CVE-2020-4240
published 2020-03-31CVE-2020-4240: IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted…
PriorityP336medium6.5CVSS 3.1
AVNACLPRNUIRSUCNIHAN
EPSS
1.92%
77.5th percentile
IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request to overwrite or create arbitrary files on the system. IBM X-Force ID: 175417.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | spectrum_protect_plus | — | — |
| ibm | spectrum_protect_plus | — | — |
| ibm | spectrum_protect_plus | 10.1.0 – 10.1.5 | — |
| msrc | cbl2_freetype_2.11.1-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| msrc | cm1_freetype_2.11.1-1_on_cbl_mariner_1.0 | — | — |
| msrc | microsoft_sharepoint_enterprise_server_2016 | — | — |
| msrc | microsoft_sharepoint_foundation_2010_service_pack_2 | — | — |
| msrc | microsoft_sharepoint_foundation_2013_service_pack_1 | — | — |
| msrc | microsoft_sharepoint_server_2019 | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
nvdv3.04.8MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:P
vendor_redhat9.6CRITICAL
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mh42-q5qx-q9r6: IBM Spectrum Protect Plus 10
ghsa_unreviewed·2022-05-24
CVE-2020-4240 [MEDIUM] GHSA-mh42-q5qx-q9r6: IBM Spectrum Protect Plus 10
IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request to overwrite or create arbitrary files on the system. IBM X-Force ID: 175417.
Project0
Project Zero RCA: CVE-2020-15999: FreeType Heap Buffer Overflow in Load_SBit_Png
project_zero·CVSS 9.6
CVE-2020-15999 [CRITICAL] Project Zero RCA: CVE-2020-15999: FreeType Heap Buffer Overflow in Load_SBit_Png
# CVE-2020-15999: FreeType Heap Buffer Overflow in Load_SBit_Png
*Sergei Glazunov, Project Zero (Originally posted on [Project Zero blog](https://googleprojectzero.blogspot.com/p/rca.html) 2021-02-04)*
## The Basics
**Disclosure or Patch Date:** 19 October 2020
**Product:** Google Chrome/ Freetype
**Advisory:** https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop_20.html
**Affected Versions:** 86.0.4240.80 and previous
**First Patched Version:** 86.0.4240.111
**Issue/Bug Report:**
* Project Zero: https://bugs.chromium.org/p/project-zero/issues/detail?id=2103
* Chromium: https://bugs.chromium.org/p/chromium/issues/detail?id=1139963
* FreeType: https://savannah.nongnu.org/bugs/?59308
**Patch CL:**
* Chromium: https://chromium.googlesource.com/chromium/src
Microsoft
Microsoft SharePoint Remote Code Execution Vulnerability
vendor_msrc·2020-12-08·CVSS 8.8
CVE-2020-17121 [HIGH] Microsoft SharePoint Remote Code Execution Vulnerability
Microsoft SharePoint Remote Code Execution Vulnerability
FAQ: What is the attack vector for this vulnerability?
In a network-based attack an attacker could gain access to create a site and could execute code remotely. The attacker would need to have privileges.
Microsoft Office SharePoint: Microsoft Office SharePoint
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely;Older Software Release:Exploitation More Likely
Reference: https://www.microsoft.com/download/details.aspx?familyid=259a4b86-7086-4240-8928-d40956abc4db
Reference: https://support.microsoft.com/kb/4493138
Reference: https://www.microsoft.com/download/details.aspx?familyid=4abefe8e-b03a-47b2
Red Hat
chromium-browser: Inappropriate implementation in V8
vendor_redhat·2020-11-11·CVSS 8.8
CVE-2020-16013 [HIGH] CWE-358 chromium-browser: Inappropriate implementation in V8
chromium-browser: Inappropriate implementation in V8
Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.198 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Red Hat
chromium-browser: Use after free in site isolation
vendor_redhat·2020-11-11·CVSS 9.6
CVE-2020-16017 [CRITICAL] CWE-416 chromium-browser: Use after free in site isolation
chromium-browser: Use after free in site isolation
Use after free in site isolation in Google Chrome prior to 86.0.4240.198 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Microsoft
Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
vendor_msrc·2020-11-10·CVSS 6.5
CVE-2020-15999 [CRITICAL] CWE-787 Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Marine
Red Hat
chromium-browser: Inappropriate implementation in base
vendor_redhat·2020-11-09·CVSS 9.6
CVE-2020-16016 [CRITICAL] chromium-browser: Inappropriate implementation in base
chromium-browser: Inappropriate implementation in base
Inappropriate implementation in base in Google Chrome prior to 86.0.4240.193 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Red Hat
chromium-browser: Heap buffer overflow in UI on Windows
vendor_redhat·2020-11-02·CVSS 9.6
CVE-2020-16011 [CRITICAL] chromium-browser: Heap buffer overflow in UI on Windows
chromium-browser: Heap buffer overflow in UI on Windows
Heap buffer overflow in UI in Google Chrome on Windows prior to 86.0.4240.183 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Package: chromium-browser (Red Hat Enterprise Linux 6) - Not affected
Red Hat
chromium-browser: Stack buffer overflow in WebRTC
vendor_redhat·2020-11-02·CVSS 8.8
CVE-2020-16008 [HIGH] chromium-browser: Stack buffer overflow in WebRTC
chromium-browser: Stack buffer overflow in WebRTC
Stack buffer overflow in WebRTC in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit stack corruption via a crafted WebRTC packet.
