8.8

CVE-2020-6385

Exploit

Insufficient policy enforcement in storage in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass site isolation via a crafted HTML page.

Data is provided by the National Vulnerability Database (NVD)
GoogleChrome Version < 80.0.3987.87
OpensuseBackports Sle Version15.0 Updatesp1
FedoraprojectFedora Version30
FedoraprojectFedora Version31
DebianDebian Linux Version9.0
DebianDebian Linux Version10.0
SusePackage Hub Version-
   SuseLinux Enterprise Version12.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.4% 0.796
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-754 Improper Check for Unusual or Exceptional Conditions

The product does not check or incorrectly checks for unusual or exceptional conditions that are not expected to occur frequently during day to day operation of the product.