CVE-2020-6516
- EPSS 3.17%
- Published 22.07.2020 17:15:13
- Last modified 21.11.2024 05:35:52
Policy bypass in CORS in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
CVE-2020-6517
- EPSS 2.4%
- Published 22.07.2020 17:15:13
- Last modified 21.11.2024 05:35:52
Heap buffer overflow in history in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2020-6518
- EPSS 3.07%
- Published 22.07.2020 17:15:13
- Last modified 21.11.2024 05:35:53
Use after free in developer tools in Google Chrome prior to 84.0.4147.89 allowed a remote attacker who had convinced the user to use developer tools to potentially exploit heap corruption via a crafted HTML page.
CVE-2020-6519
- EPSS 29.23%
- Published 22.07.2020 17:15:13
- Last modified 21.11.2024 05:35:53
Policy bypass in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass content security policy via a crafted HTML page.
CVE-2020-6520
- EPSS 2.4%
- Published 22.07.2020 17:15:13
- Last modified 21.11.2024 05:35:53
Buffer overflow in Skia in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2020-6521
- EPSS 1.65%
- Published 22.07.2020 17:15:13
- Last modified 21.11.2024 05:35:53
Side-channel information leakage in autofill in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
CVE-2020-6522
- EPSS 2.07%
- Published 22.07.2020 17:15:13
- Last modified 21.11.2024 05:35:53
Inappropriate implementation in external protocol handlers in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
CVE-2020-6523
- EPSS 3.07%
- Published 22.07.2020 17:15:13
- Last modified 21.11.2024 05:35:53
Out of bounds write in Skia in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2020-15396
- EPSS 0.07%
- Published 30.06.2020 12:15:12
- Last modified 21.11.2024 05:05:29
In HylaFAX+ through 7.0.2 and HylaFAX Enterprise, the faxsetup utility calls chown on files in user-owned directories. By winning a race, a local attacker could use this to escalate his privileges to root.
CVE-2020-8164
- EPSS 7.52%
- Published 19.06.2020 17:15:18
- Last modified 21.11.2024 05:38:25
A deserialization of untrusted data vulnerability exists in rails < 5.2.4.3, rails < 6.0.3.1 which can allow an attacker to supply information can be inadvertently leaked fromStrong Parameters.