Google Security Advisories · February 2020 — Google Security Advisories
190 advisories 120 CVEs 7 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2020-02. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 7 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

DEBIAN-CVE-2020-6418

Open SourceExploitedCISA KEV listedHIGH2020-02-27

DEBIAN-CVE-2020-6418

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

openSUSE-SU-2020:0259-1

Open SourceExploitedCISA KEV listedCRITICAL2020-02-27

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected openSUSE:Leap 15.1 chromium
Upstream advisory

openSUSE-SU-2020:0245-1

Open SourceExploitedCISA KEV listedCRITICAL2020-02-26

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 12 SP3 chromium
Upstream advisory

CVE-2020-6418

GoogleExploitedCISA KEV listedHIGH2020-02-25

Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2020-6418

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
fedora affected fedoraproject
Upstream advisory

CVE-2020-6418

Project ZeroExploitedCISA KEV listed2020-02-25

Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2020-6418

Upstream advisory

RHBA-2020:0402

Open SourceExploitedVulnCheck KEV listedHIGH2020-02-19

Red Hat Bug Fix Advisory: OpenShift Container Platform 3.11 bug fix update

Affected products

ProductStatusVendorPackageEcosystem
atomic-enterprise-service-catalog affected Red Hat:openshift:3.11::el7 atomic-enterprise-service-catalog
atomic-enterprise-service-catalog-svcat affected Red Hat:openshift:3.11::el7 atomic-enterprise-service-catalog-svcat
atomic-openshift affected Red Hat:openshift:3.11::el7 atomic-openshift
atomic-openshift-clients affected Red Hat:openshift:3.11::el7 atomic-openshift-clients
atomic-openshift-clients-redistributable affected Red Hat:openshift:3.11::el7 atomic-openshift-clients-redistributable
atomic-openshift-cluster-autoscaler affected Red Hat:openshift:3.11::el7 atomic-openshift-cluster-autoscaler
atomic-openshift-descheduler affected Red Hat:openshift:3.11::el7 atomic-openshift-descheduler
atomic-openshift-docker-excluder affected Red Hat:openshift:3.11::el7 atomic-openshift-docker-excluder
atomic-openshift-dockerregistry affected Red Hat:openshift:3.11::el7 atomic-openshift-dockerregistry
atomic-openshift-excluder affected Red Hat:openshift:3.11::el7 atomic-openshift-excluder
atomic-openshift-hyperkube affected Red Hat:openshift:3.11::el7 atomic-openshift-hyperkube
atomic-openshift-hypershift affected Red Hat:openshift:3.11::el7 atomic-openshift-hypershift
atomic-openshift-master affected Red Hat:openshift:3.11::el7 atomic-openshift-master
atomic-openshift-metrics-server affected Red Hat:openshift:3.11::el7 atomic-openshift-metrics-server
atomic-openshift-node affected Red Hat:openshift:3.11::el7 atomic-openshift-node
atomic-openshift-node-problem-detector affected Red Hat:openshift:3.11::el7 atomic-openshift-node-problem-detector
atomic-openshift-pod affected Red Hat:openshift:3.11::el7 atomic-openshift-pod
atomic-openshift-sdn-ovs affected Red Hat:openshift:3.11::el7 atomic-openshift-sdn-ovs
atomic-openshift-service-idler affected Red Hat:openshift:3.11::el7 atomic-openshift-service-idler
atomic-openshift-template-service-broker affected Red Hat:openshift:3.11::el7 atomic-openshift-template-service-broker
atomic-openshift-tests affected Red Hat:openshift:3.11::el7 atomic-openshift-tests
atomic-openshift-web-console affected Red Hat:openshift:3.11::el7 atomic-openshift-web-console
cri-o affected Red Hat:openshift:3.11::el7 cri-o
cri-o-debuginfo affected Red Hat:openshift:3.11::el7 cri-o-debuginfo
golang-github-openshift-oauth-proxy affected Red Hat:openshift:3.11::el7 golang-github-openshift-oauth-proxy
golang-github-prometheus-alertmanager affected Red Hat:openshift:3.11::el7 golang-github-prometheus-alertmanager
golang-github-prometheus-node_exporter affected Red Hat:openshift:3.11::el7 golang-github-prometheus-node_exporter
golang-github-prometheus-prometheus affected Red Hat:openshift:3.11::el7 golang-github-prometheus-prometheus
jenkins affected Red Hat:openshift:3.11::el7 jenkins
jenkins-2-plugins affected Red Hat:openshift:3.11::el7 jenkins-2-plugins
openshift-ansible affected Red Hat:openshift:3.11::el7 openshift-ansible
openshift-ansible-docs affected Red Hat:openshift:3.11::el7 openshift-ansible-docs
openshift-ansible-playbooks affected Red Hat:openshift:3.11::el7 openshift-ansible-playbooks
openshift-ansible-roles affected Red Hat:openshift:3.11::el7 openshift-ansible-roles
openshift-ansible-test affected Red Hat:openshift:3.11::el7 openshift-ansible-test
openshift-enterprise-autoheal affected Red Hat:openshift:3.11::el7 openshift-enterprise-autoheal
openshift-enterprise-cluster-capacity affected Red Hat:openshift:3.11::el7 openshift-enterprise-cluster-capacity
openshift-kuryr affected Red Hat:openshift:3.11::el7 openshift-kuryr
openshift-kuryr-cni affected Red Hat:openshift:3.11::el7 openshift-kuryr-cni
openshift-kuryr-common affected Red Hat:openshift:3.11::el7 openshift-kuryr-common
openshift-kuryr-controller affected Red Hat:openshift:3.11::el7 openshift-kuryr-controller
prometheus affected Red Hat:openshift:3.11::el7 prometheus
prometheus-alertmanager affected Red Hat:openshift:3.11::el7 prometheus-alertmanager
prometheus-node-exporter affected Red Hat:openshift:3.11::el7 prometheus-node-exporter
python2-kuryr-kubernetes affected Red Hat:openshift:3.11::el7 python2-kuryr-kubernetes
Upstream advisory

