CVE-2019-13734 is a critical out-of-bounds write vulnerability in SQLite, affecting Google Chrome prior to version 79.0.3945.79, as well as various Linux distributions and other products utilizing SQLite. With a CVSS score of 8.8 (HIGH), it allows a remote unauthenticated attacker to achieve heap corruption and potentially arbitrary code execution by enticing a user to visit a crafted HTML page. While there is no evidence of active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion and media coverage, indicating high awareness and potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 79.0.3945.79CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
30CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:* | ||
31CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:* | ||
3.11CPE matchmatch criteria | cpe:2.3:a:redhat:openshift_container_platform:3.11:*:*:*:*:*:*:* | ||
4.2CPE matchmatch criteria | cpe:2.3:a:redhat:openshift_container_platform:4.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.