rpm package
opensuse/chromium&distro=openSUSE Leap 15.0
pkg:rpm/opensuse/chromium&distro=openSUSE%20Leap%2015.0
Vulnerabilities (144)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2019-5797 | — | < 73.0.3683.75-lp150.206.1 | 73.0.3683.75-lp150.206.1 | Sep 29, 2022 | Double free in DOMStorage in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | ||
| CVE-2019-5815 | — | < 74.0.3729.108-lp150.209.2 | 74.0.3729.108-lp150.209.2 | Dec 11, 2019 | Type confusion in xsltNumberFormatGetMultipleLevel prior to libxslt 1.1.33 could allow attackers to potentially exploit heap corruption via crafted XML data. | ||
| CVE-2019-5881 | — | < 77.0.3865.75-lp150.239.1 | 77.0.3865.75-lp150.239.1 | Nov 25, 2019 | Out of bounds read in SwiftShader in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. | ||
| CVE-2019-5880 | — | < 77.0.3865.75-lp150.239.1 | 77.0.3865.75-lp150.239.1 | Nov 25, 2019 | Insufficient policy enforcement in Blink in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to leak cross-origin data via a crafted HTML page. | ||
| CVE-2019-5879 | — | < 77.0.3865.75-lp150.239.1 | 77.0.3865.75-lp150.239.1 | Nov 25, 2019 | Insufficient policy enforcement in extensions in Google Chrome prior to 77.0.3865.75 allowed an attacker who convinced a user to install a malicious extension to read local files via a crafted Chrome Extension. | ||
| CVE-2019-5878 | — | < 77.0.3865.75-lp150.239.1 | 77.0.3865.75-lp150.239.1 | Nov 25, 2019 | Use after free in V8 in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | ||
| CVE-2019-5877 | — | < 77.0.3865.75-lp150.239.1 | 77.0.3865.75-lp150.239.1 | Nov 25, 2019 | Out of bounds memory access in JavaScript in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | ||
| CVE-2019-5876 | — | < 77.0.3865.75-lp150.239.1 | 77.0.3865.75-lp150.239.1 | Nov 25, 2019 | Use after free in media in Google Chrome on Android prior to 77.0.3865.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | ||
| CVE-2019-5875 | — | < 77.0.3865.75-lp150.239.1 | 77.0.3865.75-lp150.239.1 | Nov 25, 2019 | Insufficient data validation in downloads in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. | ||
| CVE-2019-5874 | — | < 77.0.3865.75-lp150.239.1 | 77.0.3865.75-lp150.239.1 | Nov 25, 2019 | Insufficient filtering in URI schemes in Google Chrome on Windows prior to 77.0.3865.75 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. | ||
| CVE-2019-5872 | — | < 77.0.3865.75-lp150.239.1 | 77.0.3865.75-lp150.239.1 | Nov 25, 2019 | Use after free in Mojo in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | ||
| CVE-2019-5871 | — | < 77.0.3865.75-lp150.239.1 | 77.0.3865.75-lp150.239.1 | Nov 25, 2019 | Heap buffer overflow in Skia in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | ||
| CVE-2019-5870 | — | < 77.0.3865.75-lp150.239.1 | 77.0.3865.75-lp150.239.1 | Nov 25, 2019 | Use after free in media in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | ||
| CVE-2019-5869 | — | < 76.0.3809.132-lp150.234.1 | 76.0.3809.132-lp150.234.1 | Nov 25, 2019 | Use after free in Blink in Google Chrome prior to 76.0.3809.132 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | ||
| CVE-2019-5868 | — | < 76.0.3809.100-lp150.229.1 | 76.0.3809.100-lp150.229.1 | Nov 25, 2019 | Use after free in PDFium in Google Chrome prior to 76.0.3809.100 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. | ||
| CVE-2019-5867 | — | < 76.0.3809.100-lp150.229.1 | 76.0.3809.100-lp150.229.1 | Nov 25, 2019 | Out of bounds read in JavaScript in Google Chrome prior to 76.0.3809.100 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | ||
| CVE-2019-5865 | — | < 76.0.3809.87-lp150.224.1 | 76.0.3809.87-lp150.224.1 | Nov 25, 2019 | Insufficient policy enforcement in navigations in Google Chrome prior to 76.0.3809.87 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. | ||
| CVE-2019-5864 | — | < 76.0.3809.87-lp150.224.1 | 76.0.3809.87-lp150.224.1 | Nov 25, 2019 | Insufficient data validation in CORS in Google Chrome prior to 76.0.3809.87 allowed an attacker who convinced a user to install a malicious extension to bypass content security policy via a crafted Chrome Extension. | ||
| CVE-2019-5862 | — | < 76.0.3809.87-lp150.224.1 | 76.0.3809.87-lp150.224.1 | Nov 25, 2019 | Insufficient data validation in AppCache in Google Chrome prior to 76.0.3809.87 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. | ||
| CVE-2019-5861 | — | < 76.0.3809.87-lp150.224.1 | 76.0.3809.87-lp150.224.1 | Nov 25, 2019 | Insufficient data validation in Blink in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to bypass anti-clickjacking policy via a crafted HTML page. |
- CVE-2019-5797Sep 29, 2022affected < 73.0.3683.75-lp150.206.1fixed 73.0.3683.75-lp150.206.1
Double free in DOMStorage in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2019-5815Dec 11, 2019affected < 74.0.3729.108-lp150.209.2fixed 74.0.3729.108-lp150.209.2
Type confusion in xsltNumberFormatGetMultipleLevel prior to libxslt 1.1.33 could allow attackers to potentially exploit heap corruption via crafted XML data.
