rpm package
opensuse/opera&distro=openSUSE Leap 15.1 NonFree
pkg:rpm/opensuse/opera&distro=openSUSE%20Leap%2015.1%20NonFree
Vulnerabilities (103)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2020-6521 | — | < 70.0.3728.71-lp151.2.24.1 | 70.0.3728.71-lp151.2.24.1 | Jul 22, 2020 | Side-channel information leakage in autofill in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. | ||
| CVE-2020-6520 | — | < 70.0.3728.71-lp151.2.24.1 | 70.0.3728.71-lp151.2.24.1 | Jul 22, 2020 | Buffer overflow in Skia in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | ||
| CVE-2020-6519 | — | < 70.0.3728.71-lp151.2.24.1 | 70.0.3728.71-lp151.2.24.1 | Jul 22, 2020 | Policy bypass in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass content security policy via a crafted HTML page. | ||
| CVE-2020-6518 | — | < 70.0.3728.71-lp151.2.24.1 | 70.0.3728.71-lp151.2.24.1 | Jul 22, 2020 | Use after free in developer tools in Google Chrome prior to 84.0.4147.89 allowed a remote attacker who had convinced the user to use developer tools to potentially exploit heap corruption via a crafted HTML page. | ||
| CVE-2020-6517 | — | < 70.0.3728.71-lp151.2.24.1 | 70.0.3728.71-lp151.2.24.1 | Jul 22, 2020 | Heap buffer overflow in history in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | ||
| CVE-2020-6516 | — | < 70.0.3728.71-lp151.2.24.1 | 70.0.3728.71-lp151.2.24.1 | Jul 22, 2020 | Policy bypass in CORS in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to leak cross-origin data via a crafted HTML page. | ||
| CVE-2020-6515 | — | < 70.0.3728.71-lp151.2.24.1 | 70.0.3728.71-lp151.2.24.1 | Jul 22, 2020 | Use after free in tab strip in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | ||
| CVE-2020-6514 | — | < 70.0.3728.71-lp151.2.24.1 | 70.0.3728.71-lp151.2.24.1 | Jul 22, 2020 | Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in a privileged network position to potentially exploit heap corruption via a crafted SCTP stream. | ||
| CVE-2020-6513 | — | < 70.0.3728.71-lp151.2.24.1 | 70.0.3728.71-lp151.2.24.1 | Jul 22, 2020 | Heap buffer overflow in PDFium in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. | ||
| CVE-2020-6512 | — | < 70.0.3728.71-lp151.2.24.1 | 70.0.3728.71-lp151.2.24.1 | Jul 22, 2020 | Type Confusion in V8 in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | ||
| CVE-2020-6511 | — | < 70.0.3728.71-lp151.2.24.1 | 70.0.3728.71-lp151.2.24.1 | Jul 22, 2020 | Information leak in content security policy in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to leak cross-origin data via a crafted HTML page. | ||
| CVE-2020-6510 | — | < 70.0.3728.71-lp151.2.24.1 | 70.0.3728.71-lp151.2.24.1 | Jul 22, 2020 | Heap buffer overflow in background fetch in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | ||
| CVE-2020-6509 | — | < 69.0.3686.49-lp151.2.21.1 | 69.0.3686.49-lp151.2.21.1 | Jul 22, 2020 | Use after free in extensions in Google Chrome prior to 83.0.4103.116 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension. | ||
| CVE-2020-6831 | — | < 68.0.3618.104-lp151.2.18.1 | 68.0.3618.104-lp151.2.18.1 | May 26, 2020 | A buffer overflow could occur when parsing and validating SCTP chunks in WebRTC. This could have led to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox ESR < 68.8, Firefox < 76, and Thunderbird < 68.8.0. | ||
| CVE-2020-6464 | — | < 68.0.3618.104-lp151.2.18.1 | 68.0.3618.104-lp151.2.18.1 | May 21, 2020 | Type confusion in Blink in Google Chrome prior to 81.0.4044.138 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | ||
| CVE-2020-6462 | — | < 68.0.3618.63-lp151.2.15.1 | 68.0.3618.63-lp151.2.15.1 | May 21, 2020 | Use after free in task scheduling in Google Chrome prior to 81.0.4044.129 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | ||
| CVE-2020-6461 | — | < 68.0.3618.63-lp151.2.15.1 | 68.0.3618.63-lp151.2.15.1 | May 21, 2020 | Use after free in storage in Google Chrome prior to 81.0.4044.129 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | ||
| CVE-2020-6460 | — | < 68.0.3618.63-lp151.2.15.1 | 68.0.3618.63-lp151.2.15.1 | May 21, 2020 | Insufficient data validation in URL formatting in Google Chrome prior to 81.0.4044.122 allowed a remote attacker to perform domain spoofing via a crafted domain name. | ||
| CVE-2020-6459 | — | < 68.0.3618.63-lp151.2.15.1 | 68.0.3618.63-lp151.2.15.1 | May 21, 2020 | Use after free in payments in Google Chrome prior to 81.0.4044.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | ||
| CVE-2020-6458 | — | < 68.0.3618.63-lp151.2.15.1 | 68.0.3618.63-lp151.2.15.1 | May 21, 2020 | Out of bounds read and write in PDFium in Google Chrome prior to 81.0.4044.122 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. |
- CVE-2020-6521Jul 22, 2020affected < 70.0.3728.71-lp151.2.24.1fixed 70.0.3728.71-lp151.2.24.1
Side-channel information leakage in autofill in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
- CVE-2020-6520Jul 22, 2020affected < 70.0.3728.71-lp151.2.24.1fixed 70.0.3728.71-lp151.2.24.1
Buffer overflow in Skia in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2020-6519Jul 22, 2020affected < 70.0.3728.71-lp151.2.24.1fixed 70.0.3728.71-lp151.2.24.1
Policy bypass in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass content security policy via a crafted HTML page.
