CVE-2020-3987
published 2020-09-16CVE-2020-3987: VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) contain an out-of-bounds read vulnerability in Cortado ThinPrint component (EMR…
PriorityP427medium6.1CVSS 3.1
AVLACLPRLUINSUCHINAL
EPSS
0.30%
22.1th percentile
VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) contain an out-of-bounds read vulnerability in Cortado ThinPrint component (EMR STRETCHDIBITS parser). A malicious actor with normal access to a virtual machine may be able to exploit these issues to create a partial denial-of-service condition or to leak memory from TPView process running on the system where Workstation or Horizon Client for Windows is installed.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | horizon_client | >= 5.0.0 < 5.4.4 | 5.4.4 |
| vmware | workstation_player | >= 15.0.0 < 16.0.0 | 16.0.0 |
| vmware | workstation_pro | >= 15.0.0 < 16.0.0 | 16.0.0 |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L
nvdv2.03.6LOWAV:L/AC:L/Au:N/C:P/I:N/A:P
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-33qq-wfvm-3749: VMware Workstation (15
ghsa_unreviewed·2022-05-24
CVE-2020-3987 [MEDIUM] GHSA-33qq-wfvm-3749: VMware Workstation (15
VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) contain an out-of-bounds read vulnerability in Cortado ThinPrint component (EMR STRETCHDIBITS parser). A malicious actor with normal access to a virtual machine may be able to exploit these issues to create a partial denial-of-service condition or to leak memory from TPView process running on the system where Workstation or Horizon Client for Windows is installed.
VMware
VMware Workstation, Fusion and Horizon Client updates address multiple security vulnerabilities (CVE-2020-3980, CVE-2020-3986, CVE-2020-3987, CVE-2020-3988, CVE-2020-3989, CVE-2020-3990)
vendor_vmware·2020-09-14·CVSS 6.7
CVE-2020-3980 [MEDIUM] VMware Workstation, Fusion and Horizon Client updates address multiple security vulnerabilities (CVE-2020-3980, CVE-2020-3986, CVE-2020-3987, CVE-2020-3988, CVE-2020-3989, CVE-2020-3990)
VMSA-2020-0020: VMware Workstation, Fusion and Horizon Client updates address multiple security vulnerabilities (CVE-2020-3980, CVE-2020-3986, CVE-2020-3987, CVE-2020-3988, CVE-2020-3989, CVE-2020-3990)
VMware Fusion contains a privilege escalation vulnerability due to the way it allows configuring the system wide path. VMware has evaluated the severity of this issue to be in the Moderate severity range with a maximum CVSSv3 base score of 6.7.
CVEs: CVE-2020-3980, CVE-2020-3986, CVE-2020-3987, CVE-2020-3988, CVE-2020-3989, CVE-2020-3990
Affected products: Fusion Pro, Horizon Client, VMware Fusion, VMware Horizon, VMware Workstation, Workstation Player, Workstation Pro
Red Hat
chromium-browser: Heap buffer overflow in media
vendor_redhat·2020-03-31·CVSS 8.8
CVE-2020-6452 [HIGH] CWE-122 chromium-browser: Heap buffer overflow in media
chromium-browser: Heap buffer overflow in media
Heap buffer overflow in media in Google Chrome prior to 80.0.3987.162 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Red Hat
chromium-browser: Use after free in WebAudio
vendor_redhat·2020-03-31·CVSS 8.8
CVE-2020-6451 [HIGH] CWE-416 chromium-browser: Use after free in WebAudio
chromium-browser: Use after free in WebAudio
Use after free in WebAudio in Google Chrome prior to 80.0.3987.162 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Red Hat
chromium-browser: Use after free in WebGL
vendor_redhat·2020-03-18·CVSS 8.8
CVE-2020-6422 [HIGH] chromium-browser: Use after free in WebGL
chromium-browser: Use after free in WebGL
Use after free in WebGL in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Red Hat
chromium-browser: Use after free in media
vendor_redhat·2020-03-18·CVSS 8.8
CVE-2020-6424 [HIGH] chromium-browser: Use after free in media
chromium-browser: Use after free in media
Use after free in media in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Red Hat
chromium-browser: Insufficient policy enforcement in extensions
vendor_redhat·2020-03-18·CVSS 5.4
CVE-2020-6425 [MEDIUM] chromium-browser: Insufficient policy enforcement in extensions
chromium-browser: Insufficient policy enforcement in extensions
Insufficient policy enforcement in extensions in Google Chrome prior to 80.0.3987.149 allowed an attacker who convinced a user to install a malicious extension to bypass site isolation via a crafted Chrome Extension.
Red Hat
chromium-browser: Out of bounds memory access in streams
vendor_redhat·2020-02-26·CVSS 8.8
CVE-2020-6407 [HIGH] chromium-browser: Out of bounds memory access in streams
chromium-browser: Out of bounds memory access in streams
Out of bounds memory access in streams in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Red Hat
chromium-browser: Use after free in WebAudio
vendor_redhat·2020-02-18·CVSS 8.8
CVE-2020-6384 [HIGH] chromium-browser: Use after free in WebAudio
chromium-browser: Use after free in WebAudio
Use after free in WebAudio in Google Chrome prior to 80.0.3987.116 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Red Hat
chromium-browser: Use after free in speech
vendor_redhat·2020-02-18·CVSS 8.8
CVE-2020-6386 [HIGH] chromium-browser: Use after free in speech
chromium-browser: Use after free in speech
Use after free in speech in Google Chrome prior to 80.0.3987.116 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Red Hat
chromium-browser: Inappropriate implementation in AppCache
vendor_redhat·2020-02-04·CVSS 6.5
CVE-2020-6499 [MEDIUM] chromium-browser: Inappropriate implementation in AppCache
chromium-browser: Inappropriate implementation in AppCache
Inappropriate implementation in AppCache in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass AppCache security restrictions via a crafted HTML page.
