CVE-2020-4235
published 2020-03-31CVE-2020-4235: IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in…
PriorityP423medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
0.67%
47.8th percentile
IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 175408.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | tivoli_netcool_impact | — | — |
| ibm | tivoli_netcool_impact | — | — |
| ibm | tivoli_netcool_impact | 7.1.0.0 – 7.1.0.17 | — |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv3.05.4MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-15969 chromium-browser: Use after free in WebRTC
bugzilla·2020-10-07·CVSS 8.8
CVE-2020-15969 [HIGH] CVE-2020-15969 chromium-browser: Use after free in WebRTC
CVE-2020-15969 chromium-browser: Use after free in WebRTC
An use after free flaw was found in the WebRTC component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1124659
External References:
https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1885917]
Affects: fedora-all [bug 1885916]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:4235 https://access.redhat.com/errata/RHSA-2020:4235
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-15969
---
Th
Bugzilla
CVE-2020-6557 chromium-browser: Inappropriate implementation in networking
bugzilla·2020-10-07·CVSS 6.5
CVE-2020-6557 [MEDIUM] CVE-2020-6557 chromium-browser: Inappropriate implementation in networking
CVE-2020-6557 chromium-browser: Inappropriate implementation in networking
An inappropriate implementation flaw was found in the networking component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1083278
External References:
https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1885917]
Affects: fedora-all [bug 1885916]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:4235 https://access.redhat.com/errata/RHSA-2020:4235
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/s
Bugzilla
CVE-2020-15988 chromium-browser: Insufficient policy enforcement in downloads
bugzilla·2020-10-07·CVSS 6.3
CVE-2020-15988 [MEDIUM] CVE-2020-15988 chromium-browser: Insufficient policy enforcement in downloads
CVE-2020-15988 chromium-browser: Insufficient policy enforcement in downloads
An insufficient policy enforcement flaw was found in the downloads component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1092518
External References:
https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1885917]
Affects: fedora-all [bug 1885916]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:4235 https://access.redhat.com/errata/RHSA-2020:4235
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.
Bugzilla
CVE-2020-15982 chromium-browser: Side-channel information leakage in cache
bugzilla·2020-10-07·CVSS 6.5
CVE-2020-15982 [MEDIUM] CVE-2020-15982 chromium-browser: Side-channel information leakage in cache
CVE-2020-15982 chromium-browser: Side-channel information leakage in cache
A side-channel information leakage flaw was found in the cache component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1039882
External References:
https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1885917]
Affects: fedora-all [bug 1885916]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:4235 https://access.redhat.com/errata/RHSA-2020:4235
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/sec
Bugzilla
CVE-2020-15973 chromium-browser: Insufficient policy enforcement in extensions
bugzilla·2020-10-07·CVSS 6.5
CVE-2020-15973 [MEDIUM] CVE-2020-15973 chromium-browser: Insufficient policy enforcement in extensions
CVE-2020-15973 chromium-browser: Insufficient policy enforcement in extensions
An insufficient policy enforcement flaw was found in the extensions component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1106890
External References:
https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1885917]
Affects: fedora-all [bug 1885916]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:4235 https://access.redhat.com/errata/RHSA-2020:4235
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redha
Bugzilla
CVE-2020-15967 chromium-browser: Use after free in payments
bugzilla·2020-10-07·CVSS 8.8
CVE-2020-15967 [HIGH] CVE-2020-15967 chromium-browser: Use after free in payments
CVE-2020-15967 chromium-browser: Use after free in payments
An use after free flaw was found in the payments component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1127322
External References:
https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1885917]
Affects: fedora-all [bug 1885916]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:4235 https://access.redhat.com/errata/RHSA-2020:4235
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-15967
Bugzilla
CVE-2020-15991 chromium-browser: Use after free in password manager
bugzilla·2020-10-07·CVSS 8.8
CVE-2020-15991 [HIGH] CVE-2020-15991 chromium-browser: Use after free in password manager
CVE-2020-15991 chromium-browser: Use after free in password manager
An use after free flaw was found in the password manager component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1133688
External References:
https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1885917]
Affects: fedora-all [bug 1885916]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:4235 https://access.redhat.com/errata/RHSA-2020:4235
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve
Bugzilla
CVE-2020-15985 chromium-browser: Inappropriate implementation in Blink
bugzilla·2020-10-07·CVSS 6.5
CVE-2020-15985 [MEDIUM] CVE-2020-15985 chromium-browser: Inappropriate implementation in Blink
CVE-2020-15985 chromium-browser: Inappropriate implementation in Blink
An inappropriate implementation flaw was found in the Blink component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1099276
External References:
https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1885917]
Affects: fedora-all [bug 1885916]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:4235 https://access.redhat.com/errata/RHSA-2020:4235
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/c
Bugzilla
CVE-2020-15986 chromium-browser: Integer overflow in media
bugzilla·2020-10-07·CVSS 6.5
CVE-2020-15986 [MEDIUM] CVE-2020-15986 chromium-browser: Integer overflow in media
