openSUSE-SU-2020:1829Vendor advisory
http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00016.html CVE-2020-16009
HIGHCISA KEV
Inappropriate implementation in V8
Record summary
CVE-2020-16009 has a selected CVSS score of 8.8 (high). CISA lists CVE-2020-16009 in KEV.
Description
Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Description source: CVE List
Exploitation context
Known exploitation
- CISA KEV
- Listed · Nov 3, 2021 · CISA
- VulnCheck KEV
- Listed · Oct 29, 2020 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationActive
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 29, 2025 · Source: CVE List
Affected products and versions
6| Product | Source | Version range | Status |
|---|---|---|---|
ChromeBrowse Google / Chrome | CVE List | Before 86.0.4240.183 | affected |
Chromium V8Browse Google / Chromium V8 | CISA | Version data not supplied | |
CefSharp.CommonBrowse NuGet / CefSharp.Common | GitHub Advisory | Before 86.0.241 · Fixed in 86.0.241 | affected |
CefSharp.WinFormsBrowse NuGet / CefSharp.WinForms | GitHub Advisory | Before 86.0.241 · Fixed in 86.0.241 | affected |
CefSharp.WpfBrowse NuGet / CefSharp.Wpf | GitHub Advisory | Before 86.0.241 · Fixed in 86.0.241 | affected |
CefSharp.Wpf.HwndHostBrowse NuGet / CefSharp.Wpf.HwndHost | GitHub Advisory | Before 86.0.241 · Fixed in 86.0.241 | affected |
References
Showing 12 of 15openSUSE-SU-2020:1831Vendor advisory
http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00017.html packetstormsecurity.com
http://packetstormsecurity.com/files/159974/Chrome-V8-Turbofan-Type-Confusion.html chromereleases.googleblog.com
https://chromereleases.googleblog.com/2020/11/stable-channel-update-for-desktop.html crbug.com
https://crbug.com/1143772 github.com
https://github.com/cefsharp/CefSharp github.com
https://github.com/cefsharp/CefSharp/security/advisories/GHSA-m7mf-48hp-5qmr FEDORA-2020-3e005ce2e0Vendor advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/S4XYJ7B6OXHZNYSA5J3DBUOFEC6WCAGW FEDORA-2020-4e8e48da22Vendor advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SC3U3H6AISVZB5PLZLLNF4HMQ4UFFL7M lists.fedoraproject.org
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/S4XYJ7B6OXHZNYSA5J3DBUOFEC6WCAGW lists.fedoraproject.org
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SC3U3H6AISVZB5PLZLLNF4HMQ4UFFL7M nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-16009