CVE-2020-9283

Open SourceWeaponized exploitHIGH2020-02-20

Improper Verification of Cryptographic Signature in golang.org/x/crypto

CVEs:CVE-2020-9283

Affected products

ProductStatusVendorPackageEcosystem
x/crypto affected golang.org golang.org/x/crypto
Upstream advisory

CVE-2020-9283

GoogleWeaponized exploitHIGH2020-02-20

golang.org/x/crypto before v0.0.0-20200220183623-bac4c82f6975 for Go allows a panic during signature verification in the golang.org/x/crypto/ssh package. A client can attack an SSH server that accepts public keys. Also, a server can attack any SSH client.

CVEs:CVE-2020-9283

Affected products

ProductStatusVendorPackageEcosystem
debian_linux affected debian
package_ssh affected golang
Upstream advisory

DEBIAN-CVE-2020-9283

Open SourceWeaponized exploitHIGH2020-02-20

DEBIAN-CVE-2020-9283

Affected products

ProductStatusVendorPackageEcosystem
golang-go.crypto affected Debian:11 golang-go.crypto
golang-go.crypto affected Debian:12 golang-go.crypto
golang-go.crypto affected Debian:13 golang-go.crypto
golang-go.crypto affected Debian:14 golang-go.crypto
Upstream advisory

openSUSE-SU-2020:0233-1

Open SourceWeaponized exploitCRITICAL2020-02-19

Security update for chromium, re2

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 12 SP3 chromium
chromium affected SUSE:Package Hub 12 chromium
re2 affected SUSE:Package Hub 12 SP3 re2
re2 affected SUSE:Package Hub 12 re2
Upstream advisory

openSUSE-SU-2020:0210-1

Open SourceWeaponized exploitCRITICAL2020-02-12

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP1 chromium
Upstream advisory

openSUSE-SU-2020:0189-1

Open SourceWeaponized exploitCRITICAL2020-02-08

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected openSUSE:Leap 15.1 chromium
Upstream advisory

CVE-2020-0022

Open SourceWeaponized exploitHIGH2020-02-04

In reassemble_and_dispatch of packet_fragmenter.cc, there is possible out of bounds write due to an incorrect bounds calculation. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction i...

CVEs:CVE-2020-0022

Affected products

ProductStatusVendorPackageEcosystem
android affected google
honor_8a_firmware affected huawei
honor_8x_firmware affected huawei
honor_view_20_firmware affected huawei
mate_20_firmware affected huawei
mate_20_pro_firmware affected huawei
mate_20_x_firmware affected huawei
mate_30_5g_firmware affected huawei
mate_30_firmware affected huawei
mate_30_pro_5g_firmware affected huawei
mate_30_pro_firmware affected huawei
nova_3_firmware affected huawei
nova_lite_3_firmware affected huawei
p20_firmware affected huawei
p20_pro_firmware affected huawei
p30_firmware affected huawei
p30_pro_firmware affected huawei
p_smart_2019_firmware affected huawei
p_smart_firmware affected huawei
y6_2019_firmware affected huawei
y6_pro_2019_firmware affected huawei
y9_2019_firmware affected huawei
Upstream advisory

DEBIAN-CVE-2020-6404

Open SourceWeaponized exploitHIGH2020-02-11

DEBIAN-CVE-2020-6404

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6404

GoogleWeaponized exploitHIGH2020-02-05

Inappropriate implementation in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2020-6404

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
fedora affected fedoraproject
package_hub affected suse
Upstream advisory

CVE-2014-7951

Open SourceWeaponized exploitHIGH2020-02-20

Directory traversal vulnerability in the Android debug bridge (aka adb) in Android 4.0.4 allows physically proximate attackers with a direct connection to the target Android device to write to arbitrary files owned by system via a .. (dot dot) in the t...

