CVE-2020-15999

high KEV
Published 2020-10-27 · Modified 2020-11-05
CVSS v3
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS v2
VIR risk
9.5

Description

Important: freetype security update

CISA KEV

Vendor
Google
Product
Chrome FreeType
Due date
2021-11-17

Predictions

Exploit likelihood
99%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: alma — https://errata.almalinux.org/8/ALSA-2020-4952.html

vendor Authored 2026-05-27

Vendor advisory: cisa-kev — https://nvd.nist.gov/vuln/detail/CVE-2020-15999

vendor Authored 2026-05-27

Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2020:4952

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2020-15999

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2020-15999.html

vendor Authored 2026-05-27

Vendor advisory: arch — https://security.archlinux.org/ASA-202010-10

vendor Authored 2026-05-27

Vendor advisory: arch — https://security.archlinux.org/ASA-202010-11

vendor Authored 2026-05-27

Vendor advisory: arch — https://security.archlinux.org/ASA-202011-12

Exploits

OS impact

OSVersionStatusFixed in
arch archfixed83.0-1
suse slesaffected
debian debianbookwormfixed2.10.2+dfsg-4
debian debianbullseyefixed2.10.2+dfsg-4
debian debianforkyfixed2.10.2+dfsg-4
debian debiansidfixed2.10.2+dfsg-4
debian debiantrixiefixed2.10.2+dfsg-4
rockylinux rocky8fixed

Package impact

EcosystemPackageVulnerableFixed
nuget NuGetCefSharp.Common<85.3.13085.3.130
nuget NuGetCefSharp.Wpf<85.3.13085.3.130
nuget NuGetCefSharp.WinForms<85.3.13085.3.130
nuget NuGetCefSharp.Wpf.HwndHost<85.3.13085.3.130

References

Verify integrity in audit chain (admin only). AS-IS.