VYPR

apk package

wolfi/chromium

pkg:apk/wolfi/chromium

Vulnerabilities (2,588)

  • CVE-2024-7969HigAug 21, 2024
    affected < 128.0.6613.84-r0fixed 128.0.6613.84-r0

    Type Confusion in V8 in Google Chrome prior to 128.0.6613.113 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2024-7968HigAug 21, 2024
    affected < 128.0.6613.84-r0fixed 128.0.6613.84-r0

    Use after free in Autofill in Google Chrome prior to 128.0.6613.84 allowed a remote attacker who had convinced the user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2024-7967HigAug 21, 2024
    affected < 128.0.6613.84-r0fixed 128.0.6613.84-r0

    Heap buffer overflow in Fonts in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2024-7966HigAug 21, 2024
    affected < 128.0.6613.84-r0fixed 128.0.6613.84-r0

    Out of bounds memory access in Skia in Google Chrome prior to 128.0.6613.84 allowed a remote attacker who had compromised the renderer process to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

  • CVE-2024-7965HigKEVAug 21, 2024
    affected < 128.0.6613.84-r0fixed 128.0.6613.84-r0

    Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2024-7964HigAug 21, 2024
    affected < 128.0.6613.84-r0fixed 128.0.6613.84-r0

    Use after free in Passwords in Google Chrome on Android prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2024-7550HigAug 6, 2024
    affected < 127.0.6533.119-r0fixed 127.0.6533.119-r0

    Type Confusion in V8 in Google Chrome prior to 127.0.6533.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2024-7536HigAug 6, 2024
    affected < 127.0.6533.119-r0fixed 127.0.6533.119-r0

    Use after free in WebAudio in Google Chrome prior to 127.0.6533.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2024-7535HigAug 6, 2024
    affected < 127.0.6533.119-r0fixed 127.0.6533.119-r0

    Inappropriate implementation in V8 in Google Chrome prior to 127.0.6533.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2024-7534HigAug 6, 2024
    affected < 127.0.6533.119-r0fixed 127.0.6533.119-r0

    Heap buffer overflow in Layout in Google Chrome prior to 127.0.6533.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2024-7533HigAug 6, 2024
    affected < 0fixed 0

    Use after free in Sharing in Google Chrome on iOS prior to 127.0.6533.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2024-7532HigAug 6, 2024
    affected < 127.0.6533.119-r0fixed 127.0.6533.119-r0

    Out of bounds memory access in ANGLE in Google Chrome prior to 127.0.6533.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

  • CVE-2024-7005MedAug 6, 2024
    affected < 127.0.6533.72-r0fixed 127.0.6533.72-r0

    Insufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass discretionary access control via a malicious file. (Chromium security severity: Low)

  • CVE-2024-7004MedAug 6, 2024
    affected < 127.0.6533.72-r0fixed 127.0.6533.72-r0

    Insufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass discretionary access control via a malicious file. (Chromium security severity: Low)

  • CVE-2024-7003MedAug 6, 2024
    affected < 127.0.6533.72-r0fixed 127.0.6533.72-r0

    Inappropriate implementation in FedCM in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2024-7001MedAug 6, 2024
    affected < 127.0.6533.72-r0fixed 127.0.6533.72-r0

    Inappropriate implementation in HTML in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2024-7000HigAug 6, 2024
    affected < 127.0.6533.72-r0fixed 127.0.6533.72-r0

    Use after free in CSS in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2024-6999MedAug 6, 2024
    affected < 127.0.6533.72-r0fixed 127.0.6533.72-r0

    Inappropriate implementation in FedCM in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2024-6998HigAug 6, 2024
    affected < 127.0.6533.72-r0fixed 127.0.6533.72-r0

    Use after free in User Education in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2024-6997HigAug 6, 2024
    affected < 127.0.6533.72-r0fixed 127.0.6533.72-r0

    Use after free in Tabs in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

Page 123 of 130