Skip to main content

Year archive

CVEs published in 2019

Archive summary

17,305 CVEs published in 2019 — 2,593 Critical, 7,142 High, 7,228 Medium, 342 Low, 0 Unrated.

CVE-2018-20071

Published Jan 9, 2019

Insufficiently strict origin checks during JIT payment app installation in Payments in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to install a service worker fo…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20070

Published Jan 9, 2019

Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20069

Published Jan 9, 2019

Failure to prevent navigation to top frame to data URLs in Navigation in Google Chrome on iOS prior to 71.0.3578.80 allowed a remote attacker to confuse the user about the origin…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20068

Published Jan 9, 2019

Incorrect handling of 304 status codes in Navigation in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to confuse the user about the origin of the current page via…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20067

Published Jan 9, 2019

A renderer initiated back navigation was incorrectly allowed to cancel a browser initiated one in Navigation in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to co…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20066

Published Jan 9, 2019

Incorrect object lifecycle in Extensions in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-20065

Published Jan 9, 2019

Handling of URI action in PDFium in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to initiate potentially unsafe navigations without a user gesture via a crafted P…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-17457

Published Jan 9, 2019

An object lifecycle issue in Blink could lead to a use after free in WebAudio in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to execute arbitrary code inside a s…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-16087

Published Jan 9, 2019

Lack of proper state tracking in Permissions in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-16085

Published Jan 9, 2019

A use after free in ResourceCoordinator in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-16080

Published Jan 9, 2019

A missing check for popup window handling in Fullscreen in Google Chrome on macOS prior to 69.0.3497.81 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) vi…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 17,076-17,100 of 17,305 CVEsPage 684 of 693