CVE-2020-6504

Description

Insufficient policy enforcement in notifications in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to bypass notification restrictions via a crafted HTML page.

Risk Information

Base Score
4.3
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
EPSS Score
Exploitation Probability
0.068

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities affected in Google Chrome (x64) 73.0.3683.86Windows
Multiple vulnerabilities affected in Google Chrome 73.0.3683.86Windows
Multiple vulnerabilities affected in Google Chrome 73.0.3683.86 (For Debian)Linux
Multiple vulnerabilities affected in Google Chrome 73.0.3683.86 (For Centos)Linux
Multiple vulnerabilities affected in Google Chrome 73.0.3683.86 (For RedHat)Linux
Multiple vulnerabilities affected in Google Chrome 73.0.3683.86 (For Suse)Linux
Multiple vulnerabilities affected in Google Chrome 73.0.3683.86 (For Ubuntu)Linux

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-343228Google Chrome (x64) (131.0.6778.85, 131.0.6778.86)
PATCH-343227Google Chrome (131.0.6778.85, 131.0.6778.86)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234