CVE-2020-3723
published 2020-02-13CVE-2020-3723: Adobe Framemaker versions 2019.0.4 and below have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution.
PriorityP348high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
3.97%
89.3th percentile
Adobe Framemaker versions 2019.0.4 and below have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | adobe_framemaker | — | — |
| adobe | framemaker | <= 2019.0.4 | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-6560 chromium-browser: Insufficient policy enforcement in autofill
bugzilla·2020-08-27·CVSS 6.5
CVE-2020-6560 [MEDIUM] CVE-2020-6560 chromium-browser: Insufficient policy enforcement in autofill
CVE-2020-6560 chromium-browser: Insufficient policy enforcement in autofill
An insufficient policy enforcement flaw was found in the autofill component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1108181
External References:
https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop_25.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1872961]
Affects: fedora-all [bug 1872960]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:3723 https://access.redhat.com/errata/RHSA-2020:3723
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.
Bugzilla
CVE-2020-6570 chromium-browser: Side-channel information leakage in WebRTC
bugzilla·2020-08-27·CVSS 4.3
CVE-2020-6570 [MEDIUM] CVE-2020-6570 chromium-browser: Side-channel information leakage in WebRTC
CVE-2020-6570 chromium-browser: Side-channel information leakage in WebRTC
A side-channel information leakage flaw was found in the WebRTC component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1084699
External References:
https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop_25.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1872961]
Affects: fedora-all [bug 1872960]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:3723 https://access.redhat.com/errata/RHSA-2020:3723
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com
Bugzilla
CVE-2020-6568 chromium-browser: Insufficient policy enforcement in intent handling
bugzilla·2020-08-27·CVSS 6.5
CVE-2020-6568 [MEDIUM] CVE-2020-6568 chromium-browser: Insufficient policy enforcement in intent handling
CVE-2020-6568 chromium-browser: Insufficient policy enforcement in intent handling
An insufficient policy enforcement flaw was found in the intent handling component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1092451
External References:
https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop_25.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1872961]
Affects: fedora-all [bug 1872960]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:3723 https://access.redhat.com/errata/RHSA-2020:3723
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://
Bugzilla
CVE-2020-6561 chromium-browser: Inappropriate implementation in Content Security Policy
bugzilla·2020-08-27·CVSS 6.5
CVE-2020-6561 [MEDIUM] CVE-2020-6561 chromium-browser: Inappropriate implementation in Content Security Policy
CVE-2020-6561 chromium-browser: Inappropriate implementation in Content Security Policy
An inappropriate implementation flaw was found in the Content Security Policy component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=932892
External References:
https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop_25.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1872961]
Affects: fedora-all [bug 1872960]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:3723 https://access.redhat.com/errata/RHSA-2020:3723
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
Bugzilla
CVE-2020-6569 chromium-browser: Integer overflow in WebUSB
bugzilla·2020-08-27·CVSS 6.3
CVE-2020-6569 [MEDIUM] CVE-2020-6569 chromium-browser: Integer overflow in WebUSB
CVE-2020-6569 chromium-browser: Integer overflow in WebUSB
An integer overflow flaw was found in the WebUSB component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=995732
External References:
https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop_25.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1872961]
Affects: fedora-all [bug 1872960]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:3723 https://access.redhat.com/errata/RHSA-2020:3723
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-6569
Bugzilla
CVE-2020-6571 chromium-browser: Incorrect security UI in Omnibox
bugzilla·2020-08-27·CVSS 4.3
CVE-2020-6571 [MEDIUM] CVE-2020-6571 chromium-browser: Incorrect security UI in Omnibox
CVE-2020-6571 chromium-browser: Incorrect security UI in Omnibox
An incorrect security ui flaw was found in the Omnibox component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1085315
External References:
https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop_25.html
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:3723 https://access.redhat.com/errata/RHSA-2020:3723
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-6571
Bugzilla
CVE-2020-6563 chromium-browser: Insufficient policy enforcement in intent handling
bugzilla·2020-08-27·CVSS 6.5
CVE-2020-6563 [MEDIUM] CVE-2020-6563 chromium-browser: Insufficient policy enforcement in intent handling