Red Hat
chromium-browser: Inappropriate implementation in V8
vendor_redhat·2020-11-02·CVSS 8.8
CVE-2020-16009 [HIGH] chromium-browser: Inappropriate implementation in V8
chromium-browser: Inappropriate implementation in V8
Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Red Hat
chromium-browser: Insufficient policy enforcement in ANGLE
vendor_redhat·2020-11-02·CVSS 8.8
CVE-2020-16005 [HIGH] chromium-browser: Insufficient policy enforcement in ANGLE
chromium-browser: Insufficient policy enforcement in ANGLE
Insufficient policy enforcement in ANGLE in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Red Hat
chromium-browser: Use after free in user interface
vendor_redhat·2020-11-02·CVSS 8.8
CVE-2020-16004 [HIGH] chromium-browser: Use after free in user interface
chromium-browser: Use after free in user interface
Use after free in user interface in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Red Hat
chromium-browser: Inappropriate implementation in Blink
vendor_redhat·2020-10-20·CVSS 8.8
CVE-2020-16000 [HIGH] chromium-browser: Inappropriate implementation in Blink
chromium-browser: Inappropriate implementation in Blink
Inappropriate implementation in Blink in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Red Hat
chromium-browser: Use after free in printing
vendor_redhat·2020-10-20·CVSS 8.8
CVE-2020-16003 [HIGH] chromium-browser: Use after free in printing
chromium-browser: Use after free in printing
Use after free in printing in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Red Hat
chromium-browser: Use after free in media
vendor_redhat·2020-10-20·CVSS 8.8
CVE-2020-16001 [HIGH] chromium-browser: Use after free in media
chromium-browser: Use after free in media
Use after free in media in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Red Hat
chromium-browser: Use after free in autofill
vendor_redhat·2020-10-06·CVSS 8.8
CVE-2020-15990 [HIGH] chromium-browser: Use after free in autofill
chromium-browser: Use after free in autofill
Use after free in autofill in Google Chrome prior to 86.0.4240.75 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Red Hat
chromium-browser: Use after free in WebRTC
vendor_redhat·2020-10-06·CVSS 8.8
CVE-2020-15987 [HIGH] chromium-browser: Use after free in WebRTC
chromium-browser: Use after free in WebRTC
Use after free in WebRTC in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted WebRTC stream.
Red Hat
chromium-browser: Insufficient policy enforcement in Intents
vendor_redhat·2020-10-06·CVSS 7.8
CVE-2020-15980 [HIGH] chromium-browser: Insufficient policy enforcement in Intents
chromium-browser: Insufficient policy enforcement in Intents
Insufficient policy enforcement in Intents in Google Chrome on Android prior to 86.0.4240.75 allowed a local attacker to bypass navigation restrictions via crafted Intents.
Red Hat
chromium-browser: Insufficient data validation in webUI
vendor_redhat·2020-10-06·CVSS 7.8
CVE-2020-15983 [HIGH] chromium-browser: Insufficient data validation in webUI
chromium-browser: Insufficient data validation in webUI
Insufficient data validation in webUI in Google Chrome on ChromeOS prior to 86.0.4240.75 allowed a local attacker to bypass content security policy via a crafted HTML page.