- CVE-2019-5881Nov 25, 2019affected < 77.0.3865.75-lp150.239.1fixed 77.0.3865.75-lp150.239.1
Out of bounds read in SwiftShader in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
- CVE-2019-5880Nov 25, 2019affected < 77.0.3865.75-lp150.239.1fixed 77.0.3865.75-lp150.239.1
Insufficient policy enforcement in Blink in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
- CVE-2019-5879Nov 25, 2019affected < 77.0.3865.75-lp150.239.1fixed 77.0.3865.75-lp150.239.1
Insufficient policy enforcement in extensions in Google Chrome prior to 77.0.3865.75 allowed an attacker who convinced a user to install a malicious extension to read local files via a crafted Chrome Extension.
- CVE-2019-5878Nov 25, 2019affected < 77.0.3865.75-lp150.239.1fixed 77.0.3865.75-lp150.239.1
Use after free in V8 in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2019-5877Nov 25, 2019affected < 77.0.3865.75-lp150.239.1fixed 77.0.3865.75-lp150.239.1
Out of bounds memory access in JavaScript in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2019-5876Nov 25, 2019affected < 77.0.3865.75-lp150.239.1fixed 77.0.3865.75-lp150.239.1
Use after free in media in Google Chrome on Android prior to 77.0.3865.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2019-5875Nov 25, 2019affected < 77.0.3865.75-lp150.239.1fixed 77.0.3865.75-lp150.239.1
Insufficient data validation in downloads in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
- CVE-2019-5874Nov 25, 2019affected < 77.0.3865.75-lp150.239.1fixed 77.0.3865.75-lp150.239.1
Insufficient filtering in URI schemes in Google Chrome on Windows prior to 77.0.3865.75 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
- CVE-2019-5872Nov 25, 2019affected < 77.0.3865.75-lp150.239.1fixed 77.0.3865.75-lp150.239.1
Use after free in Mojo in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2019-5871Nov 25, 2019affected < 77.0.3865.75-lp150.239.1fixed 77.0.3865.75-lp150.239.1
Heap buffer overflow in Skia in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2019-5870Nov 25, 2019affected < 77.0.3865.75-lp150.239.1fixed 77.0.3865.75-lp150.239.1
Use after free in media in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
- CVE-2019-5869Nov 25, 2019affected < 76.0.3809.132-lp150.234.1fixed 76.0.3809.132-lp150.234.1
Use after free in Blink in Google Chrome prior to 76.0.3809.132 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2019-5868Nov 25, 2019affected < 76.0.3809.100-lp150.229.1fixed 76.0.3809.100-lp150.229.1
Use after free in PDFium in Google Chrome prior to 76.0.3809.100 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
- CVE-2019-5867Nov 25, 2019affected < 76.0.3809.100-lp150.229.1fixed 76.0.3809.100-lp150.229.1
Out of bounds read in JavaScript in Google Chrome prior to 76.0.3809.100 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2019-5865Nov 25, 2019affected < 76.0.3809.87-lp150.224.1fixed 76.0.3809.87-lp150.224.1
Insufficient policy enforcement in navigations in Google Chrome prior to 76.0.3809.87 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.
- CVE-2019-5864Nov 25, 2019affected < 76.0.3809.87-lp150.224.1fixed 76.0.3809.87-lp150.224.1
Insufficient data validation in CORS in Google Chrome prior to 76.0.3809.87 allowed an attacker who convinced a user to install a malicious extension to bypass content security policy via a crafted Chrome Extension.
- CVE-2019-5862Nov 25, 2019affected < 76.0.3809.87-lp150.224.1fixed 76.0.3809.87-lp150.224.1
Insufficient data validation in AppCache in Google Chrome prior to 76.0.3809.87 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.
- CVE-2019-5861Nov 25, 2019affected < 76.0.3809.87-lp150.224.1fixed 76.0.3809.87-lp150.224.1
Insufficient data validation in Blink in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to bypass anti-clickjacking policy via a crafted HTML page.
Page 1 of 8