CVEs:CVE-2014-7951

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

RHBA-2020:0527

Open SourceActive exploitation (sightings)HIGH2020-02-24

Red Hat Bug Fix Advisory: OpenShift Container Platform 4.3.3 packages update

Affected products

ProductStatusVendorPackageEcosystem
atomic-enterprise-service-catalog affected Red Hat:openshift:4.3::el7 atomic-enterprise-service-catalog
atomic-enterprise-service-catalog-svcat affected Red Hat:openshift:4.3::el7 atomic-enterprise-service-catalog-svcat
atomic-openshift-service-idler affected Red Hat:openshift:4.3::el7 atomic-openshift-service-idler
cri-o affected Red Hat:openshift:4.3::el8 cri-o
cri-o affected Red Hat:openshift:4.3::el7 cri-o
cri-o-debuginfo affected Red Hat:openshift:4.3::el7 cri-o-debuginfo
cri-o-debuginfo affected Red Hat:openshift:4.3::el8 cri-o-debuginfo
cri-o-debugsource affected Red Hat:openshift:4.3::el8 cri-o-debugsource
cri-tools affected Red Hat:openshift:4.3::el8 cri-tools
dracut affected Red Hat:openshift:4.3::el8 dracut
dracut-caps affected Red Hat:openshift:4.3::el8 dracut-caps
dracut-config-generic affected Red Hat:openshift:4.3::el8 dracut-config-generic
dracut-config-rescue affected Red Hat:openshift:4.3::el8 dracut-config-rescue
dracut-debuginfo affected Red Hat:openshift:4.3::el8 dracut-debuginfo
dracut-debugsource affected Red Hat:openshift:4.3::el8 dracut-debugsource
dracut-live affected Red Hat:openshift:4.3::el8 dracut-live
dracut-network affected Red Hat:openshift:4.3::el8 dracut-network
dracut-squash affected Red Hat:openshift:4.3::el8 dracut-squash
dracut-tools affected Red Hat:openshift:4.3::el8 dracut-tools
jenkins affected Red Hat:openshift:4.3::el7 jenkins
jenkins-2-plugins affected Red Hat:openshift:4.3::el7 jenkins-2-plugins
machine-config-daemon affected Red Hat:openshift:4.3::el8 machine-config-daemon
openshift affected Red Hat:openshift:4.3::el8 openshift
openshift affected Red Hat:openshift:4.3::el7 openshift
openshift-ansible affected Red Hat:openshift:4.3::el7 openshift-ansible
openshift-ansible-test affected Red Hat:openshift:4.3::el7 openshift-ansible-test
openshift-clients affected Red Hat:openshift:4.3::el8 openshift-clients
openshift-clients affected Red Hat:openshift:4.3::el7 openshift-clients
openshift-clients-redistributable affected Red Hat:openshift:4.3::el7 openshift-clients-redistributable
openshift-clients-redistributable affected Red Hat:openshift:4.3::el8 openshift-clients-redistributable
openshift-hyperkube affected Red Hat:openshift:4.3::el7 openshift-hyperkube
openshift-hyperkube affected Red Hat:openshift:4.3::el8 openshift-hyperkube
openshift-kuryr affected Red Hat:openshift:4.3::el8 openshift-kuryr
openshift-kuryr-cni affected Red Hat:openshift:4.3::el8 openshift-kuryr-cni
openshift-kuryr-common affected Red Hat:openshift:4.3::el8 openshift-kuryr-common
openshift-kuryr-controller affected Red Hat:openshift:4.3::el8 openshift-kuryr-controller
python3-kuryr-kubernetes affected Red Hat:openshift:4.3::el8 python3-kuryr-kubernetes
slirp4netns affected Red Hat:openshift:4.3::el8 slirp4netns
slirp4netns-debuginfo affected Red Hat:openshift:4.3::el8 slirp4netns-debuginfo
slirp4netns-debugsource affected Red Hat:openshift:4.3::el8 slirp4netns-debugsource
toolbox affected Red Hat:openshift:4.3::el8 toolbox
Upstream advisory

DEBIAN-CVE-2020-8945

Open SourceActive exploitation (sightings)CRITICAL2020-02-12

DEBIAN-CVE-2020-8945

Affected products

ProductStatusVendorPackageEcosystem
golang-github-proglottis-gpgme affected Debian:11 golang-github-proglottis-gpgme
golang-github-proglottis-gpgme affected Debian:12 golang-github-proglottis-gpgme
golang-github-proglottis-gpgme affected Debian:13 golang-github-proglottis-gpgme
golang-github-proglottis-gpgme affected Debian:14 golang-github-proglottis-gpgme
Upstream advisory

MGASA-2020-0078

Open SourcePoC exploitCRITICAL2020-02-09

Updated chromium-browser-stable packages fix security vulnerability

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:7 chromium-browser-stable
Upstream advisory

DEBIAN-CVE-2020-6402

Open SourcePoC exploitCRITICAL2020-02-11

DEBIAN-CVE-2020-6402

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6402

GooglePoC exploitCRITICAL2020-02-05

Insufficient policy enforcement in downloads in Google Chrome on OS X prior to 80.0.3987.87 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension.

