rpm package
opensuse/chromium&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/chromium&distro=openSUSE%20Tumbleweed
Vulnerabilities (4,970)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2015-6756 | — | < 55.0.2883.75-3.1 | 55.0.2883.75-3.1 | Oct 15, 2015 | Use-after-free vulnerability in the CPDFSDK_PageView implementation in fpdfsdk/src/fsdk_mgr.cpp in PDFium, as used in Google Chrome before 46.0.2490.71, allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact by leve | ||
| CVE-2015-6755 | — | < 55.0.2883.75-3.1 | 55.0.2883.75-3.1 | Oct 15, 2015 | The ContainerNode::parserInsertBefore function in core/dom/ContainerNode.cpp in Blink, as used in Google Chrome before 46.0.2490.71, proceeds with a DOM tree insertion in certain cases where a parent node no longer contains a child node, which allows remote attackers to bypass th | ||
| CVE-2015-1304 | — | < 55.0.2883.75-3.1 | 55.0.2883.75-3.1 | Oct 12, 2015 | object-observe.js in Google V8, as used in Google Chrome before 45.0.2454.101, does not properly restrict method calls on access-checked objects, which allows remote attackers to bypass the Same Origin Policy via a (1) observe or (2) getNotifier call. | ||
| CVE-2015-1303 | — | < 55.0.2883.75-3.1 | 55.0.2883.75-3.1 | Oct 12, 2015 | bindings/core/v8/V8DOMWrapper.h in Blink, as used in Google Chrome before 45.0.2454.101, does not perform a rethrow action to propagate information about a cross-context exception, which allows remote attackers to bypass the Same Origin Policy via a crafted HTML document containi | ||
| CVE-2015-1301 | — | < 55.0.2883.75-3.1 | 55.0.2883.75-3.1 | Sep 3, 2015 | Multiple unspecified vulnerabilities in Google Chrome before 45.0.2454.85 allow attackers to cause a denial of service or possibly have other impact via unknown vectors. | ||
| CVE-2015-1300 | — | < 55.0.2883.75-3.1 | 55.0.2883.75-3.1 | Sep 3, 2015 | The FrameFetchContext::updateTimingInfoForIFrameNavigation function in core/loader/FrameFetchContext.cpp in Blink, as used in Google Chrome before 45.0.2454.85, does not properly restrict the availability of IFRAME Resource Timing API times, which allows remote attackers to obtai | ||
| CVE-2015-1299 | — | < 55.0.2883.75-3.1 | 55.0.2883.75-3.1 | Sep 3, 2015 | Use-after-free vulnerability in the shared-timer implementation in Blink, as used in Google Chrome before 45.0.2454.85, allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging erroneous timer firing, related to ThreadTimers.cpp | ||
| CVE-2015-1298 | — | < 55.0.2883.75-3.1 | 55.0.2883.75-3.1 | Sep 3, 2015 | The RuntimeEventRouter::OnExtensionUninstalled function in extensions/browser/api/runtime/runtime_api.cc in Google Chrome before 45.0.2454.85 does not ensure that the setUninstallURL preference corresponds to the URL of a web site, which allows user-assisted remote attackers to t | ||
| CVE-2015-1297 | — | < 55.0.2883.75-3.1 | 55.0.2883.75-3.1 | Sep 3, 2015 | The WebRequest API implementation in extensions/browser/api/web_request/web_request_api.cc in Google Chrome before 45.0.2454.85 does not properly consider a request's source before accepting the request, which allows remote attackers to bypass intended access restrictions via a c | ||
| CVE-2015-1296 | — | < 55.0.2883.75-3.1 | 55.0.2883.75-3.1 | Sep 3, 2015 | The UnescapeURLWithAdjustmentsImpl implementation in net/base/escape.cc in Google Chrome before 45.0.2454.85 does not prevent display of Unicode LOCK characters in the omnibox, which makes it easier for remote attackers to spoof the SSL lock icon by placing one of these character | ||
| CVE-2015-1295 | — | < 55.0.2883.75-3.1 | 55.0.2883.75-3.1 | Sep 3, 2015 | Multiple use-after-free vulnerabilities in the PrintWebViewHelper class in components/printing/renderer/print_web_view_helper.cc in Google Chrome before 45.0.2454.85 allow user-assisted remote attackers to cause a denial of service or possibly have unspecified other impact by tri | ||