CVE-2020-15986 chromium-browser: Integer overflow in media
An integer overflow flaw was found in the media component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1100247
External References:
https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1885917]
Affects: fedora-all [bug 1885916]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:4235 https://access.redhat.com/errata/RHSA-2020:4235
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-15986
Bugzilla
CVE-2020-15976 chromium-browser: Use after free in WebXR
bugzilla·2020-10-07·CVSS 8.8
CVE-2020-15976 [HIGH] CVE-2020-15976 chromium-browser: Use after free in WebXR
CVE-2020-15976 chromium-browser: Use after free in WebXR
An use after free flaw was found in the WebXR component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1123522
External References:
https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1885917]
Affects: fedora-all [bug 1885916]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:4235 https://access.redhat.com/errata/RHSA-2020:4235
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-15976
---
Note
Bugzilla
CVE-2020-15978 chromium-browser: Insufficient data validation in navigation
bugzilla·2020-10-07·CVSS 8.8
CVE-2020-15978 [HIGH] CVE-2020-15978 chromium-browser: Insufficient data validation in navigation
CVE-2020-15978 chromium-browser: Insufficient data validation in navigation
An insufficient data validation flaw was found in the navigation component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1116280
External References:
https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1885917]
Affects: fedora-all [bug 1885916]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:4235 https://access.redhat.com/errata/RHSA-2020:4235
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/
Bugzilla
CVE-2020-15975 chromium-browser: Integer overflow in SwiftShader
bugzilla·2020-10-07·CVSS 8.8
CVE-2020-15975 [HIGH] CVE-2020-15975 chromium-browser: Integer overflow in SwiftShader
CVE-2020-15975 chromium-browser: Integer overflow in SwiftShader
An integer overflow flaw was found in the SwiftShader component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1110800
External References:
https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1885917]
Affects: fedora-all [bug 1885916]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:4235 https://access.redhat.com/errata/RHSA-2020:4235
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-
Bugzilla
CVE-2020-15992 chromium-browser: Insufficient policy enforcement in networking
bugzilla·2020-10-07·CVSS 8.8
CVE-2020-15992 [HIGH] CVE-2020-15992 chromium-browser: Insufficient policy enforcement in networking
CVE-2020-15992 chromium-browser: Insufficient policy enforcement in networking
An insufficient policy enforcement flaw was found in the networking component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1110195
External References:
https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop.html
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:4235 https://access.redhat.com/errata/RHSA-2020:4235
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-15992
Bugzilla
CVE-2020-15970 chromium-browser: Use after free in NFC
bugzilla·2020-10-07·CVSS 8.8
CVE-2020-15970 [HIGH] CVE-2020-15970 chromium-browser: Use after free in NFC
CVE-2020-15970 chromium-browser: Use after free in NFC
An use after free flaw was found in the NFC component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1108299
External References:
https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1885917]
Affects: fedora-all [bug 1885916]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:4235 https://access.redhat.com/errata/RHSA-2020:4235
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-15970
Bugzilla
CVE-2020-15972 chromium-browser: Use after free in audio
bugzilla·2020-10-07·CVSS 8.8
CVE-2020-15972 [HIGH] CVE-2020-15972 chromium-browser: Use after free in audio
CVE-2020-15972 chromium-browser: Use after free in audio
An use after free flaw was found in the audio component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1115901
External References:
https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1885917]
Affects: fedora-all [bug 1885916]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:4235 https://access.redhat.com/errata/RHSA-2020:4235
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-15972
Bugzilla
CVE-2020-15974 chromium-browser: Integer overflow in Blink
bugzilla·2020-10-07·CVSS 8.8
CVE-2020-15974 [HIGH] CVE-2020-15974 chromium-browser: Integer overflow in Blink
CVE-2020-15974 chromium-browser: Integer overflow in Blink
An integer overflow flaw was found in the Blink component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1104103
External References:
https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1885917]
Affects: fedora-all [bug 1885916]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:4235 https://access.redhat.com/errata/RHSA-2020:4235
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-15974
Bugzilla
CVE-2020-15984 chromium-browser: Insufficient policy enforcement in Omnibox
bugzilla·2020-10-07·CVSS 6.5
CVE-2020-15984 [MEDIUM] CVE-2020-15984 chromium-browser: Insufficient policy enforcement in Omnibox
CVE-2020-15984 chromium-browser: Insufficient policy enforcement in Omnibox
An insufficient policy enforcement flaw was found in the Omnibox component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1080395
External References:
https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1885917]
Affects: fedora-all [bug 1885916]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:4235 https://access.redhat.com/errata/RHSA-2020:4235
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/
Bugzilla
CVE-2020-15968 chromium-browser: Use after free in Blink
bugzilla·2020-10-07·CVSS 8.8
CVE-2020-15968 [HIGH] CVE-2020-15968 chromium-browser: Use after free in Blink
CVE-2020-15968 chromium-browser: Use after free in Blink
An use after free flaw was found in the Blink component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1126424
External References:
https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1885917]
