4.3
CVSSv3

CVE-2020-6442

Published: 13/04/2020 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 384
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

Inappropriate implementation in cache in Google Chrome before 81.0.4044.92 allowed a remote malicious user to leak cross-origin data via a crafted HTML page.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

google chrome

debian debian linux 10.0

fedoraproject fedora 30

opensuse leap 15.1

fedoraproject fedora 31

fedoraproject fedora 32

opensuse backports sle-15

Vendor Advisories

Synopsis Important: chromium-browser security update Type/Severity Security Advisory: Important Topic An update for chromium-browser is now available for Red Hat Enterprise Linux 6 SupplementaryRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability S ...
Several vulnerabilities have been discovered in the chromium web browser CVE-2020-6423 A use-after-free issue was found in the audio implementation CVE-2020-6430 Avihay Cohen discovered a type confusion issue in the v8 javascript library CVE-2020-6431 Luan Herrera discovered a policy enforcement error CVE-2020-6432 Luan Her ...
Severity Unknown Remote Unknown Type Unknown Description AVG-1128 chromium 8003987163-1 810404492-1 High Fixed ...
The Chrome team is delighted to announce the promotion of Chrome 81 to the stable channel for Windows, Mac and Linux This will roll out over the coming days/weeks Chrome 810404492 contains a number of fixes and improvements -- a list of changes is available in the log Watch out for upcoming Chrome and Chromium blog ...

Github Repositories

WeCTF 2020 Source Code & Organizer's Writeup

WeCTF 2020 Thank you all for participating! This README contains my writeup sketches You can also share your writeup on CTFtime Run Challenges Locally git clone githubcom/wectf/2020 cd 2020 && docker-compose up The mapping is as following localhost:1000 -> CORBra // CAVEAT: only solvable over HTTPS localho

cross-site (XS) search attack - scripts

XS-Search Attacks Cross-site search attacks allow a rogue website to expose private, sensitive user-information from web applications The attacker exploits timing and other side channels to extract the information, using cleverly-designed cross-site queries Full-text available Reproducibility System In this repo you can find several xs-search attack scripts that we run on o

WeCTF 2020 Source Code & Organizer's Writeup

WeCTF 2020 Thank you all for participating! This README contains my writeup sketches You can also share your writeup on CTFtime Run Challenges Locally git clone githubcom/wectf/2020 cd 2020 && docker-compose up The mapping is as following localhost:1000 -> CORBra // CAVEAT: only solvable over HTTPS localho