Red Hat
chromium-browser: Inappropriate implementation in Blink
vendor_redhat·2020-02-04·CVSS 8.8
CVE-2020-6404 [HIGH] chromium-browser: Inappropriate implementation in Blink
chromium-browser: Inappropriate implementation in Blink
Inappropriate implementation in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Red Hat
chromium-browser: Insufficient validation of untrusted input in Omnibox
vendor_redhat·2020-02-04·CVSS 5.4
CVE-2020-6412 [MEDIUM] chromium-browser: Insufficient validation of untrusted input in Omnibox
chromium-browser: Insufficient validation of untrusted input in Omnibox
Insufficient validation of untrusted input in Omnibox in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
Red Hat
chromium-browser: Out of bounds read in JavaScript
vendor_redhat·2020-02-04·CVSS 6.5
CVE-2020-6395 [MEDIUM] chromium-browser: Out of bounds read in JavaScript
chromium-browser: Out of bounds read in JavaScript
Out of bounds read in JavaScript in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
Red Hat
chromium-browser: Uninitialized use in PDFium
vendor_redhat·2020-02-04·CVSS 8.8
CVE-2020-6398 [HIGH] chromium-browser: Uninitialized use in PDFium
chromium-browser: Uninitialized use in PDFium
Use of uninitialized data in PDFium in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
Red Hat
chromium-browser: Out of bounds write in WebRTC
vendor_redhat·2020-02-04·CVSS 8.8
CVE-2020-6387 [HIGH] chromium-browser: Out of bounds write in WebRTC
chromium-browser: Out of bounds write in WebRTC
Out of bounds write in WebRTC in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted video stream.
Red Hat
chromium-browser: Insufficient policy enforcement in AppCache
vendor_redhat·2020-02-04·CVSS 6.5
CVE-2020-6399 [MEDIUM] chromium-browser: Insufficient policy enforcement in AppCache
chromium-browser: Insufficient policy enforcement in AppCache
Insufficient policy enforcement in AppCache in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Red Hat
chromium-browser: Use after free in audio
vendor_redhat·2020-02-04·CVSS 8.8
CVE-2020-6406 [HIGH] chromium-browser: Use after free in audio
chromium-browser: Use after free in audio
Use after free in audio in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Red Hat
chromium-browser: Insufficient policy enforcement in downloads
vendor_redhat·2020-02-04·CVSS 8.8
CVE-2020-6402 [HIGH] chromium-browser: Insufficient policy enforcement in downloads
chromium-browser: Insufficient policy enforcement in downloads
Insufficient policy enforcement in downloads in Google Chrome on OS X prior to 80.0.3987.87 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension.
Red Hat
chromium-browser: Inappropriate implementation in Skia
vendor_redhat·2020-02-04·CVSS 4.3
CVE-2020-6396 [MEDIUM] chromium-browser: Inappropriate implementation in Skia
chromium-browser: Inappropriate implementation in Skia
Inappropriate implementation in Skia in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
Red Hat
chromium-browser: Incorrect security UI in Omnibox
vendor_redhat·2020-02-04·CVSS 4.3
CVE-2020-6403 [MEDIUM] chromium-browser: Incorrect security UI in Omnibox
chromium-browser: Incorrect security UI in Omnibox
Incorrect implementation in Omnibox in Google Chrome on iOS prior to 80.0.3987.87 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
Red Hat
chromium-browser: Insufficient policy enforcement in navigation
vendor_redhat·2020-02-04·CVSS 8.8
CVE-2020-6410 [HIGH] chromium-browser: Insufficient policy enforcement in navigation
chromium-browser: Insufficient policy enforcement in navigation
Insufficient policy enforcement in navigation in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to confuse the user via a crafted domain name.
Red Hat
chromium-browser: Insufficient policy enforcement in Blink
vendor_redhat·2020-02-04·CVSS 5.4
CVE-2020-6394 [MEDIUM] chromium-browser: Insufficient policy enforcement in Blink
chromium-browser: Insufficient policy enforcement in Blink
Insufficient policy enforcement in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass content security policy via a crafted HTML page.
Red Hat
chromium-browser: Incorrect security UI in sharing
vendor_redhat·2020-02-04·CVSS 6.5
CVE-2020-6397 [MEDIUM] chromium-browser: Incorrect security UI in sharing
chromium-browser: Incorrect security UI in sharing
Inappropriate implementation in sharing in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to spoof security UI via a crafted HTML page.
Red Hat
chromium-browser: Insufficient data validation in streams
vendor_redhat·2020-02-04·CVSS 8.8
CVE-2020-6416 [HIGH] chromium-browser: Insufficient data validation in streams
chromium-browser: Insufficient data validation in streams
Insufficient data validation in streams in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Red Hat
chromium-browser: Type Confusion in JavaScript
vendor_redhat·2020-02-04·CVSS 8.8
CVE-2020-6382 [HIGH] chromium-browser: Type Confusion in JavaScript
chromium-browser: Type Confusion in JavaScript
Type confusion in JavaScript in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Red Hat
chromium-browser: Inappropriate implementation in Omnibox
vendor_redhat·2020-02-04·CVSS 8.8
CVE-2020-6409 [HIGH] chromium-browser: Inappropriate implementation in Omnibox
chromium-browser: Inappropriate implementation in Omnibox
Inappropriate implementation in Omnibox in Google Chrome prior to 80.0.3987.87 allowed a remote attacker who convinced the user to enter a URI to bypass navigation restrictions via a crafted domain name.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-09-16
Published