CVE-2020-6504 – chromium-browser: Insufficient policy enforcement in notifications
https://notcve.org/view.php?id=CVE-2020-6504
Insufficient policy enforcement in notifications in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to bypass notification restrictions via a crafted HTML page. Una aplicación insuficiente de la política en notifications en Google Chrome versiones anteriores a 74.0.3729.108, permitió a un atacante remoto omitir las restricciones de notificación por medio de una página HTML diseñada • https://chromereleases.googleblog.com/2019/04/stable-channel-update-for-desktop_23.html https://crbug.com/875503 https://access.redhat.com/security/cve/CVE-2020-6504 https://bugzilla.redhat.com/show_bug.cgi?id=1844472 • CWE-276: Incorrect Default Permissions CWE-358: Improperly Implemented Security Check for Standard •
CVE-2020-6502 – chromium-browser: Incorrect security UI in permissions
https://notcve.org/view.php?id=CVE-2020-6502
Incorrect implementation in permissions in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to spoof security UI via a crafted HTML page. Una implementación incorrecta en permissions en Google Chrome versiones anteriores a 80.0.3987.87, permitió a un atacante remoto falsificar la Interfaz de Usuario de seguridad por medio de una página HTML diseñada • https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop.html https://crbug.com/785159 https://access.redhat.com/security/cve/CVE-2020-6502 https://bugzilla.redhat.com/show_bug.cgi?id=1844549 • CWE-276: Incorrect Default Permissions •
CVE-2020-6503 – chromium-browser: Inappropriate implementation in accessibility
https://notcve.org/view.php?id=CVE-2020-6503
Inappropriate implementation in accessibility in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. Una implementación inapropiada en accessibility en Google Chrome versiones anteriores a 74.0.3729.108, permitió a un atacante remoto obtener información potencialmente confidencial de la memoria del proceso por medio de una página HTML diseñada • https://chromereleases.googleblog.com/2019/04/stable-channel-update-for-desktop_23.html https://crbug.com/639322 https://access.redhat.com/security/cve/CVE-2020-6503 https://bugzilla.redhat.com/show_bug.cgi?id=1844476 • CWE-209: Generation of Error Message Containing Sensitive Information CWE-358: Improperly Implemented Security Check for Standard •
CVE-2020-6501 – chromium-browser: Insufficient policy enforcement in CSP
https://notcve.org/view.php?id=CVE-2020-6501
Insufficient policy enforcement in CSP in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass content security policy via a crafted HTML page. Una aplicación insuficiente de la política en CSP en Google Chrome versiones anteriores a 80.0.3987.87, permitió a un atacante remoto omitir la política de seguridad de contenido por medio de una página HTML diseñada • https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop.html https://crbug.com/990581 https://access.redhat.com/security/cve/CVE-2020-6501 https://bugzilla.redhat.com/show_bug.cgi?id=1844546 • CWE-276: Incorrect Default Permissions •
CVE-2020-6500 – chromium-browser: Inappropriate implementation in interstitials
https://notcve.org/view.php?id=CVE-2020-6500
Inappropriate implementation in interstitials in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. Una implementación inapropiada en interstitials en Google Chrome versiones anteriores a 80.0.3987.87, permitió a un atacante remoto falsificar el contenido del Omnibox (barra de URL) por medio de una página HTML diseñada • https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop.html https://crbug.com/843095 https://access.redhat.com/security/cve/CVE-2020-6500 https://bugzilla.redhat.com/show_bug.cgi?id=1844542 •