rpm package
opensuse/chromium&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/chromium&distro=openSUSE%20Tumbleweed
Vulnerabilities (4,992)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2024-1077 | Hig | 8.8 | < 121.0.6167.184-1.1 | 121.0.6167.184-1.1 | Jan 30, 2024 | Use after free in Network in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially exploit heap corruption via a malicious file. (Chromium security severity: High) | |
| CVE-2024-1060 | Hig | 8.8 | < 121.0.6167.184-1.1 | 121.0.6167.184-1.1 | Jan 30, 2024 | Use after free in Canvas in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| CVE-2024-1059 | Hig | 8.8 | < 121.0.6167.184-1.1 | 121.0.6167.184-1.1 | Jan 30, 2024 | Use after free in Peer Connection in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially exploit stack corruption via a crafted HTML page. (Chromium security severity: High) | |
| CVE-2024-0814 | Med | 6.5 | < 121.0.6167.184-1.1 | 121.0.6167.184-1.1 | Jan 24, 2024 | Incorrect security UI in Payments in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially spoof security UI via a crafted HTML page. (Chromium security severity: Medium) | |
| CVE-2024-0813 | Hig | 8.8 | < 121.0.6167.184-1.1 | 121.0.6167.184-1.1 | Jan 24, 2024 | Use after free in Reading Mode in Google Chrome prior to 121.0.6167.85 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via specific UI interaction. (Chromium security severity: Medium) | |
| CVE-2024-0812 | Hig | 8.8 | < 121.0.6167.184-1.1 | 121.0.6167.184-1.1 | Jan 24, 2024 | Inappropriate implementation in Accessibility in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High) | |
| CVE-2024-0811 | Med | 4.3 | < 121.0.6167.184-1.1 | 121.0.6167.184-1.1 | Jan 24, 2024 | Inappropriate implementation in Extensions API in Google Chrome prior to 121.0.6167.85 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension. (Chromium security severity: Low) | |
| CVE-2024-0810 | Med | 4.3 | < 121.0.6167.184-1.1 | 121.0.6167.184-1.1 | Jan 24, 2024 | Insufficient policy enforcement in DevTools in Google Chrome prior to 121.0.6167.85 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension. (Chromium security severity: Medium) | |
| CVE-2024-0809 | Med | 4.3 | < 121.0.6167.184-1.1 | 121.0.6167.184-1.1 | Jan 24, 2024 | Inappropriate implementation in Autofill in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to bypass Autofill restrictions via a crafted HTML page. (Chromium security severity: Low) | |
| CVE-2024-0808 | Cri | 9.8 | < 121.0.6167.184-1.1 | 121.0.6167.184-1.1 | Jan 24, 2024 | Integer underflow in WebUI in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit heap corruption via a malicious file. (Chromium security severity: High) | |
| CVE-2024-0807 | Hig | 8.8 | < 121.0.6167.184-1.1 | 121.0.6167.184-1.1 | Jan 24, 2024 | Use after free in Web Audio in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| CVE-2024-0806 | Hig | 8.8 | < 121.0.6167.184-1.1 | 121.0.6167.184-1.1 | Jan 24, 2024 | Use after free in Passwords in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit heap corruption via specific UI interaction. (Chromium security severity: Medium) | |
| CVE-2024-0805 | Med | 4.3 | < 121.0.6167.184-1.1 | 121.0.6167.184-1.1 | Jan 24, 2024 | Inappropriate implementation in Downloads in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to perform domain spoofing via a crafted domain name. (Chromium security severity: Medium) | |
| CVE-2024-0804 | Hig | 7.5 | < 121.0.6167.184-1.1 | 121.0.6167.184-1.1 | Jan 24, 2024 | Insufficient policy enforcement in iOS Security UI in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium) | |
| CVE-2024-0519 | Hig | 8.8 | KEV | < 120.0.6099.224-1.1 | 120.0.6099.224-1.1 | Jan 16, 2024 | Out of bounds memory access in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
| CVE-2024-0518 | Hig | 8.8 | < 120.0.6099.224-1.1 | 120.0.6099.224-1.1 | Jan 16, 2024 | Type confusion in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| CVE-2024-0517 | Hig | 8.8 | < 120.0.6099.224-1.1 | 120.0.6099.224-1.1 | Jan 16, 2024 | Out of bounds write in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| CVE-2024-0333 | Med | 5.3 | < 120.0.6099.216-1.1 | 120.0.6099.216-1.1 | Jan 10, 2024 | Insufficient data validation in Extensions in Google Chrome prior to 120.0.6099.216 allowed an attacker in a privileged network position to install a malicious extension via a crafted HTML page. (Chromium security severity: High) | |
