Vulnerabilities > Debian > Debian Linux > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-06-27 CVE-2019-5830 Insufficient policy enforcement in CORS in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
network
low complexity
google opensuse debian fedoraproject
6.5
2019-06-27 CVE-2019-5823 Open Redirect vulnerability in multiple products
Insufficient policy enforcement in service workers in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
network
low complexity
google opensuse debian fedoraproject CWE-601
5.4
2019-06-27 CVE-2019-5818 Use of Uninitialized Resource vulnerability in multiple products
Uninitialized data in media in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted video file.
network
low complexity
google opensuse debian fedoraproject CWE-908
6.5
2019-06-27 CVE-2019-5814 Cross-Site Request Forgery (CSRF) vulnerability in multiple products
Insufficient policy enforcement in Blink in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
network
low complexity
google opensuse debian fedoraproject CWE-352
6.5
2019-06-27 CVE-2019-5810 Cleartext Storage of Sensitive Information vulnerability in multiple products
Information leak in autofill in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
network
low complexity
google opensuse debian fedoraproject CWE-312
6.5
2019-06-27 CVE-2019-5805 Use After Free vulnerability in multiple products
Use-after-free in PDFium in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
network
low complexity
google opensuse debian fedoraproject CWE-416
6.5
2019-06-26 CVE-2019-12979 Improper Initialization vulnerability in multiple products
ImageMagick 7.0.8-34 has a "use of uninitialized value" vulnerability in the SyncImageSettings function in MagickCore/image.c.
6.8
2019-06-26 CVE-2019-12976 Memory Leak vulnerability in multiple products
ImageMagick 7.0.8-34 has a memory leak in the ReadPCLImage function in coders/pcl.c.
5.5
2019-06-26 CVE-2019-12975 Memory Leak vulnerability in multiple products
ImageMagick 7.0.8-34 has a memory leak vulnerability in the WriteDPXImage function in coders/dpx.c.
5.5
2019-06-26 CVE-2019-12973 Excessive Iteration vulnerability in multiple products
In OpenJPEG 2.3.1, there is excessive iteration in the opj_t1_encode_cblks function of openjp2/t1.c.
local
low complexity
uclouvain opensuse debian oracle CWE-834
5.5