CVE-2020-6563 chromium-browser: Insufficient policy enforcement in intent handling
An insufficient policy enforcement flaw was found in the intent handling component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1104628
External References:
https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop_25.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1872961]
Affects: fedora-all [bug 1872960]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:3723 https://access.redhat.com/errata/RHSA-2020:3723
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://
Bugzilla
CVE-2020-6567 chromium-browser: Insufficient validation of untrusted input in command line handling
bugzilla·2020-08-27·CVSS 6.5
CVE-2020-6567 [MEDIUM] CVE-2020-6567 chromium-browser: Insufficient validation of untrusted input in command line handling
CVE-2020-6567 chromium-browser: Insufficient validation of untrusted input in command line handling
An insufficient validation of untrusted input flaw was found in the command line handling component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=937179
External References:
https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop_25.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1872961]
Affects: fedora-all [bug 1872960]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:3723 https://access.redhat.com/errata/RHSA-2020:3723
---
This bug is now closed. Further updates for individual products will be reflec
Bugzilla
CVE-2020-6564 chromium-browser: Incorrect security UI in permissions
bugzilla·2020-08-27·CVSS 6.5
CVE-2020-6564 [MEDIUM] CVE-2020-6564 chromium-browser: Incorrect security UI in permissions
CVE-2020-6564 chromium-browser: Incorrect security UI in permissions
An incorrect security ui flaw was found in the permissions component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=841622
External References:
https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop_25.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1872961]
Affects: fedora-all [bug 1872960]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:3723 https://access.redhat.com/errata/RHSA-2020:3723
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cv
Bugzilla
CVE-2020-6566 chromium-browser: Insufficient policy enforcement in media
bugzilla·2020-08-27·CVSS 6.5
CVE-2020-6566 [MEDIUM] CVE-2020-6566 chromium-browser: Insufficient policy enforcement in media
CVE-2020-6566 chromium-browser: Insufficient policy enforcement in media
An insufficient policy enforcement flaw was found in the media component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1065264
External References:
https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop_25.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1872961]
Affects: fedora-all [bug 1872960]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:3723 https://access.redhat.com/errata/RHSA-2020:3723
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/se
Bugzilla
CVE-2020-6565 chromium-browser: Incorrect security UI in Omnibox
bugzilla·2020-08-27·CVSS 6.5
CVE-2020-6565 [MEDIUM] CVE-2020-6565 chromium-browser: Incorrect security UI in Omnibox
CVE-2020-6565 chromium-browser: Incorrect security UI in Omnibox
An incorrect security ui flaw was found in the Omnibox component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1029907
External References:
https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop_25.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1872961]
Affects: fedora-all [bug 1872960]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:3723 https://access.redhat.com/errata/RHSA-2020:3723
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2
Bugzilla
CVE-2020-6562 chromium-browser: Insufficient policy enforcement in Blink
bugzilla·2020-08-27·CVSS 6.5
CVE-2020-6562 [MEDIUM] CVE-2020-6562 chromium-browser: Insufficient policy enforcement in Blink
CVE-2020-6562 chromium-browser: Insufficient policy enforcement in Blink
An insufficient policy enforcement flaw was found in the Blink component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1086845
External References:
https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop_25.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1872961]
Affects: fedora-all [bug 1872960]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:3723 https://access.redhat.com/errata/RHSA-2020:3723
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/se
Checkpoint
31st October – Threat Intelligence Report
blogs_checkpoint·2022-10-31
CVE-2022-3723 31st October – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 31st October – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 31st October, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
US-based communications company Twilio has disclosed a new data breach that occurred on June 2022 allegedly by the same threat actors behind the August hack. The hackers have used voice phishing to trick a Twilio employee into handling over their credentials, which the hackers then used to access customer information.
Cu
2020-02-13
Published