| CVE-2015-1294 | — | < 55.0.2883.75-3.1 | 55.0.2883.75-3.1 | Sep 3, 2015 | Use-after-free vulnerability in the SkMatrix::invertNonIdentity function in core/SkMatrix.cpp in Skia, as used in Google Chrome before 45.0.2454.85, allows remote attackers to cause a denial of service or possibly have unspecified other impact by triggering the use of matrix elem | ||
| CVE-2015-1293 | — | < 55.0.2883.75-3.1 | 55.0.2883.75-3.1 | Sep 3, 2015 | The DOM implementation in Blink, as used in Google Chrome before 45.0.2454.85, allows remote attackers to bypass the Same Origin Policy via unspecified vectors. | ||
| CVE-2015-1292 | — | < 55.0.2883.75-3.1 | 55.0.2883.75-3.1 | Sep 3, 2015 | The NavigatorServiceWorker::serviceWorker function in modules/serviceworkers/NavigatorServiceWorker.cpp in Blink, as used in Google Chrome before 45.0.2454.85, allows remote attackers to bypass the Same Origin Policy by accessing a Service Worker. | ||
| CVE-2015-1291 | — | < 55.0.2883.75-3.1 | 55.0.2883.75-3.1 | Sep 3, 2015 | The ContainerNode::parserRemoveChild function in core/dom/ContainerNode.cpp in Blink, as used in Google Chrome before 45.0.2454.85, does not check whether a node is expected, which allows remote attackers to bypass the Same Origin Policy or cause a denial of service (DOM tree cor | ||
| CVE-2015-1289 | — | < 55.0.2883.75-3.1 | 55.0.2883.75-3.1 | Jul 23, 2015 | Multiple unspecified vulnerabilities in Google Chrome before 44.0.2403.89 allow attackers to cause a denial of service or possibly have other impact via unknown vectors. | ||
| CVE-2015-1288 | — | < 55.0.2883.75-3.1 | 55.0.2883.75-3.1 | Jul 23, 2015 | The Spellcheck API implementation in Google Chrome before 44.0.2403.89 does not use an HTTPS session for downloading a Hunspell dictionary, which allows man-in-the-middle attackers to deliver incorrect spelling suggestions or possibly have unspecified other impact via a crafted f | ||
| CVE-2015-1287 | — | < 55.0.2883.75-3.1 | 55.0.2883.75-3.1 | Jul 23, 2015 | Blink, as used in Google Chrome before 44.0.2403.89, enables a quirks-mode exception that limits the cases in which a Cascading Style Sheets (CSS) document is required to have the text/css content type, which allows remote attackers to bypass the Same Origin Policy via a crafted | ||
| CVE-2015-1286 | — | < 55.0.2883.75-3.1 | 55.0.2883.75-3.1 | Jul 23, 2015 | Cross-site scripting (XSS) vulnerability in the V8ContextNativeHandler::GetModuleSystem function in extensions/renderer/v8_context_native_handler.cc in Google Chrome before 44.0.2403.89 allows remote attackers to inject arbitrary web script or HTML by leveraging the lack of a cer | ||
| CVE-2015-1285 | — | < 55.0.2883.75-3.1 | 55.0.2883.75-3.1 | Jul 23, 2015 | The XSSAuditor::canonicalize function in core/html/parser/XSSAuditor.cpp in the XSS auditor in Blink, as used in Google Chrome before 44.0.2403.89, does not properly choose a truncation point, which makes it easier for remote attackers to obtain sensitive information via an unspe |
- CVE-2015-6756Oct 15, 2015affected < 55.0.2883.75-3.1fixed 55.0.2883.75-3.1
Use-after-free vulnerability in the CPDFSDK_PageView implementation in fpdfsdk/src/fsdk_mgr.cpp in PDFium, as used in Google Chrome before 46.0.2490.71, allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact by leve
- CVE-2015-6755Oct 15, 2015affected < 55.0.2883.75-3.1fixed 55.0.2883.75-3.1
The ContainerNode::parserInsertBefore function in core/dom/ContainerNode.cpp in Blink, as used in Google Chrome before 46.0.2490.71, proceeds with a DOM tree insertion in certain cases where a parent node no longer contains a child node, which allows remote attackers to bypass th
- CVE-2015-1304Oct 12, 2015affected < 55.0.2883.75-3.1fixed 55.0.2883.75-3.1
object-observe.js in Google V8, as used in Google Chrome before 45.0.2454.101, does not properly restrict method calls on access-checked objects, which allows remote attackers to bypass the Same Origin Policy via a (1) observe or (2) getNotifier call.
