apk package
wolfi/chromium-docker-selenium-compat
pkg:apk/wolfi/chromium-docker-selenium-compat
Vulnerabilities (924)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2024-3839 | Med | 6.5 | < 124.0.6367.60-r0 | 124.0.6367.60-r0 | Apr 17, 2024 | Out of bounds read in Fonts in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium) | |
| CVE-2024-3838 | Med | 5.5 | < 124.0.6367.60-r0 | 124.0.6367.60-r0 | Apr 17, 2024 | Inappropriate implementation in Autofill in Google Chrome prior to 124.0.6367.60 allowed an attacker who convinced a user to install a malicious app to perform UI spoofing via a crafted app. (Chromium security severity: Medium) | |
| CVE-2024-3837 | Hig | 8.8 | < 124.0.6367.60-r0 | 124.0.6367.60-r0 | Apr 17, 2024 | Use after free in QUIC in Google Chrome prior to 124.0.6367.60 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) | |
| CVE-2024-3834 | Hig | 8.8 | < 124.0.6367.60-r0 | 124.0.6367.60-r0 | Apr 17, 2024 | Use after free in Downloads in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| CVE-2024-3833 | Hig | 8.8 | < 124.0.6367.60-r0 | 124.0.6367.60-r0 | Apr 17, 2024 | Object corruption in WebAssembly in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High) | |
| CVE-2024-3832 | Hig | 8.8 | < 124.0.6367.60-r0 | 124.0.6367.60-r0 | Apr 17, 2024 | Object corruption in V8 in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High) | |
| CVE-2024-3159 | Hig | 8.8 | < 123.0.6312.105-r0 | 123.0.6312.105-r0 | Apr 6, 2024 | Out of bounds memory access in V8 in Google Chrome prior to 123.0.6312.105 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High) | |
| CVE-2024-3158 | Hig | 8.8 | < 123.0.6312.105-r0 | 123.0.6312.105-r0 | Apr 6, 2024 | Use after free in Bookmarks in Google Chrome prior to 123.0.6312.105 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| CVE-2024-3156 | Hig | 8.8 | < 123.0.6312.105-r0 | 123.0.6312.105-r0 | Apr 6, 2024 | Inappropriate implementation in V8 in Google Chrome prior to 123.0.6312.105 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) | |
| CVE-2024-2176 | Hig | 8.8 | < 122.0.6261.128-r0 | 122.0.6261.128-r0 | Mar 6, 2024 | Use after free in FedCM in Google Chrome prior to 122.0.6261.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| CVE-2024-2174 | Hig | 8.8 | < 122.0.6261.128-r0 | 122.0.6261.128-r0 | Mar 6, 2024 | Inappropriate implementation in V8 in Google Chrome prior to 122.0.6261.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| CVE-2024-2173 | Hig | 8.8 | < 122.0.6261.128-r0 | 122.0.6261.128-r0 | Mar 6, 2024 | Out of bounds memory access in V8 in Google Chrome prior to 122.0.6261.111 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) | |
| CVE-2018-10229 | Med | 4.8 | < 0 | 0 | May 4, 2018 | A hardware vulnerability in GPU memory modules allows attackers to accelerate micro-architectural attacks through the use of the JavaScript WebGL API. | |
| CVE-2013-6662 | Med | 6.5 | < 0 | 0 | Apr 13, 2017 | Google Chrome caches TLS sessions before certificate validation occurs. | |
| CVE-2013-6647 | Cri | 9.8 | < 0 | 0 | Apr 11, 2017 | A use-after-free in AnimationController::endAnimationUpdate in Google Chrome. | |
| CVE-2016-7153 | Med | 5.3 | < 0 | 0 | Sep 6, 2016 | The HTTP/2 protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "H | |
| CVE-2016-7152 | Med | 5.3 | < 0 | 0 | Sep 6, 2016 | The HTTPS protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HE | |
| CVE-2015-4000 | Low | 3.7 | < 0 | 0 | May 21, 2015 | The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by D | |
| CVE-2012-4930 | — | < 0 | 0 | Sep 15, 2012 | The SPDY protocol 3 and earlier, as used in Mozilla Firefox, Google Chrome, and other products, can perform TLS encryption of compressed data without properly obfuscating the length of the unencrypted data, which allows man-in-the-middle attackers to obtain plaintext HTTP headers | ||
