CVE-2020-3740
published 2020-02-13CVE-2020-3740: Adobe Framemaker versions 2019.0.4 and below have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.
PriorityP346critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
5.00%
91.3th percentile
Adobe Framemaker versions 2019.0.4 and below have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | adobe_framemaker | — | — |
| adobe | framemaker | <= 2019.0.4 | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_oracle6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xhmj-2p35-gj29: Adobe Framemaker versions 2019
ghsa_unreviewed·2022-05-24
CVE-2020-3740 [HIGH] CWE-119 GHSA-xhmj-2p35-gj29: Adobe Framemaker versions 2019
Adobe Framemaker versions 2019.0.4 and below have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.
Oracle
Oracle Oracle Enterprise Manager Risk Matrix: Comp Management and Life Cycle Management (RSA BSAFE Crypto-J) — CVE-2019-3740
vendor_oracle·2020-10-15·CVSS 6.5
CVE-2019-3740 [MEDIUM] Oracle Oracle Enterprise Manager Risk Matrix: Comp Management and Life Cycle Management (RSA BSAFE Crypto-J) — CVE-2019-3740
Oracle Oracle Enterprise Manager Risk Matrix: Comp Management and Life Cycle Management (RSA BSAFE Crypto-J) vulnerability
CVE: CVE-2019-3740
CVSS: 6.5
Protocol: HTTPS
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2020 (OCT 2020)
Oracle
Oracle Oracle Retail Applications Risk Matrix: SIM Integration (BSAFE Crypto-J) — CVE-2019-3740
vendor_oracle·2020-07-15·CVSS 6.5
CVE-2019-3740 [MEDIUM] Oracle Oracle Retail Applications Risk Matrix: SIM Integration (BSAFE Crypto-J) — CVE-2019-3740
Oracle Oracle Retail Applications Risk Matrix: SIM Integration (BSAFE Crypto-J) vulnerability
CVE: CVE-2019-3740
CVSS: 6.5
Protocol: TLS
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2020 (JUL 2020)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-6575 chromium-browser: Race in Mojo
bugzilla·2020-09-08·CVSS 8.3
CVE-2020-6575 [HIGH] CVE-2020-6575 chromium-browser: Race in Mojo
CVE-2020-6575 chromium-browser: Race in Mojo
A race flaw was found in the Mojo component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1081874
External References:
https://chromereleases.googleblog.com/2020/09/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1877098]
Affects: fedora-all [bug 1877097]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:3740 https://access.redhat.com/errata/RHSA-2020:3740
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-6575
Bugzilla
CVE-2020-6573 chromium-browser: Use after free in video
bugzilla·2020-09-08·CVSS 9.6
CVE-2020-6573 [CRITICAL] CVE-2020-6573 chromium-browser: Use after free in video
CVE-2020-6573 chromium-browser: Use after free in video
An use after free flaw was found in the video component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1116304
External References:
https://chromereleases.googleblog.com/2020/09/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1877098]
Affects: fedora-all [bug 1877097]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:3740 https://access.redhat.com/errata/RHSA-2020:3740
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-6573
Bugzilla
CVE-2020-6576 chromium-browser: Use after free in offscreen canvas
bugzilla·2020-09-08·CVSS 8.8
CVE-2020-6576 [HIGH] CVE-2020-6576 chromium-browser: Use after free in offscreen canvas
CVE-2020-6576 chromium-browser: Use after free in offscreen canvas
An use after free flaw was found in the offscreen canvas component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1111737
External References:
https://chromereleases.googleblog.com/2020/09/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1877098]
Affects: fedora-all [bug 1877097]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:3740 https://access.redhat.com/errata/RHSA-2020:3740
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-
Bugzilla
CVE-2020-15959 chromium-browser: Insufficient policy enforcement in networking
bugzilla·2020-09-08·CVSS 4.3
CVE-2020-15959 [MEDIUM] CVE-2020-15959 chromium-browser: Insufficient policy enforcement in networking
CVE-2020-15959 chromium-browser: Insufficient policy enforcement in networking
An insufficient policy enforcement flaw was found in the networking component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1122684
External References:
https://chromereleases.googleblog.com/2020/09/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1877098]
Affects: fedora-all [bug 1877097]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:3740 https://access.redhat.com/errata/RHSA-2020:3740
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redha
Bugzilla
CVE-2020-6574 chromium-browser: Insufficient policy enforcement in installer
bugzilla·2020-09-08·CVSS 7.8
CVE-2020-6574 [HIGH] CVE-2020-6574 chromium-browser: Insufficient policy enforcement in installer
CVE-2020-6574 chromium-browser: Insufficient policy enforcement in installer
An insufficient policy enforcement flaw was found in the installer component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1102196
External References:
https://chromereleases.googleblog.com/2020/09/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1877098]
Affects: fedora-all [bug 1877097]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:3740 https://access.redhat.com/errata/RHSA-2020:3740
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.c
2020-02-13
Published