- CVE-2015-1303Oct 12, 2015affected < 55.0.2883.75-3.1fixed 55.0.2883.75-3.1
bindings/core/v8/V8DOMWrapper.h in Blink, as used in Google Chrome before 45.0.2454.101, does not perform a rethrow action to propagate information about a cross-context exception, which allows remote attackers to bypass the Same Origin Policy via a crafted HTML document containi
- CVE-2015-1301Sep 3, 2015affected < 55.0.2883.75-3.1fixed 55.0.2883.75-3.1
Multiple unspecified vulnerabilities in Google Chrome before 45.0.2454.85 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
- CVE-2015-1300Sep 3, 2015affected < 55.0.2883.75-3.1fixed 55.0.2883.75-3.1
The FrameFetchContext::updateTimingInfoForIFrameNavigation function in core/loader/FrameFetchContext.cpp in Blink, as used in Google Chrome before 45.0.2454.85, does not properly restrict the availability of IFRAME Resource Timing API times, which allows remote attackers to obtai
- CVE-2015-1299Sep 3, 2015affected < 55.0.2883.75-3.1fixed 55.0.2883.75-3.1
Use-after-free vulnerability in the shared-timer implementation in Blink, as used in Google Chrome before 45.0.2454.85, allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging erroneous timer firing, related to ThreadTimers.cpp
- CVE-2015-1298Sep 3, 2015affected < 55.0.2883.75-3.1fixed 55.0.2883.75-3.1
The RuntimeEventRouter::OnExtensionUninstalled function in extensions/browser/api/runtime/runtime_api.cc in Google Chrome before 45.0.2454.85 does not ensure that the setUninstallURL preference corresponds to the URL of a web site, which allows user-assisted remote attackers to t
- CVE-2015-1297Sep 3, 2015affected < 55.0.2883.75-3.1fixed 55.0.2883.75-3.1
The WebRequest API implementation in extensions/browser/api/web_request/web_request_api.cc in Google Chrome before 45.0.2454.85 does not properly consider a request's source before accepting the request, which allows remote attackers to bypass intended access restrictions via a c
- CVE-2015-1296Sep 3, 2015affected < 55.0.2883.75-3.1fixed 55.0.2883.75-3.1
The UnescapeURLWithAdjustmentsImpl implementation in net/base/escape.cc in Google Chrome before 45.0.2454.85 does not prevent display of Unicode LOCK characters in the omnibox, which makes it easier for remote attackers to spoof the SSL lock icon by placing one of these character
- CVE-2015-1295Sep 3, 2015affected < 55.0.2883.75-3.1fixed 55.0.2883.75-3.1
Multiple use-after-free vulnerabilities in the PrintWebViewHelper class in components/printing/renderer/print_web_view_helper.cc in Google Chrome before 45.0.2454.85 allow user-assisted remote attackers to cause a denial of service or possibly have unspecified other impact by tri
- CVE-2015-1294Sep 3, 2015affected < 55.0.2883.75-3.1fixed 55.0.2883.75-3.1
Use-after-free vulnerability in the SkMatrix::invertNonIdentity function in core/SkMatrix.cpp in Skia, as used in Google Chrome before 45.0.2454.85, allows remote attackers to cause a denial of service or possibly have unspecified other impact by triggering the use of matrix elem
- CVE-2015-1293Sep 3, 2015affected < 55.0.2883.75-3.1fixed 55.0.2883.75-3.1
The DOM implementation in Blink, as used in Google Chrome before 45.0.2454.85, allows remote attackers to bypass the Same Origin Policy via unspecified vectors.
- CVE-2015-1292Sep 3, 2015affected < 55.0.2883.75-3.1fixed 55.0.2883.75-3.1
The NavigatorServiceWorker::serviceWorker function in modules/serviceworkers/NavigatorServiceWorker.cpp in Blink, as used in Google Chrome before 45.0.2454.85, allows remote attackers to bypass the Same Origin Policy by accessing a Service Worker.
- CVE-2015-1291Sep 3, 2015affected < 55.0.2883.75-3.1fixed 55.0.2883.75-3.1
The ContainerNode::parserRemoveChild function in core/dom/ContainerNode.cpp in Blink, as used in Google Chrome before 45.0.2454.85, does not check whether a node is expected, which allows remote attackers to bypass the Same Origin Policy or cause a denial of service (DOM tree cor
- CVE-2015-1289Jul 23, 2015affected < 55.0.2883.75-3.1fixed 55.0.2883.75-3.1
Multiple unspecified vulnerabilities in Google Chrome before 44.0.2403.89 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
- CVE-2015-1288Jul 23, 2015affected < 55.0.2883.75-3.1fixed 55.0.2883.75-3.1
The Spellcheck API implementation in Google Chrome before 44.0.2403.89 does not use an HTTPS session for downloading a Hunspell dictionary, which allows man-in-the-middle attackers to deliver incorrect spelling suggestions or possibly have unspecified other impact via a crafted f
- CVE-2015-1287Jul 23, 2015affected < 55.0.2883.75-3.1fixed 55.0.2883.75-3.1
Blink, as used in Google Chrome before 44.0.2403.89, enables a quirks-mode exception that limits the cases in which a Cascading Style Sheets (CSS) document is required to have the text/css content type, which allows remote attackers to bypass the Same Origin Policy via a crafted
- CVE-2015-1286Jul 23, 2015affected < 55.0.2883.75-3.1fixed 55.0.2883.75-3.1
Cross-site scripting (XSS) vulnerability in the V8ContextNativeHandler::GetModuleSystem function in extensions/renderer/v8_context_native_handler.cc in Google Chrome before 44.0.2403.89 allows remote attackers to inject arbitrary web script or HTML by leveraging the lack of a cer
- CVE-2015-1285Jul 23, 2015affected < 55.0.2883.75-3.1fixed 55.0.2883.75-3.1
The XSSAuditor::canonicalize function in core/html/parser/XSSAuditor.cpp in the XSS auditor in Blink, as used in Google Chrome before 44.0.2403.89, does not properly choose a truncation point, which makes it easier for remote attackers to obtain sensitive information via an unspe
Page 225 of 249