| CVE-2012-4929 | — | < 0 | 0 | Sep 15, 2012 | The TLS protocol 1.2 and earlier, as used in Mozilla Firefox, Google Chrome, Qt, and other products, can encrypt compressed data without properly obfuscating the length of the unencrypted data, which allows man-in-the-middle attackers to obtain plaintext HTTP headers by observing |
- affected < 124.0.6367.60-r0fixed 124.0.6367.60-r0
Out of bounds read in Fonts in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
- affected < 124.0.6367.60-r0fixed 124.0.6367.60-r0
Inappropriate implementation in Autofill in Google Chrome prior to 124.0.6367.60 allowed an attacker who convinced a user to install a malicious app to perform UI spoofing via a crafted app. (Chromium security severity: Medium)
- affected < 124.0.6367.60-r0fixed 124.0.6367.60-r0
Use after free in QUIC in Google Chrome prior to 124.0.6367.60 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
- affected < 124.0.6367.60-r0fixed 124.0.6367.60-r0
Use after free in Downloads in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- affected < 124.0.6367.60-r0fixed 124.0.6367.60-r0
Object corruption in WebAssembly in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)
- affected < 124.0.6367.60-r0fixed 124.0.6367.60-r0
Object corruption in V8 in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)
- affected < 123.0.6312.105-r0fixed 123.0.6312.105-r0
Out of bounds memory access in V8 in Google Chrome prior to 123.0.6312.105 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)
- affected < 123.0.6312.105-r0fixed 123.0.6312.105-r0
Use after free in Bookmarks in Google Chrome prior to 123.0.6312.105 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- affected < 123.0.6312.105-r0fixed 123.0.6312.105-r0
Inappropriate implementation in V8 in Google Chrome prior to 123.0.6312.105 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
- affected < 122.0.6261.128-r0fixed 122.0.6261.128-r0
Use after free in FedCM in Google Chrome prior to 122.0.6261.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- affected < 122.0.6261.128-r0fixed 122.0.6261.128-r0
Inappropriate implementation in V8 in Google Chrome prior to 122.0.6261.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- affected < 122.0.6261.128-r0fixed 122.0.6261.128-r0
Out of bounds memory access in V8 in Google Chrome prior to 122.0.6261.111 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
- affected < 0fixed 0
A hardware vulnerability in GPU memory modules allows attackers to accelerate micro-architectural attacks through the use of the JavaScript WebGL API.
- affected < 0fixed 0
Google Chrome caches TLS sessions before certificate validation occurs.
- affected < 0fixed 0
A use-after-free in AnimationController::endAnimationUpdate in Google Chrome.
- affected < 0fixed 0
The HTTP/2 protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "H
- affected < 0fixed 0
The HTTPS protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HE
- affected < 0fixed 0
The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by D
- CVE-2012-4930Sep 15, 2012affected < 0fixed 0
The SPDY protocol 3 and earlier, as used in Mozilla Firefox, Google Chrome, and other products, can perform TLS encryption of compressed data without properly obfuscating the length of the unencrypted data, which allows man-in-the-middle attackers to obtain plaintext HTTP headers
- CVE-2012-4929Sep 15, 2012affected < 0fixed 0
The TLS protocol 1.2 and earlier, as used in Mozilla Firefox, Google Chrome, Qt, and other products, can encrypt compressed data without properly obfuscating the length of the unencrypted data, which allows man-in-the-middle attackers to obtain plaintext HTTP headers by observing
Page 46 of 47