Show filters
867 Total Results
Displaying 151-160 of 867
Sort by:
Attacker Value
Unknown
CVE-2019-1559
Disclosure Date: February 26, 2019 (last updated November 08, 2023)
If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid padding compared to if a 0 byte record is received with an invalid MAC. If the application then behaves differently based on that in a way that is detectable to the remote peer, then this amounts to a padding oracle that could be used to decrypt data. In order for this to be exploitable "non-stitched" ciphersuites must be in use. Stitched ciphersuites are optimised implementations of certain commonly used ciphersuites. Also the application must call SSL_shutdown() twice even if a protocol error has occurred (applications should not do this but some do anyway). Fixed in OpenSSL 1.0.2r (Affected 1.0.2-1.0.2q).
0
Attacker Value
Unknown
CVE-2019-5766
Disclosure Date: February 19, 2019 (last updated November 08, 2023)
Incorrect handling of origin taint checking in Canvas in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
0
Attacker Value
Unknown
CVE-2019-5757
Disclosure Date: February 19, 2019 (last updated November 08, 2023)
An incorrect object type assumption in SVG in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page.
0
Attacker Value
Unknown
CVE-2019-5775
Disclosure Date: February 19, 2019 (last updated November 08, 2023)
Incorrect handling of a confusable character in Omnibox in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.
0
Attacker Value
Unknown
CVE-2019-5767
Disclosure Date: February 19, 2019 (last updated November 08, 2023)
Insufficient protection of permission UI in WebAPKs in Google Chrome on Android prior to 72.0.3626.81 allowed an attacker who convinced the user to install a malicious application to access privacy/security sensitive web APIs via a crafted APK.
0
Attacker Value
Unknown
CVE-2019-5773
Disclosure Date: February 19, 2019 (last updated November 08, 2023)
Insufficient origin validation in IndexedDB in Google Chrome prior to 72.0.3626.81 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page.
0
Attacker Value
Unknown
CVE-2019-5760
Disclosure Date: February 19, 2019 (last updated November 08, 2023)
Insufficient checks of pointer validity in WebRTC in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
0
Attacker Value
Unknown
CVE-2019-5762
Disclosure Date: February 19, 2019 (last updated November 08, 2023)
Inappropriate memory management when caching in PDFium in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file.
0
Attacker Value
Unknown
CVE-2019-5782
Disclosure Date: February 19, 2019 (last updated November 08, 2023)
Incorrect optimization assumptions in V8 in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
0
Attacker Value
Unknown
CVE-2019-5770
Disclosure Date: February 19, 2019 (last updated November 08, 2023)
Insufficient input validation in WebGL in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
0