to execute arbitrary code;
  24. Use after free vulnerability in FileAPI component can be exploited remotely to execute arbitrary code.

Первичный источник обнаружения

Связанные продукты

Список CVE

  • CVE-2019-5754
    warning
  • CVE-2019-5782
    high
  • CVE-2019-5755
    high
  • CVE-2019-5756
    high
  • CVE-2019-5757
    high
  • CVE-2019-5758
    high
  • CVE-2019-5759
    high
  • CVE-2019-5760
    high
  • CVE-2019-5761
    high
  • CVE-2019-5762
    high
  • CVE-2019-5763
    high
  • CVE-2019-5764
    high
  • CVE-2019-5765
    warning
  • CVE-2019-5785
    warning
  • CVE-2019-5766
    warning
  • CVE-2019-5767
    warning
  • CVE-2019-5768
    warning
  • CVE-2019-5769
    high
  • CVE-2019-5770
    high
  • CVE-2019-5771
    high
  • CVE-2019-5772
    high
  • CVE-2019-5773
    warning
  • CVE-2019-5774
    high
  • CVE-2019-5775
    warning
  • CVE-2019-5776
    warning
  • CVE-2019-5777
    warning
  • CVE-2019-5778
    warning
  • CVE-2019-5779
    warning
  • CVE-2019-5780
    warning
  • CVE-2019-5783
    high
  • CVE-2019-5781
    warning
  • CVE-2019-13684
    warning
  • CVE-2018-20073
    warning
  • CVE-2019-13768
    warning

Смотрите также

Узнай статистику распространения уязвимостей в своем регионе statistics.securelist.com

Нашли неточность в описании этой уязвимости? Дайте нам знать!
Встречай новый Kaspersky!
Каждая минута твоей онлайн-жизни заслуживает топовой защиты.
Узнать больше
Kaspersky IT Security Calculator:
Оцените ваш профиль кибербезопасности
Узнать больше
Confirm changes?
Your message has been sent successfully.