CVEs:CVE-2020-6402

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
fedora affected fedoraproject
package_hub affected suse
Upstream advisory

CVE-2019-11251

Open SourcePoC exploitMEDIUM2020-02-03

Kubernetes kubectl cp Vulnerable to Symlink Attack

CVEs:CVE-2019-11251

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected k8s.io k8s.io/kubernetes
Upstream advisory

CVE-2019-11251

Open SourcePoC exploitHIGH2020-02-03

The Kubernetes kubectl cp command in versions 1.1-1.12, and versions prior to 1.13.11, 1.14.7, and 1.15.4 allows a combination of two symlinks provided by tar output of a malicious container to place a file outside of the destination directory specifie...

CVEs:CVE-2019-11251

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected kubernetes
Upstream advisory

GHSA-r5fx-8r73-v86c

Open SourcePoC exploitHIGH2020-02-14

AngularJS Cross-site Scripting due to failure to sanitize `xlink.href` attributes

Affected products

ProductStatusVendorPackageEcosystem
angular affected npm
angular affected npm angular
Upstream advisory

GHSA-r5fx-8r73-v86c

Open SourcePoC exploitHIGH2020-02-14

AngularJS Cross-site Scripting due to failure to sanitize `xlink.href` attributes

Affected products

ProductStatusVendorPackageEcosystem
angular affected npm angular
Upstream advisory

CVE-2020-0014

Open SourcePoC exploitMEDIUM2020-02-04

It is possible for a malicious application to construct a TYPE_TOAST window manually and make that window clickable. This could lead to a local escalation of privilege with no additional execution privileges needed. User action is needed for exploitati...

CVEs:CVE-2020-0014

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0023

Open SourcePoC exploitMEDIUM2020-02-04

In setPhonebookAccessPermission of AdapterService.java, there is a possible disclosure of user contacts over bluetooth due to a missing permission check. This could lead to local information disclosure if a malicious app enables contacts over a bluetoo...

CVEs:CVE-2020-0023

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-6383

GoogleCoalition ESS 30-63%HIGH2020-02-27

Type confusion in V8 in Google Chrome prior to 80.0.3987.116 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2020-6383

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2020-6383

Open SourceCoalition ESS 30-63%HIGH2020-02-27

DEBIAN-CVE-2020-6383

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2020-6398

Open SourceCoalition ESS 30-63%HIGH2020-02-11

DEBIAN-CVE-2020-6398

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6398

GoogleCoalition ESS 30-63%HIGH2020-02-05

Use of uninitialized data in PDFium in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.

CVEs:CVE-2020-6398

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
fedora affected fedoraproject
package_hub affected suse
Upstream advisory

DEBIAN-CVE-2020-6390

Open SourceCoalition ESS < 30%HIGH2020-02-11

DEBIAN-CVE-2020-6390

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6390

GoogleCoalition ESS < 30%HIGH2020-02-05

Out of bounds memory access in streams in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2020-6390

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
fedora affected fedoraproject
package_hub affected suse
Upstream advisory

CVE-2020-2121

Open SourceCoalition ESS < 30%CRITICAL2020-02-12

Jenkins Google Kubernetes Engine Plugin 0.8.0 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.

CVEs:CVE-2020-2121

Affected products

ProductStatusVendorPackageEcosystem
google_kubernetes_engine affected jenkins
Upstream advisory

CVE-2020-2121

Open SourceCoalition ESS < 30%HIGH2020-02-12

RCE vulnerability in Google Kubernetes Engine Plugin

CVEs:CVE-2020-2121

Affected products

ProductStatusVendorPackageEcosystem
org.jenkins-ci.plugins:google-kubernetes-engine affected Maven org.jenkins-ci.plugins:google-kubernetes-engine
Upstream advisory

CVE-2020-0028

Open SourceCoalition ESS < 30%HIGH2020-02-04

In notifyNetworkTested and related functions of NetworkMonitor.java, there is a possible bypass of private DNS settings. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exp...

CVEs:CVE-2020-0028

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

DEBIAN-CVE-2020-6405

Open SourceCoalition ESS < 30%CRITICAL2020-02-11

DEBIAN-CVE-2020-6405

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6405

GoogleCoalition ESS < 30%CRITICAL2020-02-05

Out of bounds read in SQLite in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

CVEs:CVE-2020-6405

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2020-8595

Open SourceCoalition ESS < 30%CRITICAL2020-02-12

Istio versions 1.2.10 (End of Life) and prior, 1.3 through 1.3.7, and 1.4 through 1.4.3 allows authentication bypass. The Authentication Policy exact-path matching logic can allow unauthorized access to HTTP paths even if they are configured to be only...