- CVE-2020-6518Jul 22, 2020affected < 70.0.3728.71-lp151.2.24.1fixed 70.0.3728.71-lp151.2.24.1
Use after free in developer tools in Google Chrome prior to 84.0.4147.89 allowed a remote attacker who had convinced the user to use developer tools to potentially exploit heap corruption via a crafted HTML page.
- CVE-2020-6517Jul 22, 2020affected < 70.0.3728.71-lp151.2.24.1fixed 70.0.3728.71-lp151.2.24.1
Heap buffer overflow in history in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2020-6516Jul 22, 2020affected < 70.0.3728.71-lp151.2.24.1fixed 70.0.3728.71-lp151.2.24.1
Policy bypass in CORS in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
- CVE-2020-6515Jul 22, 2020affected < 70.0.3728.71-lp151.2.24.1fixed 70.0.3728.71-lp151.2.24.1
Use after free in tab strip in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2020-6514Jul 22, 2020affected < 70.0.3728.71-lp151.2.24.1fixed 70.0.3728.71-lp151.2.24.1
Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in a privileged network position to potentially exploit heap corruption via a crafted SCTP stream.
- CVE-2020-6513Jul 22, 2020affected < 70.0.3728.71-lp151.2.24.1fixed 70.0.3728.71-lp151.2.24.1
Heap buffer overflow in PDFium in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
- CVE-2020-6512Jul 22, 2020affected < 70.0.3728.71-lp151.2.24.1fixed 70.0.3728.71-lp151.2.24.1
Type Confusion in V8 in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2020-6511Jul 22, 2020affected < 70.0.3728.71-lp151.2.24.1fixed 70.0.3728.71-lp151.2.24.1
Information leak in content security policy in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
- CVE-2020-6510Jul 22, 2020affected < 70.0.3728.71-lp151.2.24.1fixed 70.0.3728.71-lp151.2.24.1
Heap buffer overflow in background fetch in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2020-6509Jul 22, 2020affected < 69.0.3686.49-lp151.2.21.1fixed 69.0.3686.49-lp151.2.21.1
Use after free in extensions in Google Chrome prior to 83.0.4103.116 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.
- CVE-2020-6831May 26, 2020affected < 68.0.3618.104-lp151.2.18.1fixed 68.0.3618.104-lp151.2.18.1
A buffer overflow could occur when parsing and validating SCTP chunks in WebRTC. This could have led to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox ESR < 68.8, Firefox < 76, and Thunderbird < 68.8.0.
- CVE-2020-6464May 21, 2020affected < 68.0.3618.104-lp151.2.18.1fixed 68.0.3618.104-lp151.2.18.1
Type confusion in Blink in Google Chrome prior to 81.0.4044.138 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2020-6462May 21, 2020affected < 68.0.3618.63-lp151.2.15.1fixed 68.0.3618.63-lp151.2.15.1
Use after free in task scheduling in Google Chrome prior to 81.0.4044.129 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
- CVE-2020-6461May 21, 2020affected < 68.0.3618.63-lp151.2.15.1fixed 68.0.3618.63-lp151.2.15.1
Use after free in storage in Google Chrome prior to 81.0.4044.129 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
- CVE-2020-6460May 21, 2020affected < 68.0.3618.63-lp151.2.15.1fixed 68.0.3618.63-lp151.2.15.1
Insufficient data validation in URL formatting in Google Chrome prior to 81.0.4044.122 allowed a remote attacker to perform domain spoofing via a crafted domain name.
- CVE-2020-6459May 21, 2020affected < 68.0.3618.63-lp151.2.15.1fixed 68.0.3618.63-lp151.2.15.1
Use after free in payments in Google Chrome prior to 81.0.4044.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2020-6458May 21, 2020affected < 68.0.3618.63-lp151.2.15.1fixed 68.0.3618.63-lp151.2.15.1
Out of bounds read and write in PDFium in Google Chrome prior to 81.0.4044.122 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
Page 5 of 6