CVE-2020-6469

CRITICAL Year: 2020
CVSS v3 Score
9.6
Critical
CVSS v2 Score
6.8
Medium

Vulnerability Description

Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.

CVSS:9.6(Critical)

Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox esc...

CVSS:9.8(Critical)

The default permissions of /dev/kmem in Linux versions before 2.0.36 allows IP spoofing.

CVSS:9.8(Critical)

administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and possibly execute arbitrary code by logging in to the RDS component using the defaul...

CVSS:9.8(Critical)

An elevation of privilege vulnerability in the Android media framework (mediaanalytics). Product: Android. Versions: 8.0. Android ID: A-65540999.

CVSS:9.8(Critical)

An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. After a restart of a server, an attacker might suddenly gain API Endpoint access.

CVSS:9.8(Critical)

During installation of Ambari 2.4.0 through 2.4.2, Ambari Server artifacts are not created with proper ACLs.