Vulnerabilities > Google > Chrome > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2020-07-22 | CVE-2020-6506 | Unspecified vulnerability in Google Chrome Insufficient policy enforcement in WebView in Google Chrome on Android prior to 83.0.4103.106 allowed a remote attacker to bypass site isolation via a crafted HTML page. | 6.5 |
2020-06-03 | CVE-2020-6504 | Incorrect Default Permissions vulnerability in Google Chrome Insufficient policy enforcement in notifications in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to bypass notification restrictions via a crafted HTML page. | 4.3 |
2020-06-03 | CVE-2020-6503 | Information Exposure Through an Error Message vulnerability in Google Chrome Inappropriate implementation in accessibility in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. | 6.5 |
2020-06-03 | CVE-2020-6502 | Incorrect Default Permissions vulnerability in Google Chrome Incorrect implementation in permissions in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to spoof security UI via a crafted HTML page. | 6.5 |
2020-06-03 | CVE-2020-6501 | Incorrect Default Permissions vulnerability in Google Chrome Insufficient policy enforcement in CSP in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass content security policy via a crafted HTML page. | 6.5 |
2020-06-03 | CVE-2020-6500 | Unspecified vulnerability in Google Chrome Inappropriate implementation in interstitials in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. | 6.5 |
2020-06-03 | CVE-2020-6499 | Unspecified vulnerability in Google Chrome Inappropriate implementation in AppCache in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass AppCache security restrictions via a crafted HTML page. | 6.5 |
2020-06-03 | CVE-2020-6498 | Incorrect Default Permissions vulnerability in multiple products Incorrect implementation in user interface in Google Chrome on iOS prior to 83.0.4103.88 allowed a remote attacker to perform domain spoofing via a crafted HTML page. | 6.5 |
2020-06-03 | CVE-2020-6497 | Incorrect Default Permissions vulnerability in multiple products Insufficient policy enforcement in Omnibox in Google Chrome on iOS prior to 83.0.4103.88 allowed a remote attacker to perform domain spoofing via a crafted URI. | 6.5 |
2020-06-03 | CVE-2020-6495 | Incorrect Default Permissions vulnerability in multiple products Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.97 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension. | 6.5 |