VYPR

rpm package

opensuse/chromium&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/chromium&distro=openSUSE%20Tumbleweed

Vulnerabilities (4,985)

  • CVE-2019-5789HigMay 23, 2019
    affected < 93.0.4577.82-1.1fixed 93.0.4577.82-1.1

    An integer overflow that leads to a use-after-free in WebMIDI in Google Chrome on Windows prior to 73.0.3683.75 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page.

  • CVE-2019-5788HigMay 23, 2019
    affected < 93.0.4577.82-1.1fixed 93.0.4577.82-1.1

    An integer overflow that leads to a use-after-free in Blink Storage in Google Chrome on Linux prior to 73.0.3683.75 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page.

  • CVE-2019-5787HigMay 23, 2019
    affected < 93.0.4577.82-1.1fixed 93.0.4577.82-1.1

    Use-after-garbage-collection in Blink in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2018-5179HigApr 26, 2019
    affected < 93.0.4577.82-1.1fixed 93.0.4577.82-1.1

    A service worker can send the activate event on itself periodically which allows it to run perpetually, allowing it to monitor activity by users. Affects all versions prior to Firefox 60.

  • CVE-2019-5782HigFeb 19, 2019
    affected < 93.0.4577.82-1.1fixed 93.0.4577.82-1.1

    Incorrect optimization assumptions in V8 in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

  • CVE-2019-5781MedFeb 19, 2019
    affected < 93.0.4577.82-1.1fixed 93.0.4577.82-1.1

    Incorrect handling of a confusable character in Omnibox in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.

  • CVE-2019-5780HigFeb 19, 2019
    affected < 93.0.4577.82-1.1fixed 93.0.4577.82-1.1

    Insufficient restrictions on what can be done with Apple Events in Google Chrome on macOS prior to 72.0.3626.81 allowed a local attacker to execute JavaScript via Apple Events.

  • CVE-2019-5779MedFeb 19, 2019
    affected < 93.0.4577.82-1.1fixed 93.0.4577.82-1.1

    Insufficient policy validation in ServiceWorker in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

  • CVE-2019-5778MedFeb 19, 2019
    affected < 93.0.4577.82-1.1fixed 93.0.4577.82-1.1

    A missing case for handling special schemes in permission request checks in Extensions in Google Chrome prior to 72.0.3626.81 allowed an attacker who convinced a user to install a malicious extension to bypass extension permission checks for privileged pages via a crafted Chrome

  • CVE-2019-5777MedFeb 19, 2019
    affected < 93.0.4577.82-1.1fixed 93.0.4577.82-1.1

    Incorrect handling of a confusable character in Omnibox in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.

  • CVE-2019-5776MedFeb 19, 2019
    affected < 93.0.4577.82-1.1fixed 93.0.4577.82-1.1

    Incorrect handling of a confusable character in Omnibox in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.

  • CVE-2019-5775MedFeb 19, 2019
    affected < 93.0.4577.82-1.1fixed 93.0.4577.82-1.1

    Incorrect handling of a confusable character in Omnibox in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.

  • CVE-2019-5774HigFeb 19, 2019
    affected < 93.0.4577.82-1.1fixed 93.0.4577.82-1.1

    Omission of the .desktop filetype from the Safe Browsing checklist in SafeBrowsing in Google Chrome on Linux prior to 72.0.3626.81 allowed an attacker who convinced a user to download a .desktop file to execute arbitrary code via a downloaded .desktop file.

  • CVE-2019-5773MedFeb 19, 2019
    affected < 93.0.4577.82-1.1fixed 93.0.4577.82-1.1

    Insufficient origin validation in IndexedDB in Google Chrome prior to 72.0.3626.81 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page.

  • CVE-2019-5772HigFeb 19, 2019
    affected < 93.0.4577.82-1.1fixed 93.0.4577.82-1.1

    Sharing of objects over calls into JavaScript runtime in PDFium in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.

  • CVE-2019-5771HigFeb 19, 2019
    affected < 93.0.4577.82-1.1fixed 93.0.4577.82-1.1

    An incorrect JIT of GLSL shaders in SwiftShader in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to execute arbitrary code via a crafted HTML page.

  • CVE-2019-5770HigFeb 19, 2019
    affected < 93.0.4577.82-1.1fixed 93.0.4577.82-1.1

    Insufficient input validation in WebGL in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

  • CVE-2019-5769HigFeb 19, 2019
    affected < 93.0.4577.82-1.1fixed 93.0.4577.82-1.1

    Incorrect handling of invalid end character position when front rendering in Blink in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2019-5768MedFeb 19, 2019
    affected < 93.0.4577.82-1.1fixed 93.0.4577.82-1.1

    DevTools API not correctly gating on extension capability in DevTools in Google Chrome prior to 72.0.3626.81 allowed an attacker who convinced a user to install a malicious extension to read local files via a crafted Chrome Extension.

  • CVE-2019-5767MedFeb 19, 2019
    affected < 93.0.4577.82-1.1fixed 93.0.4577.82-1.1

    Insufficient protection of permission UI in WebAPKs in Google Chrome on Android prior to 72.0.3626.81 allowed an attacker who convinced the user to install a malicious application to access privacy/security sensitive web APIs via a crafted APK.

Page 197 of 250