CVEs:CVE-2020-8595

Affected products

ProductStatusVendorPackageEcosystem
istio affected istio
openshift_service_mesh affected redhat
Upstream advisory

DEBIAN-CVE-2020-6385

Open SourceCoalition ESS < 30%CRITICAL2020-02-11

DEBIAN-CVE-2020-6385

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6385

GoogleCoalition ESS < 30%CRITICAL2020-02-05

Insufficient policy enforcement in storage in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass site isolation via a crafted HTML page.

CVEs:CVE-2020-6385

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
fedora affected fedoraproject
package_hub affected suse
Upstream advisory

DEBIAN-CVE-2020-6382

Open SourceCoalition ESS < 30%HIGH2020-02-11

DEBIAN-CVE-2020-6382

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6382

GoogleCoalition ESS < 30%HIGH2020-02-05

Type confusion in JavaScript in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2020-6382

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
fedora affected fedoraproject
package_hub affected suse
Upstream advisory

DEBIAN-CVE-2020-6381

Open SourceCoalition ESS < 30%CRITICAL2020-02-11

DEBIAN-CVE-2020-6381

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6381

GoogleCoalition ESS < 30%CRITICAL2020-02-05

Integer overflow in JavaScript in Google Chrome on ChromeOS and Android prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2020-6381

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
fedora affected fedoraproject
package_hub affected suse
Upstream advisory

DEBIAN-CVE-2020-6388

Open SourceCoalition ESS < 30%HIGH2020-02-11

DEBIAN-CVE-2020-6388

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
chromium affected Debian:12 chromium
Upstream advisory

CVE-2020-6388

GoogleCoalition ESS < 30%HIGH2020-02-05

Out of bounds access in WebAudio in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2020-6388

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2020-6400

Open SourceCoalition ESS < 30%MEDIUM2020-02-11

DEBIAN-CVE-2020-6400

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6400

GoogleCoalition ESS < 30%MEDIUM2020-02-05

Inappropriate implementation in CORS in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVEs:CVE-2020-6400

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
fedora affected fedoraproject
package_hub affected suse
Upstream advisory

DEBIAN-CVE-2020-6415

Open SourceCoalition ESS < 30%HIGH2020-02-11

DEBIAN-CVE-2020-6415

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2020-6416

Open SourceCoalition ESS < 30%HIGH2020-02-11

DEBIAN-CVE-2020-6416

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6415

GoogleCoalition ESS < 30%HIGH2020-02-05

Inappropriate implementation in JavaScript in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2020-6415

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
fedora affected fedoraproject
package_hub affected suse
Upstream advisory

CVE-2020-6416

GoogleCoalition ESS < 30%HIGH2020-02-05

Insufficient data validation in streams in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2020-6416

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
fedora affected fedoraproject
package_hub affected suse
Upstream advisory

DEBIAN-CVE-2020-6399

Open SourceCoalition ESS < 30%CRITICAL2020-02-11

DEBIAN-CVE-2020-6399

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6399

GoogleCoalition ESS < 30%CRITICAL2020-02-05

Insufficient policy enforcement in AppCache in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVEs:CVE-2020-6399

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
Upstream advisory

DEBIAN-CVE-2020-6395

Open SourceCoalition ESS < 30%HIGH2020-02-11

DEBIAN-CVE-2020-6395

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6395

GoogleCoalition ESS < 30%HIGH2020-02-05

Out of bounds read in JavaScript in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

CVEs:CVE-2020-6395

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2020-6401

Open SourceCoalition ESS < 30%MEDIUM2020-02-11

DEBIAN-CVE-2020-6401

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6401

GoogleCoalition ESS < 30%MEDIUM2020-02-05

Insufficient validation of untrusted input in Omnibox in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.

CVEs:CVE-2020-6401

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
Upstream advisory

DEBIAN-CVE-2020-6397

Open SourceCoalition ESS < 30%MEDIUM2020-02-11

DEBIAN-CVE-2020-6397

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6397

GoogleCoalition ESS < 30%MEDIUM2020-02-05

Inappropriate implementation in sharing in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to spoof security UI via a crafted HTML page.

CVEs:CVE-2020-6397

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
fedora affected fedoraproject
package_hub affected suse
Upstream advisory

DEBIAN-CVE-2020-6413

Open SourceCoalition ESS < 30%HIGH2020-02-11

DEBIAN-CVE-2020-6413

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6413

GoogleCoalition ESS < 30%HIGH2020-02-05

Inappropriate implementation in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass HTML validators via a crafted HTML page.

