ALT-PU-2020-2743-1
Closed vulnerabilities
BDU:2021-01431
Уязвимость компонента audio браузера Google Chrome, связанная с использованием области памяти после её освобождения, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
BDU:2021-01432
Уязвимость компонента media браузера Google Chrome, связанная с использованием области памяти после её освобождения, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
BDU:2021-01484
Уязвимость компонента WebXR браузера Google Chrome, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
BDU:2021-01499
Уязвимость компонента scheduling браузера Google Chrome, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
BDU:2021-01500
Уязвимость компонента IndexedDB браузера Google Chrome, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
BDU:2021-01501
Уязвимость компонента media браузера Google Chrome, позволяющая нарушителю получить доступ к конфиденциальным данным
BDU:2021-01502
Уязвимость компонента media браузера Google Chrome, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
BDU:2021-01705
Уязвимость адресной строки Omnibox браузера Google Chrome, позволяющая нарушителю оказать воздействие на целостность данных
BDU:2021-01706
Уязвимость стандарта передачи данных WebRTC браузера Google Chrome, позволяющая нарушителю получить доступ к конфиденциальным данным
BDU:2021-01707
Уязвимость компонента WebUSB браузера Google Chrome, связанная с целочисленным переполнением значения, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
BDU:2021-01708
Уязвимость компонента media браузера Google Chrome, позволяющая нарушителю получить доступ к конфиденциальным данным
BDU:2021-01709
Уязвимость компонента «Разрешения» браузера Google Chrome, позволяющая нарушителю оказать воздействие на целостность данных
BDU:2021-01710
Уязвимость компонента Content Security Policy браузера Google Chrome, позволяющая нарушителю получить доступ к конфиденциальным данным
BDU:2021-01711
Уязвимость функции Автозаполнения браузера Google Chrome, позволяющая нарушителю получить доступ к конфиденциальным данным
BDU:2021-01712
Уязвимость компонента presentation API браузера Google Chrome, связанная с использованием области памяти после её освобождения, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
BDU:2021-01713
Уязвимость компонента SwiftShader браузера Google Chrome, связанная с выходом операции за допустимые границы буфера данных, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
BDU:2021-01714
Уязвимость расширений браузера Google Chrome, связанная с использованием области памяти после её освобождения, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
BDU:2021-01715
Уязвимость механизма отображения веб-страниц Blink браузера Google Chrome, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
BDU:2021-01756
Уязвимость модуля отображения Blink браузера Google Chrome, связанная с неправильным присвоением разрешений для критичного ресурса, позволяющая нарушителю оказать воздействие на целостность данных
Modified: 2024-11-21
CVE-2020-6542
Use after free in ANGLE in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop.html
- https://crbug.com/1107433
- https://crbug.com/1107433
- FEDORA-2020-6da740d38c
- FEDORA-2020-6da740d38c
- GLSA-202101-30
- GLSA-202101-30
- DSA-4824
- DSA-4824
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2020-1127
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2020-1127
Modified: 2024-11-21
CVE-2020-6543
Use after free in task scheduling in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop.html
- https://crbug.com/1104046
- https://crbug.com/1104046
- FEDORA-2020-6da740d38c
- FEDORA-2020-6da740d38c
- GLSA-202101-30
- GLSA-202101-30
- DSA-4824
- DSA-4824
Modified: 2024-11-21
CVE-2020-6544
Use after free in media in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop.html
- https://crbug.com/1108497
- https://crbug.com/1108497
- FEDORA-2020-6da740d38c
- FEDORA-2020-6da740d38c
- GLSA-202101-30
- GLSA-202101-30
- DSA-4824
- DSA-4824
Modified: 2024-11-21
CVE-2020-6545
Use after free in audio in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop.html
- https://crbug.com/1095584
- https://crbug.com/1095584
- FEDORA-2020-6da740d38c
- FEDORA-2020-6da740d38c
- GLSA-202101-30
- GLSA-202101-30
- DSA-4824
- DSA-4824
Modified: 2024-11-21
CVE-2020-6546
Inappropriate implementation in installer in Google Chrome prior to 84.0.4147.125 allowed a local attacker to potentially elevate privilege via a crafted filesystem.
