CVE-2020-6381

CWE-190Integer Overflow10 documents8 sources
Severity
8.8HIGH
EPSS
2.9%
top 13.62%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 11
Latest updateMay 24

Description

Integer overflow in JavaScript in Google Chrome on ChromeOS and Android prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages7 packages

CVEListV5google/chromeunspecified80.0.3987.87
NVDgoogle/chrome< 80.0.3987.87
Debianchromium< 80.0.3987.106-1+3

Also affects: Debian Linux 10.0, 9.0, Fedora 30, 31

Patches

🔴Vulnerability Details

3
GHSA
GHSA-hjqw-r6v2-ghff: Integer overflow in JavaScript in Google Chrome on ChromeOS and Android prior to 802022-05-24
CVEList
CVE-2020-6381: Integer overflow in JavaScript in Google Chrome on ChromeOS and Android prior to 802020-02-11
OSV
CVE-2020-6381: Integer overflow in JavaScript in Google Chrome on ChromeOS and Android prior to 802020-02-11

📋Vendor Advisories

3
Red Hat
chromium-browser: Integer overflow in JavaScript2020-02-04
Chrome
Stable Channel Update for Desktop: CVE-2020-63812020-02-04
Debian
CVE-2020-6381: chromium - Integer overflow in JavaScript in Google Chrome on ChromeOS and Android prior to...2020

💬Community

3
Bugzilla
CVE-2020-6381 CVE-2020-6382 CVE-2020-6385 CVE-2020-6387 CVE-2020-6388 CVE-2020-6389 CVE-2020-6390 CVE-2020-6391 CVE-2020-6392 CVE-2020-6393 CVE-2020-6394 CVE-2020-6395 CVE-2020-6396 CVE-2020-6397 CVE-2020-02-11
Bugzilla
CVE-2020-6381 CVE-2020-6382 CVE-2020-6385 CVE-2020-6387 CVE-2020-6388 CVE-2020-6389 CVE-2020-6390 CVE-2020-6391 CVE-2020-6392 CVE-2020-6393 CVE-2020-6394 CVE-2020-6395 CVE-2020-6396 CVE-2020-6397 CVE-2020-02-11
Bugzilla
CVE-2020-6381 chromium-browser: Integer overflow in JavaScript2020-02-10
CVE-2020-6381 (HIGH CVSS 8.8) | Integer overflow in JavaScript in G | cvebase.io