CVE-2020-6390
- EPSS 3.89%
- Veröffentlicht 11.02.2020 15:15:12
- Zuletzt bearbeitet 21.11.2024 05:35:37
Out of bounds memory access in streams in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2020-6391
- EPSS 1.74%
- Veröffentlicht 11.02.2020 15:15:12
- Zuletzt bearbeitet 21.11.2024 05:35:38
Insufficient validation of untrusted input in Blink in Google Chrome prior to 80.0.3987.87 allowed a local attacker to bypass content security policy via a crafted HTML page.
CVE-2020-6392
- EPSS 1.74%
- Veröffentlicht 11.02.2020 15:15:12
- Zuletzt bearbeitet 21.11.2024 05:35:38
Insufficient policy enforcement in extensions in Google Chrome prior to 80.0.3987.87 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension.
CVE-2020-6393
- EPSS 1.45%
- Veröffentlicht 11.02.2020 15:15:12
- Zuletzt bearbeitet 21.11.2024 05:35:38
Insufficient policy enforcement in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
CVE-2020-6394
- EPSS 1.06%
- Veröffentlicht 11.02.2020 15:15:12
- Zuletzt bearbeitet 21.11.2024 05:35:38
Insufficient policy enforcement in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass content security policy via a crafted HTML page.
CVE-2012-4512
- EPSS 9.04%
- Veröffentlicht 08.02.2020 19:15:10
- Zuletzt bearbeitet 21.11.2024 01:43:02
The CSS parser (khtml/css/cssparser.cpp) in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read memory via a crafted font face source, related to "type confusion."
CVE-2019-15605
- EPSS 32.25%
- Veröffentlicht 07.02.2020 15:15:11
- Zuletzt bearbeitet 21.11.2024 04:29:06
HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformed
CVE-2013-4166
- EPSS 1.01%
- Veröffentlicht 06.02.2020 15:15:10
- Zuletzt bearbeitet 21.11.2024 01:55:00
The gpg_ctx_add_recipient function in camel/camel-gpg-context.c in GNOME Evolution 3.8.4 and earlier and Evolution Data Server 3.9.5 and earlier does not properly select the GPG key to use for email encryption, which might cause the email to be encry...
CVE-2014-8141
- EPSS 9.81%
- Veröffentlicht 31.01.2020 23:15:10
- Zuletzt bearbeitet 21.11.2024 02:18:38
Heap-based buffer overflow in the getZip64Data function in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the unzip command.
CVE-2014-8139
- EPSS 9.81%
- Veröffentlicht 31.01.2020 22:15:10
- Zuletzt bearbeitet 21.11.2024 02:18:38
Heap-based buffer overflow in the CRC32 verification in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the unzip command.