Show filters
768 Total Results
Displaying 51-60 of 768
Sort by:
Attacker Value
Unknown

CVE-2020-15965

Disclosure Date: September 21, 2020 (last updated February 22, 2025)
Type confusion in V8 in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
Attacker Value
Unknown

CVE-2020-6564

Disclosure Date: September 21, 2020 (last updated February 22, 2025)
Inappropriate implementation in permissions in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to spoof the contents of a permission dialog via a crafted HTML page.
Attacker Value
Unknown

CVE-2020-6571

Disclosure Date: September 21, 2020 (last updated February 22, 2025)
Insufficient data validation in Omnibox in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
Attacker Value
Unknown

CVE-2020-6573

Disclosure Date: September 21, 2020 (last updated February 22, 2025)
Use after free in video in Google Chrome on Android prior to 85.0.4183.102 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Attacker Value
Unknown

CVE-2020-6568

Disclosure Date: September 21, 2020 (last updated February 22, 2025)
Insufficient policy enforcement in intent handling in Google Chrome on Android prior to 85.0.4183.83 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
Attacker Value
Unknown

CVE-2020-6566

Disclosure Date: September 21, 2020 (last updated February 22, 2025)
Insufficient policy enforcement in media in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Attacker Value
Unknown

CVE-2020-15964

Disclosure Date: September 21, 2020 (last updated February 22, 2025)
Insufficient data validation in media in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Attacker Value
Unknown

CVE-2020-25032

Disclosure Date: August 31, 2020 (last updated February 22, 2025)
An issue was discovered in Flask-CORS (aka CORS Middleware for Flask) before 3.0.9. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnames are in a canonical format.
Attacker Value
Unknown

CVE-2020-14352

Disclosure Date: August 30, 2020 (last updated February 22, 2025)
A flaw was found in librepo in versions before 1.12.1. A directory traversal vulnerability was found where it failed to sanitize paths in remote repository metadata. An attacker controlling a remote repository may be able to copy files outside of the destination directory on the targeted system via path traversal. This flaw could potentially result in system compromise via the overwriting of critical system files. The highest threat from this flaw is to users that make use of untrusted third-party repositories.
Attacker Value
Unknown

CVE-2020-24972

Disclosure Date: August 29, 2020 (last updated February 22, 2025)
The Kleopatra component before 3.1.12 (and before 20.07.80) for GnuPG allows remote attackers to execute arbitrary code because openpgp4fpr: URLs are supported without safe handling of command-line options. The Qt platformpluginpath command-line option can be used to load an arbitrary DLL.