cbcvebase.
CVE-2020-15999
published 2020-11-03

CVE-2020-15999: Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML…

critical9.6CVSS 3.1
AVNACLPRNUIRSCCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2021-11-17
Exploited in the wild
Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Affected

25 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianfreetype< freetype 2.10.2+dfsg-4 (bookworm)freetype 2.10.2+dfsg-4 (bookworm)
fedoraprojectfedora
freetypefreetype>= 0 < 2.10.2+dfsg-42.10.2+dfsg-4
freetypefreetype>= 0 < 2.10.2+dfsg-42.10.2+dfsg-4
freetypefreetype>= 0 < 2.10.2+dfsg-42.10.2+dfsg-4
freetypefreetype>= 0 < 2.10.2+dfsg-42.10.2+dfsg-4
freetypefreetype>= 2.6.0 < 2.10.42.10.4
googleandroid
googlechrome< 86.0.4240.11186.0.4240.111
googlechrome>= unspecified < 86.0.4240.11186.0.4240.111
googlechrome_chrome
mozillafirefox
msrccbl2_freetype_2.11.1-1_on_cbl_mariner_2.0
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
msrccm1_freetype_2.11.1-1_on_cbl_mariner_1.0
opensusebackports_sle
platformexternal_freetype>= 10:0 < 10:2021-01-0110:2021-01-01
platformexternal_freetype>= 11:0 < 11:2021-01-0111:2021-01-01
platformexternal_freetype>= 8.0:0 < 8.0:2021-01-018.0:2021-01-01
platformexternal_freetype>= 8.1:0 < 8.1:2021-01-018.1:2021-01-01
platformexternal_freetype>= 9:0 < 9:2021-01-019:2021-01-01

CVSS provenance

nvdv3.19.6CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
ghsa9.6CRITICAL
osv9.6CRITICAL
vulncheck9.6CRITICAL
cisa9.6CRITICAL