CVE-2020-6507 – Google Chrome 81.0.4044 V8 - Remote Code Execution
https://notcve.org/view.php?id=CVE-2020-6507
Out of bounds write in V8 in Google Chrome prior to 83.0.4103.106 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Una escritura fuera de límites en V8 en Google Chrome versiones anteriores a 83.0.4103.106, permitió a un atacante remoto explotar potencialmente una corrupción de la pila por medio de una página HTML diseñada • https://www.exploit-db.com/exploits/49746 http://packetstormsecurity.com/files/162088/Google-Chrome-81.0.4044-V8-Remote-Code-Execution.html http://packetstormsecurity.com/files/162105/Google-Chrome-81.0.4044-V8-Remote-Code-Execution.html https://chromereleases.googleblog.com/2020/06/stable-channel-update-for-desktop_15.html https://crbug.com/1086890 https://security.gentoo.org/glsa/202007-08 https://access.redhat.com/security/cve/CVE-2020-6507 https://bugzilla.redhat.com/show_bug.cgi?id • CWE-20: Improper Input Validation CWE-787: Out-of-bounds Write •
CVE-2020-6504 – chromium-browser: Insufficient policy enforcement in notifications
https://notcve.org/view.php?id=CVE-2020-6504
Insufficient policy enforcement in notifications in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to bypass notification restrictions via a crafted HTML page. Una aplicación insuficiente de la política en notifications en Google Chrome versiones anteriores a 74.0.3729.108, permitió a un atacante remoto omitir las restricciones de notificación por medio de una página HTML diseñada • https://chromereleases.googleblog.com/2019/04/stable-channel-update-for-desktop_23.html https://crbug.com/875503 https://access.redhat.com/security/cve/CVE-2020-6504 https://bugzilla.redhat.com/show_bug.cgi?id=1844472 • CWE-276: Incorrect Default Permissions CWE-358: Improperly Implemented Security Check for Standard •
CVE-2020-6503 – chromium-browser: Inappropriate implementation in accessibility
https://notcve.org/view.php?id=CVE-2020-6503
Inappropriate implementation in accessibility in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. Una implementación inapropiada en accessibility en Google Chrome versiones anteriores a 74.0.3729.108, permitió a un atacante remoto obtener información potencialmente confidencial de la memoria del proceso por medio de una página HTML diseñada • https://chromereleases.googleblog.com/2019/04/stable-channel-update-for-desktop_23.html https://crbug.com/639322 https://access.redhat.com/security/cve/CVE-2020-6503 https://bugzilla.redhat.com/show_bug.cgi?id=1844476 • CWE-209: Generation of Error Message Containing Sensitive Information CWE-358: Improperly Implemented Security Check for Standard •
CVE-2020-6502 – chromium-browser: Incorrect security UI in permissions
https://notcve.org/view.php?id=CVE-2020-6502
Incorrect implementation in permissions in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to spoof security UI via a crafted HTML page. Una implementación incorrecta en permissions en Google Chrome versiones anteriores a 80.0.3987.87, permitió a un atacante remoto falsificar la Interfaz de Usuario de seguridad por medio de una página HTML diseñada • https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop.html https://crbug.com/785159 https://access.redhat.com/security/cve/CVE-2020-6502 https://bugzilla.redhat.com/show_bug.cgi?id=1844549 • CWE-276: Incorrect Default Permissions •
CVE-2020-6501 – chromium-browser: Insufficient policy enforcement in CSP
https://notcve.org/view.php?id=CVE-2020-6501
Insufficient policy enforcement in CSP in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass content security policy via a crafted HTML page. Una aplicación insuficiente de la política en CSP en Google Chrome versiones anteriores a 80.0.3987.87, permitió a un atacante remoto omitir la política de seguridad de contenido por medio de una página HTML diseñada • https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop.html https://crbug.com/990581 https://access.redhat.com/security/cve/CVE-2020-6501 https://bugzilla.redhat.com/show_bug.cgi?id=1844546 • CWE-276: Incorrect Default Permissions •