Here’s a short overview of the most noteworthy vulnerabilities affecting various products disclosed this week.
Google has updated its Chrome browser for Windows, Mac, and Linux to address several vulnerabilities, including a couple of high risk flaws (CVE-2020-6509) that allow a remote attacker to compromise a vulnerable system.
A vulnerability has been found in the Elliptic package 6.5.2 for Node.js that could be exploited by a remote attacker to compromise the target system. The flaw (CVE-2020-13822) allows ECDSA signature malleability via variations in encoding, leading '