CVEs:CVE-2020-6413

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
Upstream advisory

DEBIAN-CVE-2020-6414

Open SourceCoalition ESS < 30%CRITICAL2020-02-11

DEBIAN-CVE-2020-6414

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6414

GoogleCoalition ESS < 30%CRITICAL2020-02-05

Insufficient policy enforcement in Safe Browsing in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

CVEs:CVE-2020-6414

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
Upstream advisory

DEBIAN-CVE-2020-6393

Open SourceCoalition ESS < 30%CRITICAL2020-02-11

DEBIAN-CVE-2020-6393

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6393

GoogleCoalition ESS < 30%CRITICAL2020-02-05

Insufficient policy enforcement in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVEs:CVE-2020-6393

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
fedora affected fedoraproject
package_hub affected suse
Upstream advisory

DEBIAN-CVE-2020-6406

Open SourceCoalition ESS < 30%CRITICAL2020-02-11

DEBIAN-CVE-2020-6406

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6406

GoogleCoalition ESS < 30%CRITICAL2020-02-05

Use after free in audio in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2020-6406

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
fedora affected fedoraproject
package_hub affected suse
Upstream advisory

DEBIAN-CVE-2020-6387

Open SourceCoalition ESS < 30%CRITICAL2020-02-11

DEBIAN-CVE-2020-6387

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6387

GoogleCoalition ESS < 30%CRITICAL2020-02-05

Out of bounds write in WebRTC in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted video stream.

CVEs:CVE-2020-6387

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2020-6407

Open SourceCoalition ESS < 30%HIGH2020-02-27

DEBIAN-CVE-2020-6407

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6407

GoogleCoalition ESS < 30%HIGH2020-02-25

Out of bounds memory access in streams in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2020-6407

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2020-6409

Open SourceCoalition ESS < 30%HIGH2020-02-11

DEBIAN-CVE-2020-6409

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2020-6389

Open SourceCoalition ESS < 30%CRITICAL2020-02-11

DEBIAN-CVE-2020-6389

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6389

GoogleCoalition ESS < 30%CRITICAL2020-02-05

Out of bounds write in WebRTC in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted video stream.

CVEs:CVE-2020-6389

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2020-6409

GoogleCoalition ESS < 30%HIGH2020-02-05

Inappropriate implementation in Omnibox in Google Chrome prior to 80.0.3987.87 allowed a remote attacker who convinced the user to enter a URI to bypass navigation restrictions via a crafted domain name.

CVEs:CVE-2020-6409

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2020-6396

Open SourceCoalition ESS < 30%MEDIUM2020-02-11

DEBIAN-CVE-2020-6396

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
chromium affected Debian:11 chromium
chromium affected Debian:14 chromium
chromium affected Debian:13 chromium
Upstream advisory

CVE-2020-6396

GoogleCoalition ESS < 30%MEDIUM2020-02-05

Inappropriate implementation in Skia in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

CVEs:CVE-2020-6396

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
fedora affected fedoraproject
package_hub affected suse
Upstream advisory

CVE-2020-6386

GoogleCoalition ESS < 30%CRITICAL2020-02-27

Use after free in speech in Google Chrome prior to 80.0.3987.116 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2020-6386

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2020-6386

Open SourceCoalition ESS < 30%CRITICAL2020-02-27

DEBIAN-CVE-2020-6386

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
chromium affected Debian:12 chromium
Upstream advisory

DEBIAN-CVE-2020-6410

Open SourceCoalition ESS < 30%CRITICAL2020-02-11

DEBIAN-CVE-2020-6410

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6410

GoogleCoalition ESS < 30%CRITICAL2020-02-05

Insufficient policy enforcement in navigation in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to confuse the user via a crafted domain name.

CVEs:CVE-2020-6410

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2020-6384

GoogleCoalition ESS < 30%CRITICAL2020-02-27

Use after free in WebAudio in Google Chrome prior to 80.0.3987.116 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2020-6384

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2020-6384

Open SourceCoalition ESS < 30%CRITICAL2020-02-27

DEBIAN-CVE-2020-6384

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2020-6394

Open SourceCoalition ESS < 30%CRITICAL2020-02-11

DEBIAN-CVE-2020-6394

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6394

GoogleCoalition ESS < 30%CRITICAL2020-02-05

Insufficient policy enforcement in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass content security policy via a crafted HTML page.

CVEs:CVE-2020-6394

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
fedora affected fedoraproject
package_hub affected suse
Upstream advisory

DEBIAN-CVE-2020-6408

Open SourceCoalition ESS < 30%HIGH2020-02-11

DEBIAN-CVE-2020-6408

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6408

GoogleCoalition ESS < 30%HIGH2020-02-05

Insufficient policy enforcement in CORS in Google Chrome prior to 80.0.3987.87 allowed a local attacker to obtain potentially sensitive information via a crafted HTML page.

