CVE-2020-6517
- EPSS 2.4%
- Veröffentlicht 22.07.2020 17:15:13
- Zuletzt bearbeitet 21.11.2024 05:35:52
Heap buffer overflow in history in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2020-6518
- EPSS 3.07%
- Veröffentlicht 22.07.2020 17:15:13
- Zuletzt bearbeitet 21.11.2024 05:35:53
Use after free in developer tools in Google Chrome prior to 84.0.4147.89 allowed a remote attacker who had convinced the user to use developer tools to potentially exploit heap corruption via a crafted HTML page.
CVE-2020-6519
- EPSS 29.23%
- Veröffentlicht 22.07.2020 17:15:13
- Zuletzt bearbeitet 21.11.2024 05:35:53
Policy bypass in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass content security policy via a crafted HTML page.
CVE-2020-6520
- EPSS 2.4%
- Veröffentlicht 22.07.2020 17:15:13
- Zuletzt bearbeitet 21.11.2024 05:35:53
Buffer overflow in Skia in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2020-6521
- EPSS 1.65%
- Veröffentlicht 22.07.2020 17:15:13
- Zuletzt bearbeitet 21.11.2024 05:35:53
Side-channel information leakage in autofill in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
CVE-2020-6522
- EPSS 2.07%
- Veröffentlicht 22.07.2020 17:15:13
- Zuletzt bearbeitet 21.11.2024 05:35:53
Inappropriate implementation in external protocol handlers in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
CVE-2020-6523
- EPSS 3.07%
- Veröffentlicht 22.07.2020 17:15:13
- Zuletzt bearbeitet 21.11.2024 05:35:53
Out of bounds write in Skia in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2020-15890
- EPSS 0.98%
- Veröffentlicht 21.07.2020 22:15:12
- Zuletzt bearbeitet 21.11.2024 05:06:23
LuaJit through 2.1.0-beta3 has an out-of-bounds read because __gc handler frame traversal is mishandled.
CVE-2020-15859
- EPSS 0.03%
- Veröffentlicht 21.07.2020 16:15:11
- Zuletzt bearbeitet 21.11.2024 05:06:19
QEMU 4.2.0 has a use-after-free in hw/net/e1000e_core.c because a guest OS user can trigger an e1000e packet with the data's address set to the e1000e's MMIO address.
CVE-2020-15866
- EPSS 0.6%
- Veröffentlicht 21.07.2020 15:15:14
- Zuletzt bearbeitet 21.11.2024 05:06:20
mruby through 2.1.2-rc has a heap-based buffer overflow in the mrb_yield_with_class function in vm.c because of incorrect VM stack handling. It can be triggered via the stack_copy function.