CVE-2020-6506 – chromium-browser: Insufficient policy enforcement in WebView
https://notcve.org/view.php?id=CVE-2020-6506
Insufficient policy enforcement in WebView in Google Chrome on Android prior to 83.0.4103.106 allowed a remote attacker to bypass site isolation via a crafted HTML page. Una aplicación insuficiente de políticas en WebView en Google Chrome en Android versiones anteriores a 83.0.4103.106, permitió a un atacante remoto omitir un aislamiento del sitio por medio de una página HTML diseñada • https://chromereleases.googleblog.com/2020/06/stable-channel-update-for-desktop_15.html https://crbug.com/1083819 https://lists.apache.org/thread.html/r1ab80f8591d5c2147898076e3945dad1c897513630aabec556883275%40%3Cissues.cordova.apache.org%3E https://lists.apache.org/thread.html/r1eadf38b38ee20405811958c8a01f78d6b28e058c84c9fa6c1a8663d%40%3Cissues.cordova.apache.org%3E https://lists.apache.org/thread.html/r2769c33da7f7ece7e4e31837c1e1839d6657c7c13bb8d228670b8da0%40%3Cissues.cordova.apache.org%3E https://lists.apache.org/thread.html/ra58733fbb88d5c513b3f14a14850083d506b91291 • CWE-358: Improperly Implemented Security Check for Standard •
CVE-2020-6504 – chromium-browser: Insufficient policy enforcement in notifications
https://notcve.org/view.php?id=CVE-2020-6504
Insufficient policy enforcement in notifications in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to bypass notification restrictions via a crafted HTML page. Una aplicación insuficiente de la política en notifications en Google Chrome versiones anteriores a 74.0.3729.108, permitió a un atacante remoto omitir las restricciones de notificación por medio de una página HTML diseñada • https://chromereleases.googleblog.com/2019/04/stable-channel-update-for-desktop_23.html https://crbug.com/875503 https://access.redhat.com/security/cve/CVE-2020-6504 https://bugzilla.redhat.com/show_bug.cgi?id=1844472 • CWE-276: Incorrect Default Permissions CWE-358: Improperly Implemented Security Check for Standard •
CVE-2020-6503 – chromium-browser: Inappropriate implementation in accessibility
https://notcve.org/view.php?id=CVE-2020-6503
Inappropriate implementation in accessibility in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. Una implementación inapropiada en accessibility en Google Chrome versiones anteriores a 74.0.3729.108, permitió a un atacante remoto obtener información potencialmente confidencial de la memoria del proceso por medio de una página HTML diseñada • https://chromereleases.googleblog.com/2019/04/stable-channel-update-for-desktop_23.html https://crbug.com/639322 https://access.redhat.com/security/cve/CVE-2020-6503 https://bugzilla.redhat.com/show_bug.cgi?id=1844476 • CWE-209: Generation of Error Message Containing Sensitive Information CWE-358: Improperly Implemented Security Check for Standard •
CVE-2020-6502 – chromium-browser: Incorrect security UI in permissions
https://notcve.org/view.php?id=CVE-2020-6502
Incorrect implementation in permissions in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to spoof security UI via a crafted HTML page. Una implementación incorrecta en permissions en Google Chrome versiones anteriores a 80.0.3987.87, permitió a un atacante remoto falsificar la Interfaz de Usuario de seguridad por medio de una página HTML diseñada • https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop.html https://crbug.com/785159 https://access.redhat.com/security/cve/CVE-2020-6502 https://bugzilla.redhat.com/show_bug.cgi?id=1844549 • CWE-276: Incorrect Default Permissions •
CVE-2020-6501 – chromium-browser: Insufficient policy enforcement in CSP
https://notcve.org/view.php?id=CVE-2020-6501
Insufficient policy enforcement in CSP in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass content security policy via a crafted HTML page. Una aplicación insuficiente de la política en CSP en Google Chrome versiones anteriores a 80.0.3987.87, permitió a un atacante remoto omitir la política de seguridad de contenido por medio de una página HTML diseñada • https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop.html https://crbug.com/990581 https://access.redhat.com/security/cve/CVE-2020-6501 https://bugzilla.redhat.com/show_bug.cgi?id=1844546 • CWE-276: Incorrect Default Permissions •