CVE-2020-6382
- EPSS 2.9%
- Published 11.02.2020 15:15:12
- Last modified 21.11.2024 05:35:37
Type confusion in JavaScript in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2020-6385
- EPSS 1.4%
- Published 11.02.2020 15:15:12
- Last modified 21.11.2024 05:35:37
Insufficient policy enforcement in storage in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass site isolation via a crafted HTML page.
CVE-2020-6390
- EPSS 3.89%
- Published 11.02.2020 15:15:12
- Last modified 21.11.2024 05:35:37
Out of bounds memory access in streams in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2020-6391
- EPSS 1.74%
- Published 11.02.2020 15:15:12
- Last modified 21.11.2024 05:35:38
Insufficient validation of untrusted input in Blink in Google Chrome prior to 80.0.3987.87 allowed a local attacker to bypass content security policy via a crafted HTML page.
CVE-2020-6392
- EPSS 1.74%
- Published 11.02.2020 15:15:12
- Last modified 21.11.2024 05:35:38
Insufficient policy enforcement in extensions in Google Chrome prior to 80.0.3987.87 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension.
CVE-2020-6393
- EPSS 1.45%
- Published 11.02.2020 15:15:12
- Last modified 21.11.2024 05:35:38
Insufficient policy enforcement in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
CVE-2020-6394
- EPSS 1.06%
- Published 11.02.2020 15:15:12
- Last modified 21.11.2024 05:35:38
Insufficient policy enforcement in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass content security policy via a crafted HTML page.
CVE-2012-4512
- EPSS 9.04%
- Published 08.02.2020 19:15:10
- Last modified 21.11.2024 01:43:02
The CSS parser (khtml/css/cssparser.cpp) in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read memory via a crafted font face source, related to "type confusion."
CVE-2019-15605
- EPSS 32.25%
- Published 07.02.2020 15:15:11
- Last modified 21.11.2024 04:29:06
HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformed
CVE-2013-4166
- EPSS 1.01%
- Published 06.02.2020 15:15:10
- Last modified 21.11.2024 01:55:00
The gpg_ctx_add_recipient function in camel/camel-gpg-context.c in GNOME Evolution 3.8.4 and earlier and Evolution Data Server 3.9.5 and earlier does not properly select the GPG key to use for email encryption, which might cause the email to be encry...