CVE-2020-15999
CRITICAL KEVGoogle Chrome < 86.0.4240.111 - Out-of-Bounds Write
Title source: ruleDescription
Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Exploits (5)
github
34 stars
by DarkFunct · cpoc
https://github.com/DarkFunct/CVE_Exploits/tree/main/CVE-2020-15999
References (12)
Scores
CVSS v3
9.6
EPSS
0.9291
EPSS Percentile
99.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Details
CISA KEV
2021-11-03
VulnCheck KEV
2020-10-19
InTheWild.io
2020-10-19
ENISA EUVD
EUVD-2020-1435
CWE
CWE-120
CWE-787
Status
published
Products (10)
debian/debian_linux
10.0
fedoraproject/fedora
31
freetype/freetype
2.6.0 - 2.10.4
google/chrome
< 86.0.4240.111
netapp/ontap_select_deploy_administration_utility
nuget/CefSharp.Common
0 - 85.3.130NuGet
nuget/CefSharp.WinForms
0 - 85.3.130NuGet
nuget/CefSharp.Wpf
0 - 85.3.130NuGet
nuget/CefSharp.Wpf.HwndHost
0 - 85.3.130NuGet
opensuse/backports_sle
15.0 sp2
Published
Nov 03, 2020
KEV Added
Nov 03, 2021
Tracked Since
Feb 18, 2026