Affects: fedora-all [bug 1885916]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:4235 https://access.redhat.com/errata/RHSA-2020:4235
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-15968
Bugzilla
CVE-2020-15979 chromium-browser: Inappropriate implementation in V8
bugzilla·2020-10-07·CVSS 8.8
CVE-2020-15979 [HIGH] CVE-2020-15979 chromium-browser: Inappropriate implementation in V8
CVE-2020-15979 chromium-browser: Inappropriate implementation in V8
An inappropriate implementation flaw was found in the V8 component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1127319
External References:
https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1885917]
Affects: fedora-all [bug 1885916]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:4235 https://access.redhat.com/errata/RHSA-2020:4235
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve
Bugzilla
CVE-2020-15981 chromium-browser: Out of bounds read in audio
bugzilla·2020-10-07·CVSS 6.5
CVE-2020-15981 [MEDIUM] CVE-2020-15981 chromium-browser: Out of bounds read in audio
CVE-2020-15981 chromium-browser: Out of bounds read in audio
An out of bounds read flaw was found in the audio component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1123023
External References:
https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1885917]
Affects: fedora-all [bug 1885916]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:4235 https://access.redhat.com/errata/RHSA-2020:4235
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-15981
Bugzilla
CVE-2020-15980 chromium-browser: Insufficient policy enforcement in Intents
bugzilla·2020-10-07·CVSS 7.8
CVE-2020-15980 [HIGH] CVE-2020-15980 chromium-browser: Insufficient policy enforcement in Intents
CVE-2020-15980 chromium-browser: Insufficient policy enforcement in Intents
An insufficient policy enforcement flaw was found in the Intents component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1092453
External References:
https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1885917]
Affects: fedora-all [bug 1885916]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:4235 https://access.redhat.com/errata/RHSA-2020:4235
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/
Bugzilla
CVE-2020-15977 chromium-browser: Insufficient data validation in dialogs
bugzilla·2020-10-07·CVSS 6.5
CVE-2020-15977 [MEDIUM] CVE-2020-15977 chromium-browser: Insufficient data validation in dialogs
CVE-2020-15977 chromium-browser: Insufficient data validation in dialogs
An insufficient data validation flaw was found in the dialogs component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1097724
External References:
https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1885917]
Affects: fedora-all [bug 1885916]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:4235 https://access.redhat.com/errata/RHSA-2020:4235
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/securi
Bugzilla
CVE-2020-15987 chromium-browser: Use after free in WebRTC
bugzilla·2020-10-07·CVSS 8.8
CVE-2020-15987 [HIGH] CVE-2020-15987 chromium-browser: Use after free in WebRTC
CVE-2020-15987 chromium-browser: Use after free in WebRTC
An use after free flaw was found in the WebRTC component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1127774
External References:
https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1885917]
Affects: fedora-all [bug 1885916]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:4235 https://access.redhat.com/errata/RHSA-2020:4235
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-15987
Bugzilla
CVE-2020-15989 chromium-browser: Uninitialized use in PDFium
bugzilla·2020-10-07·CVSS 5.5
CVE-2020-15989 [MEDIUM] CVE-2020-15989 chromium-browser: Uninitialized use in PDFium
CVE-2020-15989 chromium-browser: Uninitialized use in PDFium
An uninitialized use flaw was found in the PDFium component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1108351
External References:
https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1885917]
Affects: fedora-all [bug 1885916]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:4235 https://access.redhat.com/errata/RHSA-2020:4235
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-15989
Bugzilla
CVE-2020-15971 chromium-browser: Use after free in printing
bugzilla·2020-10-07·CVSS 8.8
CVE-2020-15971 [HIGH] CVE-2020-15971 chromium-browser: Use after free in printing
CVE-2020-15971 chromium-browser: Use after free in printing
An use after free flaw was found in the printing component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1114062
External References:
https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1885917]
Affects: fedora-all [bug 1885916]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:4235 https://access.redhat.com/errata/RHSA-2020:4235
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-15971
Bugzilla
CVE-2020-15990 chromium-browser: Use after free in autofill
bugzilla·2020-10-07·CVSS 8.8
CVE-2020-15990 [HIGH] CVE-2020-15990 chromium-browser: Use after free in autofill
CVE-2020-15990 chromium-browser: Use after free in autofill
An use after free flaw was found in the autofill component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1133671
External References:
https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1885917]
Affects: fedora-all [bug 1885916]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:4235 https://access.redhat.com/errata/RHSA-2020:4235
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-15990
Bugzilla
CVE-2020-15983 chromium-browser: Insufficient data validation in webUI
bugzilla·2020-10-07·CVSS 7.8
CVE-2020-15983 [HIGH] CVE-2020-15983 chromium-browser: Insufficient data validation in webUI
CVE-2020-15983 chromium-browser: Insufficient data validation in webUI
An insufficient data validation flaw was found in the webUI component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1076786
External References:
https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1885917]
Affects: fedora-all [bug 1885916]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:4235 https://access.redhat.com/errata/RHSA-2020:4235
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/c
2020-03-31
Published