|
209711
|
8.8 |
HIGH
Network
|
google debian fedoraproject opensuse
|
chrome debian_linux fedora backports_sle
|
Integer overflow in Blink in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to bypass site isolation via a crafted HTML page.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2020-15974
|
2024-11-21 14:06 |
2020-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209712
|
6.5 |
MEDIUM
Network
|
google fedoraproject opensuse debian
|
chrome fedora backports_sle debian_linux
|
Insufficient policy enforcement in extensions in Google Chrome prior to 86.0.4240.75 allowed an attacker who convinced a user to install a malicious extension to bypass same origin policy via a craft…
|
NVD-CWE-noinfo
|
CVE-2020-15973
|
2024-11-21 14:06 |
2020-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209713
|
8.8 |
HIGH
Network
|
google debian fedoraproject opensuse
|
chrome debian_linux fedora backports_sle
|
Use after free in audio in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
|
CWE-787 CWE-416
Out-of-bounds Write Use After Free
|
CVE-2020-15972
|
2024-11-21 14:06 |
2020-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209714
|
8.8 |
HIGH
Network
|
google fedoraproject opensuse debian
|
chrome fedora backports_sle debian_linux
|
Use after free in printing in Google Chrome prior to 86.0.4240.75 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
|
CWE-416
Use After Free
|
CVE-2020-15971
|
2024-11-21 14:06 |
2020-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209715
|
8.8 |
HIGH
Network
|
google fedoraproject opensuse debian
|
chrome fedora backports_sle debian_linux
|
Use after free in NFC in Google Chrome prior to 86.0.4240.75 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
|
CWE-416
Use After Free
|
CVE-2020-15970
|
2024-11-21 14:06 |
2020-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209716
|
8.8 |
HIGH
Network
|
google debian fedoraproject opensuse apple
|
chrome debian_linux fedora backports_sle ipados safari watchos macos tvos iphone_os
|
Use after free in WebRTC in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
|
CWE-787 CWE-416
Out-of-bounds Write Use After Free
|
CVE-2020-15969
|
2024-11-21 14:06 |
2020-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209717
|
8.8 |
HIGH
Network
|
google debian fedoraproject opensuse
|
chrome debian_linux fedora backports_sle
|
Use after free in Blink in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
|
CWE-416
Use After Free
|
CVE-2020-15968
|
2024-11-21 14:06 |
2020-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209718
|
8.8 |
HIGH
Network
|
google fedoraproject opensuse debian
|
chrome fedora backports_sle debian_linux
|
Use after free in payments in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
|
CWE-416
Use After Free
|
CVE-2020-15967
|
2024-11-21 14:06 |
2020-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209719
|
5.4 |
MEDIUM
Network
|
ea
|
origin_client
|
A cross-site scripting (XSS) vulnerability exists in the Origin Client for Mac and PC 10.5.86 or earlier that could allow a remote attacker to execute arbitrary Javascript in a target user’s Origin c…
|
CWE-79
Cross-site Scripting
|
CVE-2020-15914
|
2024-11-21 14:06 |
2020-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209720
|
3.3 |
LOW
Local
|
aptdaemon_project
|
aptdaemon
|
There is no input validation on the Locale property in an apt transaction. An unprivileged user can supply a full path to a writable directory, which lets aptd read a file as root. Having a symlink i…
|
CWE-22
Path Traversal
|
CVE-2020-15703
|
2024-11-21 14:06 |
2020-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|