CVE-2020-16042
published 2021-01-08CVE-2020-16042: Uninitialized Use in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to obtain potentially sensitive information from process memory via a…
PriorityP428medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
EPSS
0.89%
55.0th percentile
Uninitialized Use in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chromium | chromium | >= 0 < 87.0.4280.88-0.1 | 87.0.4280.88-0.1 |
| chromium | chromium | >= 0 < 87.0.4280.88-0.1 | 87.0.4280.88-0.1 |
| chromium | chromium | >= 0 < 87.0.4280.88-0.1 | 87.0.4280.88-0.1 |
| chromium | chromium | >= 0 < 87.0.4280.88-0.1 | 87.0.4280.88-0.1 |
| debian | chromium | < chromium 87.0.4280.88-0.1 (bookworm) | chromium 87.0.4280.88-0.1 (bookworm) |
| debian | firefox | < chromium 87.0.4280.88-0.1 (bookworm) | chromium 87.0.4280.88-0.1 (bookworm) |
| debian | firefox-esr | < chromium 87.0.4280.88-0.1 (bookworm) | chromium 87.0.4280.88-0.1 (bookworm) |
| debian | thunderbird | < chromium 87.0.4280.88-0.1 (bookworm) | chromium 87.0.4280.88-0.1 (bookworm) |
| chrome | < 87.0.4280.88 | 87.0.4280.88 | |
| chrome | >= unspecified < 87.0.4280.88 | 87.0.4280.88 | |
| chrome_chrome | — | — | |
| mozilla | firefox | — | — |
| mozilla | firefox | >= 0 < 84.0+build3-0ubuntu0.16.04.1 | 84.0+build3-0ubuntu0.16.04.1 |
| mozilla | firefox | >= 0 < 84.0+build3-0ubuntu0.18.04.1 | 84.0+build3-0ubuntu0.18.04.1 |
| mozilla | firefox | >= 0 < 84.0+build3-0ubuntu0.20.04.1 | 84.0+build3-0ubuntu0.20.04.1 |
| mozilla | thunderbird | >= 0 < 1:78.6.0-1 | 1:78.6.0-1 |
| mozilla | thunderbird | >= 0 < 1:78.6.0-1 | 1:78.6.0-1 |
| mozilla | thunderbird | >= 0 < 1:78.6.0-1 | 1:78.6.0-1 |
| mozilla | thunderbird | >= 0 < 1:78.6.0-1 | 1:78.6.0-1 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jcqg-j4q8-3vwg: Uninitialized Use in V8 in Google Chrome prior to 87
ghsa_unreviewed·2022-05-24
CVE-2020-16042 [MEDIUM] CWE-200 GHSA-jcqg-j4q8-3vwg: Uninitialized Use in V8 in Google Chrome prior to 87
Uninitialized Use in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
OSV
CVE-2020-16042: Uninitialized Use in V8 in Google Chrome prior to 87
osv·2021-01-08·CVSS 6.5
CVE-2020-16042 [MEDIUM] CVE-2020-16042: Uninitialized Use in V8 in Google Chrome prior to 87
Uninitialized Use in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
OSV
firefox vulnerabilities
osv·2020-12-15·CVSS 6.5
CVE-2020-16042 [MEDIUM] firefox vulnerabilities
firefox vulnerabilities
Multiple security issues were discovered in Firefox. If a user were
tricked into opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, obtain sensitive
information, bypass the CSS sanitizer, bypass security restrictions,
spoof the URL bar, or execute arbitrary code. (CVE-2020-16042,
CVE-2020-26971, CVE-2020-26972, CVE-2020-26793, CVE-2020-26974,
CVE-2020-26976, CVE-2020-26978, CVE-2020-26979,
CVE-2020-35113, CVE-2020-35114)
It was discovered that the proxy.onRequest API did not catch
view-source URLs. If a user were tricked in to installing an
extension with the proxy permission and opening View Source, an
attacker could potentially exploit this to obtain sensitive
information. (CVE-2020-35111)
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2021-01-20·CVSS 6.5
CVE-2020-16042 [MEDIUM] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Multiple security issues were discovered in Thunderbird. If a user were
tricked in to opening a specially crafted website in a browsing context,
an attacker could potentially exploit these to cause a denial of service,
obtain sensitive information, bypass the CSS sanitizer, or execute
arbitrary code. (CVE-2020-16042, CVE-2020-16044, CVE-2020-26971,
CVE-2020-26973, CVE-2020-26974, CVE-2020-26978, CVE-2020-35113)
It was discovered that the proxy.onRequest API did not catch
view-source URLs. If a user were tricked in to installing an
extension with the proxy permission and opening View Source, an
attacker could potentially exploit this to obtain sensitive
information. (CVE-2020-35111)
A stack ov
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2020-12-15·CVSS 6.5
CVE-2020-26971 [MEDIUM] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox could be made to crash or run programs as your login if it
opened a malicious website.
