VYPR

rpm package

opensuse/chromium&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/chromium&distro=openSUSE%20Tumbleweed

Vulnerabilities (4,985)

  • CVE-2017-5125HigFeb 7, 2018
    affected < 93.0.4577.82-1.1fixed 93.0.4577.82-1.1

    Heap buffer overflow in Skia in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2017-5124MedFeb 7, 2018
    affected < 93.0.4577.82-1.1fixed 93.0.4577.82-1.1

    Incorrect application of sandboxing in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted MHTML page.

  • CVE-2017-15395MedFeb 7, 2018
    affected < 93.0.4577.82-1.1fixed 93.0.4577.82-1.1

    A use after free in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page, aka an ImageCapture NULL pointer dereference.

  • CVE-2017-15394MedFeb 7, 2018
    affected < 93.0.4577.82-1.1fixed 93.0.4577.82-1.1

    Insufficient Policy Enforcement in Extensions in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to perform domain spoofing in permission dialogs via IDN homographs in a crafted Chrome Extension.

  • CVE-2017-15393HigFeb 7, 2018
    affected < 93.0.4577.82-1.1fixed 93.0.4577.82-1.1

    Insufficient Policy Enforcement in Devtools remote debugging in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to obtain access to remote debugging functionality via a crafted HTML page, aka a Referer leak.

  • CVE-2017-15392MedFeb 7, 2018
    affected < 93.0.4577.82-1.1fixed 93.0.4577.82-1.1

    Insufficient data validation in V8 in Google Chrome prior to 62.0.3202.62 allowed an attacker who can write to the Windows Registry to potentially exploit heap corruption via a crafted Windows Registry entry, related to PlatformIntegration.

  • CVE-2017-15391MedFeb 7, 2018
    affected < 93.0.4577.82-1.1fixed 93.0.4577.82-1.1

    Insufficient Policy Enforcement in Extensions in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to access Extension pages without authorisation via a crafted HTML page.

  • CVE-2017-15390MedFeb 7, 2018
    affected < 93.0.4577.82-1.1fixed 93.0.4577.82-1.1

    Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to perform domain spoofing via IDN homographs in a crafted domain name.

  • CVE-2017-15389MedFeb 7, 2018
    affected < 93.0.4577.82-1.1fixed 93.0.4577.82-1.1

    An insufficient watchdog timer in navigation in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

  • CVE-2017-15388HigFeb 7, 2018
    affected < 93.0.4577.82-1.1fixed 93.0.4577.82-1.1

    Iteration through non-finite points in Skia in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

  • CVE-2017-15387HigFeb 7, 2018
    affected < 93.0.4577.82-1.1fixed 93.0.4577.82-1.1

    Insufficient enforcement of Content Security Policy in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to open javascript: URL windows when they should not be allowed to via a crafted HTML page.

  • CVE-2017-15386MedFeb 7, 2018
    affected < 93.0.4577.82-1.1fixed 93.0.4577.82-1.1

    Incorrect implementation in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

  • CVE-2018-6406HigJan 30, 2018
    affected < 93.0.4577.82-1.1fixed 93.0.4577.82-1.1

    The function ParseVP9SuperFrameIndex in common/libwebm_util.cc in libwebm through 2018-01-30 does not validate the child_frame_length data obtained from a .webm file, which allows remote attackers to cause an information leak or a denial of service (heap-based buffer over-read an

  • CVE-2017-11225CriDec 9, 2017
    affected < 93.0.4577.82-1.1fixed 93.0.4577.82-1.1

    An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability is an instance of a use after free vulnerability in the Primetime SDK metadata functionality. The mismatch between an old and a new object can provide an attacker with unintended mem

  • CVE-2017-11215CriDec 9, 2017
    affected < 93.0.4577.82-1.1fixed 93.0.4577.82-1.1

    An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability is an instance of a use after free vulnerability in the Primetime SDK. The mismatch between an old and a new object can provide an attacker with unintended memory access -- potential

  • CVE-2017-5122HigOct 27, 2017
    affected < 93.0.4577.82-1.1fixed 93.0.4577.82-1.1

    Inappropriate use of table size handling in V8 in Google Chrome prior to 61.0.3163.100 for Windows allowed a remote attacker to trigger out-of-bounds access via a crafted HTML page.

  • CVE-2017-5121HigOct 27, 2017
    affected < 93.0.4577.82-1.1fixed 93.0.4577.82-1.1

    Inappropriate use of JIT optimisation in V8 in Google Chrome prior to 61.0.3163.100 for Linux, Windows, and Mac allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page, related to the escape analysis phase.

  • CVE-2017-5120MedOct 27, 2017
    affected < 93.0.4577.82-1.1fixed 93.0.4577.82-1.1

    Inappropriate use of www mismatch redirects in browser navigation in Google Chrome prior to 61.0.3163.79 for Mac, Windows, and Linux, and 61.0.3163.81 for Android, allowed a remote attacker to potentially downgrade HTTPS requests to HTTP via a crafted HTML page. In other words, C

  • CVE-2017-5119MedOct 27, 2017
    affected < 93.0.4577.82-1.1fixed 93.0.4577.82-1.1

    Use of an uninitialized value in Skia in Google Chrome prior to 61.0.3163.79 for Mac, Windows, and Linux, and 61.0.3163.81 for Android, allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

  • CVE-2017-5118MedOct 27, 2017
    affected < 93.0.4577.82-1.1fixed 93.0.4577.82-1.1

    Blink in Google Chrome prior to 61.0.3163.79 for Mac, Windows, and Linux, and 61.0.3163.81 for Android, failed to correctly propagate CSP restrictions to javascript scheme pages, which allowed a remote attacker to bypass content security policy via a crafted HTML page.

Page 209 of 250