Unknown · CVSS Not scored
Use after free in password manager in Google Chrome prior to 86.0.4240.75 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Published Nov 3, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Insufficient policy enforcement in ANGLE in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published Nov 3, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Use after free in media in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published Nov 3, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Stack buffer overflow in WebRTC in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit stack corruption via a crafted WebRTC packet.
Published Nov 3, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Use after free in PDFium in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
Published Nov 3, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Use after free in USB in Google Chrome prior to 86.0.4240.99 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Published Nov 3, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Use after free in WebRTC in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted WebRTC stream.
Published Nov 3, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Use after free in printing in Google Chrome prior to 86.0.4240.75 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Published Nov 3, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Insufficient data validation in installer in Google Chrome prior to 86.0.4240.183 allowed a local attacker to potentially elevate privilege via a crafted filesystem.
Published Nov 3, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Inappropriate implementation in Blink in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published Nov 3, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Immuta v2.8.2 accepts user-supplied project names without properly sanitizing the input, allowing attackers to inject arbitrary HTML content that is rendered as part of the application. An attacker could leverage this to redirect application users to a phishing website in an attempt to steal credentials.
Published Nov 5, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Use after free in printing in Google Chrome prior to 86.0.4240.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published Nov 3, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Heap buffer overflow in UI in Google Chrome on Windows prior to 86.0.4240.183 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Published Nov 3, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published Nov 3, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Inappropriate implementation in cache in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
Published Nov 3, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Insufficient policy enforcement in extensions in Google Chrome prior to 86.0.4240.75 allowed an attacker who convinced a user to install a malicious extension to bypass same origin policy via a crafted Chrome Extension.
Published Nov 3, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Use after free in printing in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published Nov 3, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Use after free in payments in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
Published Nov 3, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Integer overflow in media in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published Nov 3, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Use after free in V8 in Google Chrome prior to 86.0.4240.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published Nov 3, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Integer overflow in SwiftShader in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published Nov 3, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Inappropriate implementation in Blink in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to spoof security UI via a crafted HTML page.
Published Nov 3, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Insufficient data validation in dialogs in Google Chrome on OS X prior to 86.0.4240.75 allowed a remote attacker to obtain potentially sensitive information from disk via a crafted HTML page.
Published Nov 3, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Use after free in WebXR in Google Chrome on Android prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published Nov 3, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Use after free in audio in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published Nov 3, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Out of bounds read in audio in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
Published Nov 3, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Use after free in passwords in Google Chrome prior to 86.0.4240.99 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Published Nov 3, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Use after free in NFC in Google Chrome prior to 86.0.4240.75 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Published Nov 3, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Insufficient data validation in webUI in Google Chrome on ChromeOS prior to 86.0.4240.75 allowed a local attacker to bypass content security policy via a crafted HTML page.
Published Nov 3, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Use after free in user interface in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published Nov 3, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Immuta v2.8.2 is affected by stored XSS that allows a low-privileged user to escalate privileges to administrative permissions. Additionally, unauthenticated attackers can phish unauthenticated Immuta users to steal credentials or force actions on authenticated users through reflected, DOM-based XSS.
Published Nov 5, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Use after free in Mojo in Google Chrome prior to 86.0.4240.99 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Published Nov 3, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Use after free in Blink in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published Nov 3, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Integer overflow in Blink in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to bypass site isolation via a crafted HTML page.
Published Nov 3, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Out of bounds write in V8 in Google Chrome prior to 86.0.4240.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published Nov 3, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Insufficient policy enforcement in networking in Google Chrome prior to 86.0.4240.75 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page.
Published Nov 3, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Uninitialized data in PDFium in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted PDF file.
Published Nov 3, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Insufficient data validation in navigation in Google Chrome on Android prior to 86.0.4240.75 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page.
Published Nov 3, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Insufficient policy enforcement in downloads in Google Chrome on Windows prior to 86.0.4240.75 allowed a remote attacker who convinced the user to open files to execute arbitrary code via a crafted HTML page.
Published Nov 3, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Insufficient policy enforcement in Omnibox in Google Chrome on iOS prior to 86.0.4240.75 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted URL.
Published Nov 3, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Use after free in WebRTC in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published Nov 3, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Immuta v2.8.2 is affected by one instance of insecure permissions that can lead to user account takeover.
Published Nov 5, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Immuta v2.8.2 is affected by improper session management: user sessions are not revoked upon logout.
Published Nov 5, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In Ortus TestBox 2.4.0 through 4.1.0, unvalidated query string parameters passed to system/runners/HTMLRunner.cfm allow an attacker to write an arbitrary CFM file (within the application's context) containing attacker-defined CFML tags, leading to Remote Code Execution.
Published Nov 24, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In Ortus TestBox 2.4.0 through 4.1.0, unvalidated query string parameters to test-browser/index.cfm allow directory traversal.
Published Nov 24, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Use-after-free vulnerability in fs/block_dev.c in the Linux kernel before 5.8 allows local users to gain privileges or cause a denial of service by leveraging improper access to a certain error field.
Published Nov 23, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in PassMark BurnInTest v9.1 Build 1008, OSForensics v7.1 Build 1012, and PerformanceTest v10.0 Build 1008. The kernel driver exposes IOCTL functionality that allows low-privilege users to map arbitrary physical memory into the address space of the calling process. This could lead to arbitrary Ring-0 code execution and escalation of privileges. This affects DirectIo32.sys and DirectIo64.sys drivers. This issue is fixed in BurnInTest v9.2, PerformanceTest v10.0 Build 1009, OSForensics v8.0.
Published Nov 13, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The Linux kernel before version 5.8 is vulnerable to a NULL pointer dereference in drivers/tty/serial/8250/8250_core.c:serial8250_isa_init_ports() that allows local users to cause a denial of service by using the p->serial_in pointer which uninitialized.
Published Nov 23, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
BinaryNights ForkLift 3.x before 3.4 has a local privilege escalation vulnerability because the privileged helper tool implements an XPC interface that allows file operations to any process (copy, move, delete) as root and changing permissions.
Published Nov 17, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
SuiteCRM through 7.11.13 allows CSV Injection via registration fields in the Accounts, Contacts, Opportunities, and Leads modules. These fields are mishandled during a Download Import File Template operation.
Published Nov 18, 2020 · Updated Aug 4, 2024