Modified: 2024-11-21
CVE-2020-6547
Incorrect security UI in media in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially obtain sensitive information via a crafted HTML page.
Modified: 2024-11-21
CVE-2020-6548
Heap buffer overflow in Skia in Google Chrome prior to 84.0.4147.125 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
- https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop.html
- https://crbug.com/1103827
- https://crbug.com/1103827
- FEDORA-2020-6da740d38c
- FEDORA-2020-6da740d38c
- GLSA-202101-30
- GLSA-202101-30
- DSA-4824
- DSA-4824
Modified: 2024-11-21
CVE-2020-6549
Use after free in media in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- http://packetstormsecurity.com/files/159558/Chrome-MediaElementEventListener-UpdateSources-Use-After-Free.html
- http://packetstormsecurity.com/files/159558/Chrome-MediaElementEventListener-UpdateSources-Use-After-Free.html
- https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop.html
- https://crbug.com/1105426
- https://crbug.com/1105426
- FEDORA-2020-6da740d38c
- FEDORA-2020-6da740d38c
- GLSA-202101-30
- GLSA-202101-30
- DSA-4824
- DSA-4824
Modified: 2024-11-21
CVE-2020-6550
Use after free in IndexedDB in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- http://packetstormsecurity.com/files/159609/Chrome-WebIDBGetDBNamesCallbacksImpl-SuccessNamesAndVersionsList-Use-After-Free.html
- http://packetstormsecurity.com/files/159609/Chrome-WebIDBGetDBNamesCallbacksImpl-SuccessNamesAndVersionsList-Use-After-Free.html
- https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop.html
- https://crbug.com/1106682
- https://crbug.com/1106682
- FEDORA-2020-6da740d38c
- FEDORA-2020-6da740d38c
- GLSA-202101-30
- GLSA-202101-30
- DSA-4824
- DSA-4824
Modified: 2024-11-21
CVE-2020-6551
Use after free in WebXR in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- http://packetstormsecurity.com/files/159611/Chrome-XRSystem-FocusedFrameChanged-and-FocusController-NotifyFocusChangedObservers-Use-After-Free.html
- http://packetstormsecurity.com/files/159611/Chrome-XRSystem-FocusedFrameChanged-and-FocusController-NotifyFocusChangedObservers-Use-After-Free.html
- https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop.html
- https://crbug.com/1107815
- https://crbug.com/1107815
- FEDORA-2020-6da740d38c
- FEDORA-2020-6da740d38c
- GLSA-202101-30
- GLSA-202101-30
- DSA-4824
- DSA-4824
Modified: 2024-11-21
CVE-2020-6552
Use after free in Blink in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Modified: 2024-11-21
CVE-2020-6554
Use after free in extensions in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially perform a sandbox escape via a crafted Chrome Extension.
Modified: 2024-11-21
CVE-2020-6555
Out of bounds read in WebGL in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
- https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop.html
- https://crbug.com/1105202
- https://crbug.com/1105202
- FEDORA-2020-6da740d38c
- FEDORA-2020-6da740d38c
- GLSA-202101-30
- GLSA-202101-30
- DSA-4824
- DSA-4824
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2020-1123
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2020-1123
Modified: 2024-11-21
CVE-2020-6556
Heap buffer overflow in SwiftShader in Google Chrome prior to 84.0.4147.135 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- openSUSE-SU-2020:1713
- openSUSE-SU-2020:1713
- https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop_18.html
- https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop_18.html
- https://crbug.com/1115345
- https://crbug.com/1115345
- FEDORA-2020-6da740d38c
- FEDORA-2020-6da740d38c
- DSA-4824
- DSA-4824
Modified: 2024-11-21
