apk package
wolfi/chromium
pkg:apk/wolfi/chromium
Vulnerabilities (2,588)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2024-2626 | Med | 6.5 | < 123.0.6312.58-r0 | 123.0.6312.58-r0 | Mar 20, 2024 | Out of bounds read in Swiftshader in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium) | |
| CVE-2024-2625 | Hig | 8.8 | < 123.0.6312.58-r0 | 123.0.6312.58-r0 | Mar 20, 2024 | Object lifecycle issue in V8 in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High) | |
| CVE-2024-2400 | Hig | 8.8 | < 122.0.6261.128-r0 | 122.0.6261.128-r0 | Mar 13, 2024 | Use after free in Performance Manager in Google Chrome prior to 122.0.6261.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| CVE-2024-2176 | Hig | 8.8 | < 122.0.6261.128-r0 | 122.0.6261.128-r0 | Mar 6, 2024 | Use after free in FedCM in Google Chrome prior to 122.0.6261.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| CVE-2024-2174 | Hig | 8.8 | < 122.0.6261.128-r0 | 122.0.6261.128-r0 | Mar 6, 2024 | Inappropriate implementation in V8 in Google Chrome prior to 122.0.6261.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| CVE-2024-2173 | Hig | 8.8 | < 122.0.6261.128-r0 | 122.0.6261.128-r0 | Mar 6, 2024 | Out of bounds memory access in V8 in Google Chrome prior to 122.0.6261.111 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) | |
| CVE-2024-1939 | Hig | 8.8 | < 122.0.6261.94-r0 | 122.0.6261.94-r0 | Feb 29, 2024 | Type Confusion in V8 in Google Chrome prior to 122.0.6261.94 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| CVE-2024-1938 | Hig | 8.8 | < 122.0.6261.94-r0 | 122.0.6261.94-r0 | Feb 29, 2024 | Type Confusion in V8 in Google Chrome prior to 122.0.6261.94 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High) | |
| CVE-2024-1676 | Med | 5.4 | < 122.0.6261.57-r0 | 122.0.6261.57-r0 | Feb 21, 2024 | Inappropriate implementation in Navigation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Low) | |
| CVE-2024-1675 | Hig | 8.8 | < 122.0.6261.57-r0 | 122.0.6261.57-r0 | Feb 21, 2024 | Insufficient policy enforcement in Download in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. (Chromium security severity: Medium) | |
| CVE-2024-1674 | Hig | 8.8 | < 122.0.6261.57-r0 | 122.0.6261.57-r0 | Feb 21, 2024 | Inappropriate implementation in Navigation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium) | |
| CVE-2024-1673 | Hig | 8.8 | < 122.0.6261.57-r0 | 122.0.6261.57-r0 | Feb 21, 2024 | Use after free in Accessibility in Google Chrome prior to 122.0.6261.57 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via specific UI gestures. (Chromium security severity: Medium) | |
| CVE-2024-1672 | Med | 5.4 | < 122.0.6261.57-r0 | 122.0.6261.57-r0 | Feb 21, 2024 | Inappropriate implementation in Content Security Policy in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Medium) | |
| CVE-2024-1671 | Med | 6.5 | < 122.0.6261.57-r0 | 122.0.6261.57-r0 | Feb 21, 2024 | Inappropriate implementation in Site Isolation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Medium) | |
| CVE-2024-1670 | Hig | 8.8 | < 122.0.6261.57-r0 | 122.0.6261.57-r0 | Feb 21, 2024 | Use after free in Mojo in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| CVE-2024-1669 | Hig | 8.8 | < 122.0.6261.57-r0 | 122.0.6261.57-r0 | Feb 21, 2024 | Out of bounds memory access in Blink in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) | |
| CVE-2018-10229 | Med | 4.8 | < 0 | 0 | May 4, 2018 | A hardware vulnerability in GPU memory modules allows attackers to accelerate micro-architectural attacks through the use of the JavaScript WebGL API. | |
| CVE-2013-6662 | Med | 6.5 | < 0 | 0 | Apr 13, 2017 | Google Chrome caches TLS sessions before certificate validation occurs. | |
| CVE-2013-6647 | Cri | 9.8 | < 0 | 0 | Apr 11, 2017 | A use-after-free in AnimationController::endAnimationUpdate in Google Chrome. | |
| CVE-2016-7153 | Med | 5.3 | < 0 | 0 | Sep 6, 2016 | The HTTP/2 protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "H |
- affected < 123.0.6312.58-r0fixed 123.0.6312.58-r0
Out of bounds read in Swiftshader in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)
- affected < 123.0.6312.58-r0fixed 123.0.6312.58-r0
Object lifecycle issue in V8 in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)
- affected < 122.0.6261.128-r0fixed 122.0.6261.128-r0
Use after free in Performance Manager in Google Chrome prior to 122.0.6261.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- affected < 122.0.6261.128-r0fixed 122.0.6261.128-r0
Use after free in FedCM in Google Chrome prior to 122.0.6261.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- affected < 122.0.6261.128-r0fixed 122.0.6261.128-r0
Inappropriate implementation in V8 in Google Chrome prior to 122.0.6261.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- affected < 122.0.6261.128-r0fixed 122.0.6261.128-r0
Out of bounds memory access in V8 in Google Chrome prior to 122.0.6261.111 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
- affected < 122.0.6261.94-r0fixed 122.0.6261.94-r0
Type Confusion in V8 in Google Chrome prior to 122.0.6261.94 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- affected < 122.0.6261.94-r0fixed 122.0.6261.94-r0
Type Confusion in V8 in Google Chrome prior to 122.0.6261.94 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)
- affected < 122.0.6261.57-r0fixed 122.0.6261.57-r0
Inappropriate implementation in Navigation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Low)
- affected < 122.0.6261.57-r0fixed 122.0.6261.57-r0
Insufficient policy enforcement in Download in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. (Chromium security severity: Medium)
- affected < 122.0.6261.57-r0fixed 122.0.6261.57-r0
Inappropriate implementation in Navigation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
- affected < 122.0.6261.57-r0fixed 122.0.6261.57-r0
Use after free in Accessibility in Google Chrome prior to 122.0.6261.57 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via specific UI gestures. (Chromium security severity: Medium)
- affected < 122.0.6261.57-r0fixed 122.0.6261.57-r0
Inappropriate implementation in Content Security Policy in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Medium)
- affected < 122.0.6261.57-r0fixed 122.0.6261.57-r0
Inappropriate implementation in Site Isolation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Medium)
- affected < 122.0.6261.57-r0fixed 122.0.6261.57-r0
Use after free in Mojo in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- affected < 122.0.6261.57-r0fixed 122.0.6261.57-r0
Out of bounds memory access in Blink in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
- affected < 0fixed 0
A hardware vulnerability in GPU memory modules allows attackers to accelerate micro-architectural attacks through the use of the JavaScript WebGL API.
- affected < 0fixed 0
Google Chrome caches TLS sessions before certificate validation occurs.
- affected < 0fixed 0
A use-after-free in AnimationController::endAnimationUpdate in Google Chrome.
- affected < 0fixed 0
The HTTP/2 protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "H
Page 129 of 130