CVEs:CVE-2020-6408

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
fedora affected fedoraproject
package_hub affected suse
Upstream advisory

DEBIAN-CVE-2020-6403

Open SourceCoalition ESS < 30%MEDIUM2020-02-11

DEBIAN-CVE-2020-6403

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6403

GoogleCoalition ESS < 30%MEDIUM2020-02-05

Incorrect implementation in Omnibox in Google Chrome on iOS prior to 80.0.3987.87 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

CVEs:CVE-2020-6403

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
fedora affected fedoraproject
package_hub affected suse
Upstream advisory

DEBIAN-CVE-2020-6412

Open SourceCoalition ESS < 30%MEDIUM2020-02-11

DEBIAN-CVE-2020-6412

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6412

GoogleCoalition ESS < 30%MEDIUM2020-02-05

Insufficient validation of untrusted input in Omnibox in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.

CVEs:CVE-2020-6412

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
Upstream advisory

DEBIAN-CVE-2020-6392

Open SourceCoalition ESS < 30%CRITICAL2020-02-11

DEBIAN-CVE-2020-6392

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
chromium affected Debian:12 chromium
Upstream advisory

CVE-2020-6392

GoogleCoalition ESS < 30%CRITICAL2020-02-05

Insufficient policy enforcement in extensions in Google Chrome prior to 80.0.3987.87 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension.

CVEs:CVE-2020-6392

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
fedora affected fedoraproject
package_hub affected suse
Upstream advisory

DEBIAN-CVE-2020-6411

Open SourceCoalition ESS < 30%MEDIUM2020-02-11

DEBIAN-CVE-2020-6411

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6411

GoogleCoalition ESS < 30%MEDIUM2020-02-05

Insufficient validation of untrusted input in Omnibox in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.

CVEs:CVE-2020-6411

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2020-6391

Open SourceCoalition ESS < 30%MEDIUM2020-02-11

DEBIAN-CVE-2020-6391

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6391

GoogleCoalition ESS < 30%MEDIUM2020-02-05

Insufficient validation of untrusted input in Blink in Google Chrome prior to 80.0.3987.87 allowed a local attacker to bypass content security policy via a crafted HTML page.

CVEs:CVE-2020-6391

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
fedora affected fedoraproject
package_hub affected suse
Upstream advisory

DEBIAN-CVE-2020-6378

Open SourceCoalition ESS < 30%CRITICAL2020-02-11

DEBIAN-CVE-2020-6378

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2020-6380

Open SourceCoalition ESS < 30%CRITICAL2020-02-11

DEBIAN-CVE-2020-6380

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2020-6379

Open SourceCoalition ESS < 30%CRITICAL2020-02-11

DEBIAN-CVE-2020-6379

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:14 chromium
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
Upstream advisory

CVE-2020-8843

Open SourceCoalition ESS < 30%CRITICAL2020-02-14

An issue was discovered in Istio 1.3 through 1.3.6. Under certain circumstances, it is possible to bypass a specifically configured Mixer policy. Istio-proxy accepts the x-istio-attributes header at ingress that can be used to affect policy decisions w...

CVEs:CVE-2020-8843

Affected products

ProductStatusVendorPackageEcosystem
istio affected istio
Upstream advisory

CVE-2020-0021

Open SourceCoalition ESS < 30%MEDIUM2020-02-04

In removeUnusedPackagesLPw of PackageManagerService.java, there is a possible permanent denial-of-service due to a missing package dependency test. This could lead to remote denial of service with User execution privileges needed. User interaction is n...

CVEs:CVE-2020-0021

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-9447

GoogleCoalition ESS < 30%MEDIUM2020-02-28

Cross-site Scripting in GwtUpload

CVEs:CVE-2020-9447

Affected products

ProductStatusVendorPackageEcosystem
com.googlecode.gwtupload:gwtupload affected Maven com.googlecode.gwtupload:gwtupload
Upstream advisory

CVE-2020-9447

GoogleCoalition ESS < 30%CRITICAL2020-02-28

There is an XSS (cross-site scripting) vulnerability in GwtUpload 1.0.3 in the file upload functionality. Someone can upload a file with a malicious filename, which contains JavaScript code, which would result in XSS. Cross-site scripting enables attac...

CVEs:CVE-2020-9447

Affected products

ProductStatusVendorPackageEcosystem
gwtupload affected gwtupload_project
Upstream advisory

CVE-2020-8860

Open SourceCoalition ESS < 30%HIGH2020-02-20

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Samsung Galaxy S10 Firmware G973FXXS3ASJA, O(8.x), P(9.0), Q(10.0) devices with Exynos chipsets. User interaction is required to exploit this vulnerabilit...

CVEs:CVE-2020-8860

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-6417

GoogleCoalition ESS < 30%HIGH2020-02-05

Inappropriate implementation in installer in Google Chrome prior to 80.0.3987.87 allowed a local attacker to execute arbitrary code via a crafted registry entry.