| CVE-2024-0225 | Hig | 8.8 | < 120.0.6099.216-1.1 | 120.0.6099.216-1.1 | Jan 4, 2024 | Use after free in WebGPU in Google Chrome prior to 120.0.6099.199 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| CVE-2024-0224 | Hig | 8.8 | < 120.0.6099.216-1.1 | 120.0.6099.216-1.1 | Jan 4, 2024 | Use after free in WebAudio in Google Chrome prior to 120.0.6099.199 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
- affected < 121.0.6167.184-1.1fixed 121.0.6167.184-1.1
Use after free in Network in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially exploit heap corruption via a malicious file. (Chromium security severity: High)
- affected < 121.0.6167.184-1.1fixed 121.0.6167.184-1.1
Use after free in Canvas in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- affected < 121.0.6167.184-1.1fixed 121.0.6167.184-1.1
Use after free in Peer Connection in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially exploit stack corruption via a crafted HTML page. (Chromium security severity: High)
- affected < 121.0.6167.184-1.1fixed 121.0.6167.184-1.1
Incorrect security UI in Payments in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially spoof security UI via a crafted HTML page. (Chromium security severity: Medium)
- affected < 121.0.6167.184-1.1fixed 121.0.6167.184-1.1
Use after free in Reading Mode in Google Chrome prior to 121.0.6167.85 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via specific UI interaction. (Chromium security severity: Medium)
- affected < 121.0.6167.184-1.1fixed 121.0.6167.184-1.1
Inappropriate implementation in Accessibility in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)
- affected < 121.0.6167.184-1.1fixed 121.0.6167.184-1.1
Inappropriate implementation in Extensions API in Google Chrome prior to 121.0.6167.85 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension. (Chromium security severity: Low)
- affected < 121.0.6167.184-1.1fixed 121.0.6167.184-1.1
Insufficient policy enforcement in DevTools in Google Chrome prior to 121.0.6167.85 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension. (Chromium security severity: Medium)
- affected < 121.0.6167.184-1.1fixed 121.0.6167.184-1.1
Inappropriate implementation in Autofill in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to bypass Autofill restrictions via a crafted HTML page. (Chromium security severity: Low)
- affected < 121.0.6167.184-1.1fixed 121.0.6167.184-1.1
Integer underflow in WebUI in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit heap corruption via a malicious file. (Chromium security severity: High)
- affected < 121.0.6167.184-1.1fixed 121.0.6167.184-1.1
Use after free in Web Audio in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- affected < 121.0.6167.184-1.1fixed 121.0.6167.184-1.1
Use after free in Passwords in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit heap corruption via specific UI interaction. (Chromium security severity: Medium)
- affected < 121.0.6167.184-1.1fixed 121.0.6167.184-1.1
Inappropriate implementation in Downloads in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to perform domain spoofing via a crafted domain name. (Chromium security severity: Medium)
- affected < 121.0.6167.184-1.1fixed 121.0.6167.184-1.1
Insufficient policy enforcement in iOS Security UI in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
- affected < 120.0.6099.224-1.1fixed 120.0.6099.224-1.1
Out of bounds memory access in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- affected < 120.0.6099.224-1.1fixed 120.0.6099.224-1.1
Type confusion in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- affected < 120.0.6099.224-1.1fixed 120.0.6099.224-1.1
Out of bounds write in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- affected < 120.0.6099.216-1.1fixed 120.0.6099.216-1.1
Insufficient data validation in Extensions in Google Chrome prior to 120.0.6099.216 allowed an attacker in a privileged network position to install a malicious extension via a crafted HTML page. (Chromium security severity: High)
- affected < 120.0.6099.216-1.1fixed 120.0.6099.216-1.1
Use after free in WebGPU in Google Chrome prior to 120.0.6099.199 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- affected < 120.0.6099.216-1.1fixed 120.0.6099.216-1.1
Use after free in WebAudio in Google Chrome prior to 120.0.6099.199 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Page 126 of 250