IBM Java Security Components in IBM SDK, Java Technology Edition 8 before SR1 FP10, 7 R1 before SR3 FP10, 7 before SR9 FP10, 6 R1 before SR8 FP7, 6 before SR16 FP7, and 5.0 before SR16 FP13 stores plaintext information in memory dumps, which allows local users to obtain sensitive information by reading a file.
An insufficient policy enforcement flaw was found in the payments component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=101160
External References:
https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html
An incorrect security ui flaw was found in the Omnibox component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=100268
External References:
https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html
An incorrect security ui flaw was found in the interstitials component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=901789
External References:
https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html
An insufficient policy enforcement flaw was found in the navigation component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=979442
External References:
https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html
An incorrect security ui flaw was found in the Omnibox component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=884693
External References:
https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html
An incorrect security ui flaw was found in the printing component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=708595
External References:
https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html
An insufficient policy enforcement flaw was found in the extensions component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=696208
External References:
https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html
An insufficient policy enforcement flaw was found in the extensions component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=442579
External References:
https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html
An insufficient policy enforcement flaw was found in the developer tools component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=993706
External References:
https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html
An incorrect security ui flaw was found in the Omnibox component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=101076
External References:
https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html
An insufficient policy enforcement flaw was found in the Omnibox component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=999932
External References:
https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html
An insufficient policy enforcement flaw was found in the audio component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=990867
External References:
https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html
An insufficient policy enforcement flaw was found in the cookies component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=853670
External References:
https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html
An incorrect security ui flaw was found in the external protocol handling component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=754304
External References:
https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html
An incorrect security ui flaw was found in the Omnibox component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=101756
External References:
https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html
An incorrect security ui flaw was found in the Omnibox component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=824715
External References:
https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html
An incorrect security ui flaw was found in the sharing component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=100559
External References:
https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html
An insufficient policy enforcement flaw was found in the autocomplete component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=101388
External References:
https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html
An insufficient policy enforcement flaw was found in the navigation component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=101744
External References:
https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html
An unspecified vulnerability in Java SE related to the Deployment component could allow an unauthenticated attacker to cause low confidentiality impact, low integrity impact, and no availability impact.
Created from Advisory: ADV0024179
A NULL pointer dereference flaw was discovered in the DrawGlyphList class in the 2D component in OpenJDK. A specially crafted font file could use this flaw to cause a Java application to crash.
An unspecified vulnerability in Java SE related to the JAXP component could allow an unauthenticated attacker to cause a denial of service resulting in a low availability impact using unknown attack vectors.
An unspecified vulnerability in Java SE related to the Concurrency component could allow an unauthenticated attacker to cause a denial of service resulting in a low availability impact using unknown attack vectors.
An exposed debugging endpoint in the browser in Google Chrome on Android prior to 72.0.3626.81 allowed a local attacker to obtain potentially sensitive information from process memory via a crafted Intent.
A missing case for handling special schemes in permission request checks in Extensions in Google Chrome prior to 72.0.3626.81 allowed an attacker who convinced a user to install a malicious extension to bypass extension permission checks for privileged pages via a crafted Chrome Extension.
An insufficient data validation flaw was found in the IndexedDB component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=917668
External References:
https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.html
An inappropriate implementation flaw was found in the QUIC Networking component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=914497
External References:
https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.html
An insufficient policy enforcement flaw was found in the URL Formatter component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=895207
External References:
https://chromereleases.googleblog.com/2018/12/stable-channel-update-for-desktop.html