CVEs:CVE-2020-6417

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2019-19273

Open SourceCoalition ESS < 30%HIGH2020-02-04

On Samsung mobile devices with O(8.0) and P(9.0) software and an Exynos 8895 chipset, RKP (aka the Samsung Hypervisor EL2 implementation) allows arbitrary memory write operations. The Samsung ID is SVE-2019-16265.

CVEs:CVE-2019-19273

Affected products

ProductStatusVendorPackageEcosystem
android affected google
exynos_8895 affected samsung
Upstream advisory

CVE-2019-2200

Open SourceCoalition ESS < 30%HIGH2020-02-04

In updatePermissions of PermissionManagerService.java, it may be possible for a malicious app to obtain a custom permission from another app due to a permission bypass. This could lead to local escalation of privilege with User execution privileges nee...

CVEs:CVE-2019-2200

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0027

Open SourceCoalition ESS < 30%HIGH2020-02-04

In HidRawSensor::batch of HidRawSensor.cpp, there is a possible out of bounds write due to an unexpected switch fallthrough. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed...

CVEs:CVE-2020-0027

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0005

Open SourceCoalition ESS < 30%HIGH2020-02-04

In btm_read_remote_ext_features_complete of btm_acl.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for ...

CVEs:CVE-2020-0005

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0017

Open SourceCoalition ESS < 30%MEDIUM2020-02-04

In multiple places, it was possible for the primary user’s dictionary to be visible to and modifiable by secondary users. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for e...

CVEs:CVE-2020-0017

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0026

Open SourceCoalition ESS < 30%HIGH2020-02-04

In Parcel::continueWrite of Parcel.cpp, there is possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Produc...

CVEs:CVE-2020-0026

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0015

Open SourceCoalition ESS < 30%HIGH2020-02-04

In onCreate of CertInstaller.java, there is a possible way to overlay the Certificate Installation dialog by a malicious application. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is n...

CVEs:CVE-2020-0015

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0018

Open SourceCoalition ESS < 30%MEDIUM2020-02-04

In MotionEntry::appendDescription of InputDispatcher.cpp, there is a possible log information disclosure. This could lead to local disclosure of user input with System execution privileges needed. User interaction is not needed for exploitation.Product...

CVEs:CVE-2020-0018

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0030

Open SourceCoalition ESS < 30%HIGH2020-02-04

In binder_thread_release of binder.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: ...

CVEs:CVE-2020-0030

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0020

Open SourceCoalition ESS < 30%MEDIUM2020-02-04

In getAttributeRange of ExifInterface.java, there is a possible failure to redact location information from media files due to an incorrect bounds check. This could lead to local information disclosure with User execution privileges needed. User intera...

CVEs:CVE-2020-0020

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-0565

GoogleEPSS <= 49%CRITICAL2020-02-25

NaCl in 2015 allowed the CLFLUSH instruction, making rowhammer attacks possible.

CVEs:CVE-2015-0565

Affected products

ProductStatusVendorPackageEcosystem
native_client affected google
Upstream advisory

AZL-78996

Open SourceEPSS <= 49%CRITICAL2020-02-08

CVE-2015-5741 affecting package golang 1.25.7-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

CVE-2014-7224

Open SourceEPSS <= 49%CRITICAL2020-02-07

A Code Execution vulnerability exists in Android prior to 4.4.0 related to the addJavascriptInterface method and the accessibility and accessibilityTraversal objects, which could let a remote malicious user execute arbitrary code.

CVEs:CVE-2014-7224

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2010-3917

GoogleEPSS <= 49%HIGH2020-02-06

Google Chrome before 3.0 does not properly handle XML documents, which allows remote attackers to obtain sensitive information via a crafted web site.

CVEs:CVE-2010-3917

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-3901

Open SourceEPSS <= 49%CRITICAL2020-02-12

Android SQLite Journal before 4.0.1 has an information disclosure vulnerability.

CVEs:CVE-2011-3901

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-7914

Open SourceEPSS <= 49%CRITICAL2020-02-21

btif/src/btif_dm.c in Android before 5.1 does not properly enforce the temporary nature of a Bluetooth pairing, which allows user-assisted remote attackers to bypass intended access restrictions via crafted Bluetooth packets after the tapping of a craf...

CVEs:CVE-2014-7914

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2009-5139

GoogleEPSS <= 49%CRITICAL2020-02-12

The SIP implementation on the Gizmo5 software phone provides hashed credentials in a response to an invalid authentication challenge, which makes it easier for remote attackers to obtain access via a brute-force attack, related to a "SIP Digest Leak" i...

CVEs:CVE-2009-5139

Affected products

ProductStatusVendorPackageEcosystem
gizmo5 affected google
Upstream advisory

CVE-2011-2343

Open SourceEPSS <= 49%LOW2020-02-12

The Bluetooth stack in Android before 2.3.6 allows a physically proximate attacker to obtain contact information via an AT phonebook transfer.

CVEs:CVE-2011-2343

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.