Vulnerabilities > Google > Chrome > 78.0.3904.19

DATE CVE VULNERABILITY TITLE RISK
2019-11-25 CVE-2019-13706 Out-of-bounds Write vulnerability in multiple products
Out of bounds memory access in PDFium in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
local
low complexity
google opensuse CWE-787
7.8
2019-11-25 CVE-2019-13705 Improper Privilege Management vulnerability in multiple products
Insufficient policy enforcement in extensions in Google Chrome prior to 78.0.3904.70 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension.
network
low complexity
google opensuse CWE-269
4.3
2019-11-25 CVE-2019-13704 Authentication Bypass by Spoofing vulnerability in multiple products
Insufficient policy enforcement in navigation in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to bypass content security policy via a crafted HTML page.
network
low complexity
google opensuse CWE-290
4.3
2019-11-25 CVE-2019-13703 Authentication Bypass by Spoofing vulnerability in multiple products
Insufficient policy enforcement in the Omnibox in Google Chrome on Android prior to 78.0.3904.70 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
network
low complexity
google opensuse CWE-290
4.3
2019-11-25 CVE-2019-13702 Improper Privilege Management vulnerability in multiple products
Inappropriate implementation in installer in Google Chrome on Windows prior to 78.0.3904.70 allowed a local attacker to perform privilege escalation via a crafted executable.
local
low complexity
google opensuse CWE-269
7.8
2019-11-25 CVE-2019-13701 Authentication Bypass by Spoofing vulnerability in multiple products
Incorrect implementation in navigation in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
network
low complexity
google opensuse CWE-290
4.3
2019-11-25 CVE-2019-13700 Out-of-bounds Write vulnerability in multiple products
Out of bounds memory access in the gamepad API in Google Chrome prior to 78.0.3904.70 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
network
low complexity
google opensuse CWE-787
8.8
2019-11-25 CVE-2019-13699 Use After Free vulnerability in multiple products
Use after free in media in Google Chrome prior to 78.0.3904.70 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
network
low complexity
google opensuse CWE-416
8.8
2019-09-27 CVE-2019-8075 Adobe Flash Player version 32.0.0.192 and earlier versions have a Same Origin Policy Bypass vulnerability.
network
low complexity
adobe google debian fedoraproject
7.5