VYPR

rpm package

opensuse/chromium&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/chromium&distro=openSUSE%20Tumbleweed

Vulnerabilities (5,785)

  • CVE-2012-2891Sep 26, 2012
    affected < 55.0.2883.75-3.1fixed 55.0.2883.75-3.1

    The IPC implementation in Google Chrome before 22.0.1229.79 allows attackers to obtain potentially sensitive information about memory addresses via unspecified vectors.

  • CVE-2012-2889Sep 26, 2012
    affected < 55.0.2883.75-3.1fixed 55.0.2883.75-3.1

    Cross-site scripting (XSS) vulnerability in Google Chrome before 22.0.1229.79 allows remote attackers to inject arbitrary web script or HTML via vectors involving frames, aka "Universal XSS (UXSS)."

  • CVE-2012-2888Sep 26, 2012
    affected < 55.0.2883.75-3.1fixed 55.0.2883.75-3.1

    Use-after-free vulnerability in Google Chrome before 22.0.1229.79 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving SVG text references.

  • CVE-2012-2887Sep 26, 2012
    affected < 55.0.2883.75-3.1fixed 55.0.2883.75-3.1

    Use-after-free vulnerability in Google Chrome before 22.0.1229.79 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving onclick events.

  • CVE-2012-2886Sep 26, 2012
    affected < 55.0.2883.75-3.1fixed 55.0.2883.75-3.1

    Cross-site scripting (XSS) vulnerability in Google Chrome before 22.0.1229.79 allows remote attackers to inject arbitrary web script or HTML via vectors related to the Google V8 bindings, aka "Universal XSS (UXSS)."

  • CVE-2012-2885Sep 26, 2012
    affected < 55.0.2883.75-3.1fixed 55.0.2883.75-3.1

    Double free vulnerability in Google Chrome before 22.0.1229.79 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to application exit.

  • CVE-2012-2884Sep 26, 2012
    affected < 55.0.2883.75-3.1fixed 55.0.2883.75-3.1

    Skia, as used in Google Chrome before 22.0.1229.79, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

  • CVE-2012-2883Sep 26, 2012
    affected < 55.0.2883.75-3.1fixed 55.0.2883.75-3.1

    Skia, as used in Google Chrome before 22.0.1229.79, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger an out-of-bounds write operation, a different vulnerability than CVE-2012-2874.

  • CVE-2012-2882Sep 26, 2012
    affected < 55.0.2883.75-3.1fixed 55.0.2883.75-3.1

    FFmpeg, as used in Google Chrome before 22.0.1229.79, does not properly handle OGG containers, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors, related to a "wild pointer" issue.

  • CVE-2012-2881Sep 26, 2012
    affected < 55.0.2883.75-3.1fixed 55.0.2883.75-3.1

    Google Chrome before 22.0.1229.79 does not properly handle plug-ins, which allows remote attackers to cause a denial of service (DOM tree corruption) or possibly have unspecified other impact via unknown vectors.

  • CVE-2012-2880Sep 26, 2012
    affected < 55.0.2883.75-3.1fixed 55.0.2883.75-3.1

    Race condition in Google Chrome before 22.0.1229.79 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the plug-in paint buffer.

  • CVE-2012-2879Sep 26, 2012
    affected < 55.0.2883.75-3.1fixed 55.0.2883.75-3.1

    Google Chrome before 22.0.1229.79 allows remote attackers to cause a denial of service (DOM topology corruption) via a crafted document.

  • CVE-2012-2878Sep 26, 2012
    affected < 55.0.2883.75-3.1fixed 55.0.2883.75-3.1

    Use-after-free vulnerability in Google Chrome before 22.0.1229.79 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to plug-in handling.

  • CVE-2012-2877Sep 26, 2012
    affected < 55.0.2883.75-3.1fixed 55.0.2883.75-3.1

    The extension system in Google Chrome before 22.0.1229.79 does not properly handle modal dialogs, which allows remote attackers to cause a denial of service (application crash) via unspecified vectors.

  • CVE-2012-2876Sep 26, 2012
    affected < 55.0.2883.75-3.1fixed 55.0.2883.75-3.1

    Buffer overflow in the SSE2 optimization functionality in Google Chrome before 22.0.1229.79 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

  • CVE-2012-2874Sep 26, 2012
    affected < 55.0.2883.75-3.1fixed 55.0.2883.75-3.1

    Skia, as used in Google Chrome before 22.0.1229.79, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger an out-of-bounds write operation, a different vulnerability than CVE-2012-2883.

  • CVE-2012-2872Aug 31, 2012
    affected < 55.0.2883.75-3.1fixed 55.0.2883.75-3.1

    Cross-site scripting (XSS) vulnerability in an SSL interstitial page in Google Chrome before 21.0.1180.89 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2012-2871Aug 31, 2012
    affected < 55.0.2883.75-3.1fixed 55.0.2883.75-3.1

    libxml2 2.9.0-rc1 and earlier, as used in Google Chrome before 21.0.1180.89, does not properly support a cast of an unspecified variable during handling of XSL transforms, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a craft

  • CVE-2012-2870Aug 31, 2012
    affected < 55.0.2883.75-3.1fixed 55.0.2883.75-3.1

    libxslt 1.1.26 and earlier, as used in Google Chrome before 21.0.1180.89, does not properly manage memory, which might allow remote attackers to cause a denial of service (application crash) via a crafted XSLT expression that is not properly identified during XPath navigation, re

  • CVE-2012-2869Aug 31, 2012
    affected < 55.0.2883.75-3.1fixed 55.0.2883.75-3.1

    Google Chrome before 21.0.1180.89 does not properly load URLs, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger a "stale buffer."

Page 282 of 290