CVE-2020-6558
Insufficient policy enforcement in iOSWeb in Google Chrome on iOS prior to 85.0.4183.83 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
- openSUSE-SU-2020:1499
- openSUSE-SU-2020:1499
- openSUSE-SU-2020:1510
- openSUSE-SU-2020:1510
- openSUSE-SU-2020:1514
- openSUSE-SU-2020:1514
- https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop_25.html
- https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop_25.html
- https://crbug.com/1109120
- https://crbug.com/1109120
- DSA-4824
- DSA-4824
Modified: 2024-11-21
CVE-2020-6559
Use after free in presentation API in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- openSUSE-SU-2020:1499
- openSUSE-SU-2020:1499
- openSUSE-SU-2020:1510
- openSUSE-SU-2020:1510
- openSUSE-SU-2020:1514
- openSUSE-SU-2020:1514
- https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop_25.html
- https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop_25.html
- https://crbug.com/1116706
- https://crbug.com/1116706
- FEDORA-2020-6da740d38c
- FEDORA-2020-6da740d38c
- GLSA-202101-30
- GLSA-202101-30
- DSA-4824
- DSA-4824
Modified: 2024-11-21
CVE-2020-6560
Insufficient policy enforcement in autofill in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
- openSUSE-SU-2020:1499
- openSUSE-SU-2020:1499
- openSUSE-SU-2020:1510
- openSUSE-SU-2020:1510
- openSUSE-SU-2020:1514
- openSUSE-SU-2020:1514
- https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop_25.html
- https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop_25.html
- https://crbug.com/1108181
- https://crbug.com/1108181
- FEDORA-2020-6da740d38c
- FEDORA-2020-6da740d38c
- DSA-4824
- DSA-4824
Modified: 2024-11-21
CVE-2020-6561
Inappropriate implementation in Content Security Policy in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
- openSUSE-SU-2020:1499
- openSUSE-SU-2020:1499
- openSUSE-SU-2020:1510
- openSUSE-SU-2020:1510
- openSUSE-SU-2020:1514
- openSUSE-SU-2020:1514
- https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop_25.html
- https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop_25.html
- https://crbug.com/932892
- https://crbug.com/932892
- FEDORA-2020-6da740d38c
- FEDORA-2020-6da740d38c
- GLSA-202101-30
- GLSA-202101-30
- DSA-4824
- DSA-4824
Modified: 2024-11-21
CVE-2020-6562
Insufficient policy enforcement in Blink in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
- openSUSE-SU-2020:1499
- openSUSE-SU-2020:1499
- openSUSE-SU-2020:1510
- openSUSE-SU-2020:1510
- openSUSE-SU-2020:1514
- openSUSE-SU-2020:1514
- https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop_25.html
- https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop_25.html
- https://crbug.com/1086845
- https://crbug.com/1086845
- FEDORA-2020-6da740d38c
- FEDORA-2020-6da740d38c
- GLSA-202101-30
- GLSA-202101-30
- DSA-4824
- DSA-4824
Modified: 2024-11-21
CVE-2020-6563
Insufficient policy enforcement in intent handling in Google Chrome on Android prior to 85.0.4183.83 allowed a remote attacker to obtain potentially sensitive information from disk via a crafted HTML page.
- openSUSE-SU-2020:1499
- openSUSE-SU-2020:1499
- openSUSE-SU-2020:1510
- openSUSE-SU-2020:1510
- openSUSE-SU-2020:1514
- openSUSE-SU-2020:1514
- https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop_25.html
- https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop_25.html
- https://crbug.com/1104628
- https://crbug.com/1104628
- FEDORA-2020-6da740d38c
- FEDORA-2020-6da740d38c
- DSA-4824
- DSA-4824
Modified: 2024-11-21
CVE-2020-6564
Inappropriate implementation in permissions in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to spoof the contents of a permission dialog via a crafted HTML page.
