CVE-2019-5786

Description

Object lifetime issue in Blink in Google Chrome prior to 72.0.3626.121 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.

Risk Information

Base Score
6.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
89.45

Associated Vulnerability

VulnerabilityOS Platform
Google Chrome (72.0.3626.121)Windows
Google Chrome (x64) (72.0.3626.121)Windows
Vulnerabilities CVE-2019-5786 are fixed in Chrome 72.0.3626.122Windows
Vulnerabilities CVE-2019-5786 are fixed in Chrome (x64) 72.0.3626.122Windows
Vulnerabilities CVE-2019-5786 are fixed in Google Chrome for Mac 72.0.3626.122Mac
Vulnerabilities CVE-2019-5786 are fixed in Update for Google Chrome For Mac (72.0.3626.121)Mac
chromium regression update(DSA-4395-2) chromium_72.0.3626.122-1~deb9u1_amd64.debLinux
Google Chrome (72.0.3626.121) (For Debian)Linux
Vulnerabilities CVE-2019-5786 are fixed in Chrome 72.0.3626.122 (For Debian)Linux
Google Chrome (72.0.3626.121) (For Centos)Linux
Vulnerabilities CVE-2019-5786 are fixed in Chrome 72.0.3626.122 (For Centos)Linux
Google Chrome (72.0.3626.121) (For RedHat)Linux
Vulnerabilities CVE-2019-5786 are fixed in Chrome 72.0.3626.122 (For RedHat)Linux
Google Chrome (72.0.3626.121) (For Suse)Linux
Vulnerabilities CVE-2019-5786 are fixed in Chrome 72.0.3626.122 (For Suse)Linux
Google Chrome (72.0.3626.121) (For Ubuntu)Linux
Vulnerabilities CVE-2019-5786 are fixed in Chrome 72.0.3626.122 (For Ubuntu)Linux

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-309117Google Chrome (72.0.3626.121)
PATCH-309118Google Chrome (x64) (72.0.3626.121)
PATCH-313038Google Chrome (80.0.3987.122)
PATCH-313039Google Chrome (x64) (80.0.3987.122)
PATCH-611995Google Chrome for Mac (140.0.7339.132 , 140.0.7339.133)
PATCH-609673Google Chrome for Mac (132.0.6834.83, 132.0.6834.84)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234