Vulnerabilities > Opensuse > Backports SLE > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-11-25 CVE-2019-13716 Incorrect Authorization vulnerability in multiple products
Insufficient policy enforcement in service workers in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
network
low complexity
google opensuse CWE-863
4.3
2019-11-25 CVE-2019-13715 Authentication Bypass by Spoofing vulnerability in multiple products
Insufficient validation of untrusted input in Omnibox in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
network
low complexity
google opensuse CWE-290
4.3
2019-11-25 CVE-2019-13714 Code Injection vulnerability in multiple products
Insufficient validation of untrusted input in Color Enhancer extension in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to inject CSS into an HTML page via a crafted URL.
network
low complexity
google opensuse CWE-94
6.1
2019-11-25 CVE-2019-13710 Insufficient validation of untrusted input in downloads in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to bypass download restrictions via a crafted HTML page.
network
low complexity
google opensuse
4.3
2019-11-25 CVE-2019-13709 Authentication Bypass by Spoofing vulnerability in multiple products
Insufficient policy enforcement in downloads in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to bypass download restrictions via a crafted HTML page.
network
low complexity
google opensuse CWE-290
6.5
2019-11-25 CVE-2019-13708 Authentication Bypass by Spoofing vulnerability in multiple products
Inappropriate implementation in navigation in Google Chrome on iOS prior to 78.0.3904.70 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
network
low complexity
google opensuse CWE-290
4.3
2019-11-25 CVE-2019-13704 Authentication Bypass by Spoofing vulnerability in multiple products
Insufficient policy enforcement in navigation in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to bypass content security policy via a crafted HTML page.
network
low complexity
google opensuse CWE-290
4.3
2019-11-25 CVE-2019-13703 Authentication Bypass by Spoofing vulnerability in multiple products
Insufficient policy enforcement in the Omnibox in Google Chrome on Android prior to 78.0.3904.70 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
network
low complexity
google opensuse CWE-290
4.3
2019-11-25 CVE-2019-13701 Authentication Bypass by Spoofing vulnerability in multiple products
Incorrect implementation in navigation in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
network
low complexity
google opensuse CWE-290
4.3
2019-11-22 CVE-2019-10206 Insufficiently Protected Credentials vulnerability in multiple products
ansible-playbook -k and ansible cli tools, all versions 2.8.x before 2.8.4, all 2.7.x before 2.7.13 and all 2.6.x before 2.6.19, prompt passwords by expanding them from templates as they could contain special characters.
network
low complexity
redhat debian opensuse CWE-522
6.5