CVE-2020-13113
- EPSS 0.7%
- Veröffentlicht 21.05.2020 17:15:10
- Zuletzt bearbeitet 21.11.2024 05:00:40
An issue was discovered in libexif before 0.6.22. Use of uninitialized memory in EXIF Makernote handling could lead to crashes and potential use-after-free conditions.
CVE-2020-13112
- EPSS 0.98%
- Veröffentlicht 21.05.2020 16:15:10
- Zuletzt bearbeitet 21.11.2024 05:00:40
An issue was discovered in libexif before 0.6.22. Several buffer over-reads in EXIF MakerNote handling could lead to information disclosure and crashes. This is different from CVE-2020-0093.
CVE-2020-6487
- EPSS 0.69%
- Veröffentlicht 21.05.2020 04:15:14
- Zuletzt bearbeitet 21.11.2024 05:35:49
Insufficient policy enforcement in downloads in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
CVE-2020-6488
- EPSS 0.61%
- Veröffentlicht 21.05.2020 04:15:14
- Zuletzt bearbeitet 21.11.2024 05:35:49
Insufficient policy enforcement in downloads in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
CVE-2020-6489
- EPSS 1.04%
- Veröffentlicht 21.05.2020 04:15:14
- Zuletzt bearbeitet 21.11.2024 05:35:49
Inappropriate implementation in developer tools in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had convinced the user to take certain actions in developer tools to obtain potentially sensitive information from disk via a crafted...
CVE-2020-6490
- EPSS 1.04%
- Veröffentlicht 21.05.2020 04:15:14
- Zuletzt bearbeitet 21.11.2024 05:35:49
Insufficient data validation in loader in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had been able to write to disk to leak cross-origin data via a crafted HTML page.
CVE-2020-6491
- EPSS 0.91%
- Veröffentlicht 21.05.2020 04:15:14
- Zuletzt bearbeitet 21.11.2024 05:35:50
Insufficient data validation in site information in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to spoof security UI via a crafted domain name.
CVE-2020-6479
- EPSS 0.91%
- Veröffentlicht 21.05.2020 04:15:13
- Zuletzt bearbeitet 21.11.2024 05:35:48
Inappropriate implementation in sharing in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to spoof security UI via a crafted HTML page.
CVE-2020-6480
- EPSS 0.5%
- Veröffentlicht 21.05.2020 04:15:13
- Zuletzt bearbeitet 21.11.2024 05:35:48
Insufficient policy enforcement in enterprise in Google Chrome prior to 83.0.4103.61 allowed a local attacker to bypass navigation restrictions via UI actions.
CVE-2020-6481
- EPSS 1.41%
- Veröffentlicht 21.05.2020 04:15:13
- Zuletzt bearbeitet 21.11.2024 05:35:48
Insufficient policy enforcement in URL formatting in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to perform domain spoofing via a crafted domain name.