rpm package
opensuse/chromium&distro=openSUSE Leap 16.0
pkg:rpm/opensuse/chromium&distro=openSUSE%20Leap%2016.0
Vulnerabilities (353)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2025-11213 | — | < 141.0.7390.76-bp160.1.1 | 141.0.7390.76-bp160.1.1 | Nov 6, 2025 | Inappropriate implementation in Omnibox in Google Chrome on Android prior to 141.0.7390.54 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform domain spoofing via a crafted HTML page. (Chromium security severity: Medium) | ||
| CVE-2025-11212 | — | < 141.0.7390.76-bp160.1.1 | 141.0.7390.76-bp160.1.1 | Nov 6, 2025 | Inappropriate implementation in Media in Google Chrome on Windows prior to 141.0.7390.54 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform domain spoofing via a crafted HTML page. (Chromium security severity: Medium) | ||
| CVE-2025-11211 | — | < 141.0.7390.76-bp160.1.1 | 141.0.7390.76-bp160.1.1 | Nov 6, 2025 | Out of bounds read in Media in Google Chrome prior to 141.0.7390.54 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium) | ||
| CVE-2025-11210 | — | < 141.0.7390.76-bp160.1.1 | 141.0.7390.76-bp160.1.1 | Nov 6, 2025 | Side-channel information leakage in Tab in Google Chrome prior to 141.0.7390.54 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) | ||
| CVE-2025-11209 | — | < 141.0.7390.76-bp160.1.1 | 141.0.7390.76-bp160.1.1 | Nov 6, 2025 | Inappropriate implementation in Omnibox in Google Chrome on Android prior to 141.0.7390.54 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium) | ||
| CVE-2025-11208 | — | < 141.0.7390.76-bp160.1.1 | 141.0.7390.76-bp160.1.1 | Nov 6, 2025 | Inappropriate implementation in Media in Google Chrome prior to 141.0.7390.54 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) | ||
| CVE-2025-11207 | — | < 141.0.7390.76-bp160.1.1 | 141.0.7390.76-bp160.1.1 | Nov 6, 2025 | Side-channel information leakage in Storage in Google Chrome prior to 141.0.7390.54 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: Medium) | ||
| CVE-2025-11206 | — | < 141.0.7390.76-bp160.1.1 | 141.0.7390.76-bp160.1.1 | Nov 6, 2025 | Heap buffer overflow in Video in Google Chrome prior to 141.0.7390.54 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | ||
| CVE-2025-11205 | — | < 141.0.7390.76-bp160.1.1 | 141.0.7390.76-bp160.1.1 | Nov 6, 2025 | Heap buffer overflow in WebGPU in Google Chrome prior to 141.0.7390.54 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | ||
| CVE-2025-10892 | — | < 141.0.7390.76-bp160.1.1 | 141.0.7390.76-bp160.1.1 | Sep 24, 2025 | Integer overflow in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | ||
| CVE-2025-10891 | — | < 141.0.7390.76-bp160.1.1 | 141.0.7390.76-bp160.1.1 | Sep 24, 2025 | Integer overflow in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | ||
| CVE-2025-10890 | — | < 141.0.7390.76-bp160.1.1 | 141.0.7390.76-bp160.1.1 | Sep 24, 2025 | Side-channel information leakage in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High) | ||
| CVE-2025-3063 | Hig | 8.8 | < 145.0.7632.116-bp160.1.1 | 145.0.7632.116-bp160.1.1 | Apr 2, 2025 | The Shopper Approved Reviews plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the ajax_callback_update_sa_option() function in versions 2.0 to 2.1. This makes it possible for authent |
- CVE-2025-11213Nov 6, 2025affected < 141.0.7390.76-bp160.1.1fixed 141.0.7390.76-bp160.1.1
Inappropriate implementation in Omnibox in Google Chrome on Android prior to 141.0.7390.54 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform domain spoofing via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2025-11212Nov 6, 2025affected < 141.0.7390.76-bp160.1.1fixed 141.0.7390.76-bp160.1.1
Inappropriate implementation in Media in Google Chrome on Windows prior to 141.0.7390.54 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform domain spoofing via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2025-11211Nov 6, 2025affected < 141.0.7390.76-bp160.1.1fixed 141.0.7390.76-bp160.1.1
Out of bounds read in Media in Google Chrome prior to 141.0.7390.54 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2025-11210Nov 6, 2025affected < 141.0.7390.76-bp160.1.1fixed 141.0.7390.76-bp160.1.1
Side-channel information leakage in Tab in Google Chrome prior to 141.0.7390.54 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2025-11209Nov 6, 2025affected < 141.0.7390.76-bp160.1.1fixed 141.0.7390.76-bp160.1.1
Inappropriate implementation in Omnibox in Google Chrome on Android prior to 141.0.7390.54 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2025-11208Nov 6, 2025affected < 141.0.7390.76-bp160.1.1fixed 141.0.7390.76-bp160.1.1
Inappropriate implementation in Media in Google Chrome prior to 141.0.7390.54 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2025-11207Nov 6, 2025affected < 141.0.7390.76-bp160.1.1fixed 141.0.7390.76-bp160.1.1
Side-channel information leakage in Storage in Google Chrome prior to 141.0.7390.54 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2025-11206Nov 6, 2025affected < 141.0.7390.76-bp160.1.1fixed 141.0.7390.76-bp160.1.1
Heap buffer overflow in Video in Google Chrome prior to 141.0.7390.54 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
- CVE-2025-11205Nov 6, 2025affected < 141.0.7390.76-bp160.1.1fixed 141.0.7390.76-bp160.1.1
Heap buffer overflow in WebGPU in Google Chrome prior to 141.0.7390.54 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2025-10892Sep 24, 2025affected < 141.0.7390.76-bp160.1.1fixed 141.0.7390.76-bp160.1.1
Integer overflow in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2025-10891Sep 24, 2025affected < 141.0.7390.76-bp160.1.1fixed 141.0.7390.76-bp160.1.1
Integer overflow in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2025-10890Sep 24, 2025affected < 141.0.7390.76-bp160.1.1fixed 141.0.7390.76-bp160.1.1
Side-channel information leakage in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
- affected < 145.0.7632.116-bp160.1.1fixed 145.0.7632.116-bp160.1.1
The Shopper Approved Reviews plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the ajax_callback_update_sa_option() function in versions 2.0 to 2.1. This makes it possible for authent
Page 18 of 18