Red Hat
chromium-browser: Use after free in printing
vendor_redhat·2020-10-06·CVSS 8.8
CVE-2020-15971 [HIGH] chromium-browser: Use after free in printing
chromium-browser: Use after free in printing
Use after free in printing in Google Chrome prior to 86.0.4240.75 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Red Hat
chromium-browser: Integer overflow in SwiftShader
vendor_redhat·2020-10-06·CVSS 8.8
CVE-2020-15975 [HIGH] chromium-browser: Integer overflow in SwiftShader
chromium-browser: Integer overflow in SwiftShader
Integer overflow in SwiftShader in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Red Hat
chromium-browser: Use after free in Blink
vendor_redhat·2020-10-06·CVSS 8.8
CVE-2020-15968 [HIGH] chromium-browser: Use after free in Blink
chromium-browser: Use after free in Blink
Use after free in Blink in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Red Hat
chromium-browser: Inappropriate implementation in V8
vendor_redhat·2020-10-06·CVSS 8.8
CVE-2020-15979 [HIGH] chromium-browser: Inappropriate implementation in V8
chromium-browser: Inappropriate implementation in V8
Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Red Hat
chromium-browser: Insufficient policy enforcement in networking
vendor_redhat·2020-10-06·CVSS 8.8
CVE-2020-15992 [HIGH] chromium-browser: Insufficient policy enforcement in networking
chromium-browser: Insufficient policy enforcement in networking
Insufficient policy enforcement in networking in Google Chrome prior to 86.0.4240.75 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page.
Red Hat
chromium-browser: Use after free in audio
vendor_redhat·2020-10-06·CVSS 8.8
CVE-2020-15972 [HIGH] chromium-browser: Use after free in audio
chromium-browser: Use after free in audio
Use after free in audio in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Red Hat
chromium-browser: Inappropriate implementation in networking
vendor_redhat·2020-10-06·CVSS 6.5
CVE-2020-6557 [MEDIUM] chromium-browser: Inappropriate implementation in networking
chromium-browser: Inappropriate implementation in networking
Inappropriate implementation in networking in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
Red Hat
chromium-browser: Insufficient policy enforcement in Omnibox
vendor_redhat·2020-10-06·CVSS 6.5
CVE-2020-15984 [MEDIUM] chromium-browser: Insufficient policy enforcement in Omnibox
chromium-browser: Insufficient policy enforcement in Omnibox
Insufficient policy enforcement in Omnibox in Google Chrome on iOS prior to 86.0.4240.75 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted URL.
Red Hat
chromium-browser: Integer overflow in media
vendor_redhat·2020-10-06·CVSS 6.5
CVE-2020-15986 [MEDIUM] chromium-browser: Integer overflow in media
chromium-browser: Integer overflow in media
Integer overflow in media in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Red Hat
chromium-browser: Use after free in WebXR
vendor_redhat·2020-10-06·CVSS 8.8
CVE-2020-15976 [HIGH] chromium-browser: Use after free in WebXR
chromium-browser: Use after free in WebXR
Use after free in WebXR in Google Chrome on Android prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Red Hat
chromium-browser: Inappropriate implementation in Blink
vendor_redhat·2020-10-06·CVSS 6.5
CVE-2020-15985 [MEDIUM] chromium-browser: Inappropriate implementation in Blink
chromium-browser: Inappropriate implementation in Blink
Inappropriate implementation in Blink in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to spoof security UI via a crafted HTML page.
Red Hat
chromium-browser: Integer overflow in Blink
vendor_redhat·2020-10-06·CVSS 8.8
CVE-2020-15974 [HIGH] chromium-browser: Integer overflow in Blink
chromium-browser: Integer overflow in Blink
Integer overflow in Blink in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to bypass site isolation via a crafted HTML page.
Red Hat
chromium-browser: Use after free in WebRTC
vendor_redhat·2020-10-06·CVSS 8.8
CVE-2020-15969 [HIGH] chromium-browser: Use after free in WebRTC
chromium-browser: Use after free in WebRTC
Use after free in WebRTC in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Package: firefox (Red Hat Enterprise Linux 5) - Out of support scope
Package: thunderbird (Red Hat Enterprise Linux 5) - Out of support scope
No detection rules found.
No writeups or analysis indexed.
2020-03-31
Published