Multiple security issues were discovered in Firefox. If a user were
tricked into opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, obtain sensitive
information, bypass the CSS sanitizer, bypass security restrictions,
spoof the URL bar, or execute arbitrary code. (CVE-2020-16042,
CVE-2020-26971, CVE-2020-26972, CVE-2020-26793, CVE-2020-26974,
CVE-2020-26976, CVE-2020-26978, CVE-2020-26979,
CVE-2020-35113, CVE-2020-35114)
It was discovered that the proxy.onRequest API did not catch
view-source URLs. If a user were tricked in to installing an
extension with the proxy permission and opening View So
Chrome
Stable Channel Update for Desktop: CVE-2020-16040
vendor_chrome·2020-12-02·CVSS 6.5
CVE-2020-16040 [HIGH] Stable Channel Update for Desktop: CVE-2020-16040
Stable Channel Update for Desktop
CVE-2020-16040: Insufficient data validation in V8. Reported by Lucas Pinheiro, Microsoft Browser Vulnerability Research on 2020-11-19 [$TBD][ 1151865 ] Medium CVE-2020-16041: Out of bounds read in networking
Reported by Sergei Glazunov and Mark Brand of Google Project Zero on 2020-11-23 [$TBD][ 1151890 ] Medium CVE-2020-16042: Uninitialized Use in V8
Severity: high
Red Hat
chromium-browser: Uninitialized Use in V8
vendor_redhat·2020-12-02·CVSS 6.5
CVE-2020-16042 [MEDIUM] chromium-browser: Uninitialized Use in V8
chromium-browser: Uninitialized Use in V8
Uninitialized Use in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
The Mozilla Foundation Security Advisory describes this flaw as:
When a BigInt was right-shifted the backing store was not properly cleared, allowing uninitialized memory to be read.
Package: thunderbird (Red Hat Enterprise Linux 5) - Out of support scope
Package: firefox (Red Hat Enterprise Linux 6) - Out of support scope
Package: thunderbird (Red Hat Enterprise Linux 6) - Out of support scope
Debian
CVE-2020-16042: chromium - Uninitialized Use in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote ...
vendor_debian·2020·CVSS 6.5
CVE-2020-16042 [MEDIUM] CVE-2020-16042: chromium - Uninitialized Use in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote ...
Uninitialized Use in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (fixed in 87.0.4280.88-0.1)
trixie: resolved (fixed in 87.0.4280.88-0.1)
Mozilla
Mozilla Foundation Security Advisory 2020-55: CVE-2020-16042
vendor_mozilla·CVSS 6.5
CVE-2020-16042 [MEDIUM] Mozilla Foundation Security Advisory 2020-55: CVE-2020-16042
Mozilla Foundation Security Advisory 2020-55
CVE: CVE-2020-16042
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 78.6
Mozilla
Mozilla Foundation Security Advisory 2020-56: CVE-2020-16042
vendor_mozilla·CVSS 6.5
CVE-2020-16042 [MEDIUM] Mozilla Foundation Security Advisory 2020-56: CVE-2020-16042
Mozilla Foundation Security Advisory 2020-56
CVE: CVE-2020-16042
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 78.6
Mozilla
Mozilla Foundation Security Advisory 2020-54: CVE-2020-16042
vendor_mozilla·CVSS 6.5
CVE-2020-16042 [MEDIUM] Mozilla Foundation Security Advisory 2020-54: CVE-2020-16042
Mozilla Foundation Security Advisory 2020-54
CVE: CVE-2020-16042
Product: Firefox
Impact: high
Fixed in: Firefox 84
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-01-08
Published