CVE-2020-16009

Description

Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Risk Information

Base Score
8.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
84.383

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities fixed in Google Chrome (x64) (86.0.4240.183)Windows
Multiple vulnerabilities fixed in Google Chrome (86.0.4240.183)Windows
Vulnerabilities CVE-2020-16009,CVE-2020-16017,CVE-2020-16013 are fixed in Nuget - CefSharp.Common 86.0.241Windows
Vulnerabilities CVE-2020-16009,CVE-2020-16017,CVE-2020-16013 are fixed in Nuget - CefSharp.WinForms 86.0.241Windows
Vulnerabilities CVE-2020-16009,CVE-2020-16017,CVE-2020-16013 are fixed in Nuget - CefSharp.Wpf 86.0.241Windows
Vulnerabilities CVE-2020-16009,CVE-2020-16017,CVE-2020-16013 are fixed in Nuget - CefSharp.Wpf.HwndHost 86.0.241Windows
Multiple vulnerabilities are fixed in Google Chrome For Mac (86.0.4240.183)Mac
(RHSA-2020:4974) chromium-browser security update chromium-browser-86.0.4240.183-1.el6_10.i686.rpmLinux
(RHSA-2020:4974) chromium-browser security update chromium-browser-86.0.4240.183-1.el6_10.x86_64.rpmLinux
chromium security update(DSA-4824-1) chromium_87.0.4280.88-0.4~deb10u1_i386.debLinux
chromium security update(DSA-4824-1) chromium_87.0.4280.88-0.4~deb10u1_amd64.debLinux
Multiple vulnerabilities fixed in Google Chrome (86.0.4240.183) (For Debian)Linux
Multiple vulnerabilities fixed in Google Chrome (86.0.4240.183) (For Centos)Linux
Multiple vulnerabilities fixed in Google Chrome (86.0.4240.183) (For RedHat)Linux
Multiple vulnerabilities fixed in Google Chrome (86.0.4240.183) (For Suse)Linux
Multiple vulnerabilities fixed in Google Chrome (86.0.4240.183) (For Ubuntu)Linux
Vulnerabilities CVE-2020-16009,CVE-2020-16017,CVE-2020-16013 are fixed in Nuget - CefSharp.Common for Linux 86.0.241Linux
Vulnerabilities CVE-2020-16009,CVE-2020-16017,CVE-2020-16013 are fixed in Nuget - CefSharp.WinForms for Linux 86.0.241Linux
Vulnerabilities CVE-2020-16009,CVE-2020-16017,CVE-2020-16013 are fixed in Nuget - CefSharp.Wpf for Linux 86.0.241Linux
Vulnerabilities CVE-2020-16009,CVE-2020-16017,CVE-2020-16013 are fixed in Nuget - CefSharp.Wpf.HwndHost for Linux 86.0.241Linux

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-316801Google Chrome (x64) (86.0.4240.183)
PATCH-316800Google Chrome (86.0.4240.183)
PATCH-609673Google Chrome for Mac (132.0.6834.83, 132.0.6834.84)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234