- openSUSE-SU-2020:1499
- openSUSE-SU-2020:1499
- openSUSE-SU-2020:1510
- openSUSE-SU-2020:1510
- openSUSE-SU-2020:1514
- openSUSE-SU-2020:1514
- https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop_25.html
- https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop_25.html
- https://crbug.com/841622
- https://crbug.com/841622
- FEDORA-2020-6da740d38c
- FEDORA-2020-6da740d38c
- DSA-4824
- DSA-4824
Modified: 2024-11-21
CVE-2020-6565
Inappropriate implementation in Omnibox in Google Chrome on iOS prior to 85.0.4183.83 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
- openSUSE-SU-2020:1499
- openSUSE-SU-2020:1499
- openSUSE-SU-2020:1510
- openSUSE-SU-2020:1510
- openSUSE-SU-2020:1514
- openSUSE-SU-2020:1514
- https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop_25.html
- https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop_25.html
- https://crbug.com/1029907
- https://crbug.com/1029907
- FEDORA-2020-6da740d38c
- FEDORA-2020-6da740d38c
- DSA-4824
- DSA-4824
Modified: 2024-11-21
CVE-2020-6566
Insufficient policy enforcement in media in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
- openSUSE-SU-2020:1499
- openSUSE-SU-2020:1499
- openSUSE-SU-2020:1510
- openSUSE-SU-2020:1510
- openSUSE-SU-2020:1514
- openSUSE-SU-2020:1514
- https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop_25.html
- https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop_25.html
- https://crbug.com/1065264
- https://crbug.com/1065264
- FEDORA-2020-6da740d38c
- FEDORA-2020-6da740d38c
- DSA-4824
- DSA-4824
Modified: 2024-11-21
CVE-2020-6567
Insufficient validation of untrusted input in command line handling in Google Chrome on Windows prior to 85.0.4183.83 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
- openSUSE-SU-2020:1499
- openSUSE-SU-2020:1499
- openSUSE-SU-2020:1510
- openSUSE-SU-2020:1510
- openSUSE-SU-2020:1514
- openSUSE-SU-2020:1514
- https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop_25.html
- https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop_25.html
- https://crbug.com/937179
- https://crbug.com/937179
- FEDORA-2020-6da740d38c
- FEDORA-2020-6da740d38c
- DSA-4824
- DSA-4824
Modified: 2024-11-21
CVE-2020-6568
Insufficient policy enforcement in intent handling in Google Chrome on Android prior to 85.0.4183.83 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
- openSUSE-SU-2020:1499
- openSUSE-SU-2020:1499
- openSUSE-SU-2020:1510
- openSUSE-SU-2020:1510
- openSUSE-SU-2020:1514
- openSUSE-SU-2020:1514
- https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop_25.html
- https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop_25.html
- https://crbug.com/1092451
- https://crbug.com/1092451
- FEDORA-2020-6da740d38c
- FEDORA-2020-6da740d38c
- DSA-4824
- DSA-4824
Modified: 2024-11-21
CVE-2020-6569
Integer overflow in WebUSB in Google Chrome prior to 85.0.4183.83 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
- openSUSE-SU-2020:1499
- openSUSE-SU-2020:1499
- openSUSE-SU-2020:1510
- openSUSE-SU-2020:1510
- openSUSE-SU-2020:1514
- openSUSE-SU-2020:1514
- https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop_25.html
- https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop_25.html
- https://crbug.com/995732
- https://crbug.com/995732
- FEDORA-2020-6da740d38c
- FEDORA-2020-6da740d38c
- GLSA-202101-30
- GLSA-202101-30
- DSA-4824
- DSA-4824
Modified: 2024-11-21
CVE-2020-6570
Information leakage in WebRTC in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to obtain potentially sensitive information via a crafted WebRTC interaction.
- openSUSE-SU-2020:1499
- openSUSE-SU-2020:1499
- openSUSE-SU-2020:1510
- openSUSE-SU-2020:1510
- openSUSE-SU-2020:1514
- openSUSE-SU-2020:1514
- https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop_25.html
- https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop_25.html
- https://crbug.com/1084699
- https://crbug.com/1084699
- FEDORA-2020-6da740d38c
- FEDORA-2020-6da740d38c
- GLSA-202101-30
- GLSA-202101-30
- DSA-4824
- DSA-4824
Modified: 2024-11-21
CVE-2020-6571
Insufficient data validation in Omnibox in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
- openSUSE-SU-2020:1499
- openSUSE-SU-2020:1499
- openSUSE-SU-2020:1510
- openSUSE-SU-2020:1510
- openSUSE-SU-2020:1514
- openSUSE-SU-2020:1514
- https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop_25.html
- https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop_25.html
- https://crbug.com/1085315
- https://crbug.com/1085315
- FEDORA-2020-6da740d38c
- FEDORA-2020-6da740d38c
- GLSA-202101-30
- GLSA-202101-30
- DSA-4824
- DSA-4824