CVE-2019-5785

Description

Incorrect convexity calculations in Skia in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page.

Risk Information

Base Score
6.5
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
0.375

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities fixed in Google Chrome (x64) (72.0.3626.81)Windows
Multiple vulnerabilities fixed in Google Chrome (72.0.3626.81)Windows
Vulnerabilities CVE-2019-5785 are fixed in Update for Mozilla Firefox For Mac (65.0.1)Mac
Vulnerabilities CVE-2019-5785 are fixed in Mozilla Thunderbird For Mac 60.5.1Mac
Vulnerabilities CVE-2019-5785 are fixed in Mozilla Firefox For Mac 60.5.1Mac
firefox-esr security update(DSA-4391-1) firefox-esr_60.5.1esr-1~deb9u1_i386.debLinux
firefox-esr security update(DSA-4391-1) firefox-esr_60.5.1esr-1~deb9u1_amd64.debLinux
SUSE-SU-2019:0852-1(SUSE Linux Enterprise Desktop 12-SP3 ) MozillaFirefox-60.6.1esr-109.63.2.x86_64.rpmLinux
SUSE-SU-2019:0852-1(SUSE Linux Enterprise Desktop 12-SP3 ) MozillaFirefox-debuginfo-60.6.1esr-109.63.2.x86_64.rpmLinux
SUSE-SU-2019:0852-1(SUSE Linux Enterprise Desktop 12-SP3 ) MozillaFirefox-debugsource-60.6.1esr-109.63.2.x86_64.rpmLinux
SUSE-SU-2019:0852-1(SUSE Linux Enterprise Desktop 12-SP3 ) MozillaFirefox-translations-common-60.6.1esr-109.63.2.x86_64.rpmLinux
(RHSA-2019:1144) thunderbird security update thunderbird-60.6.1-1.el8.x86_64.rpmLinux
(RHSA-2019:1144) thunderbird security update thunderbird-debugsource-60.6.1-1.el8.x86_64.rpmLinux
Multiple vulnerabilities fixed in Google Chrome (72.0.3626.81) (For Debian)Linux
Multiple vulnerabilities fixed in Google Chrome (72.0.3626.81) (For Centos)Linux
Multiple vulnerabilities fixed in Google Chrome (72.0.3626.81) (For RedHat)Linux
Multiple vulnerabilities fixed in Google Chrome (72.0.3626.81) (For Suse)Linux
Multiple vulnerabilities fixed in Google Chrome (72.0.3626.81) (For Ubuntu)Linux

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-313039Google Chrome (x64) (80.0.3987.122)
PATCH-313039Google Chrome (x64) (80.0.3987.122)
PATCH-607000Mozilla Firefox For Mac (124.0)
PATCH-611807Mozilla Thunderbird For Mac (142.0)
PATCH-612783Mozilla Firefox For Mac (145.0.1)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234