VYPR

rpm package

opensuse/opera&distro=openSUSE Leap 15.3 NonFree

pkg:rpm/opensuse/opera&distro=openSUSE%20Leap%2015.3%20NonFree

Vulnerabilities (270)

  • CVE-2022-1639HigJul 26, 2022
    affected < 87.0.4390.25-lp153.2.48.1fixed 87.0.4390.25-lp153.2.48.1

    Use after free in ANGLE in Google Chrome prior to 101.0.4951.64 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-1638HigJul 26, 2022
    affected < 87.0.4390.25-lp153.2.48.1fixed 87.0.4390.25-lp153.2.48.1

    Heap buffer overflow in V8 Internationalization in Google Chrome prior to 101.0.4951.64 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-1637MedJul 26, 2022
    affected < 87.0.4390.25-lp153.2.48.1fixed 87.0.4390.25-lp153.2.48.1

    Inappropriate implementation in Web Contents in Google Chrome prior to 101.0.4951.64 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2022-1636HigJul 26, 2022
    affected < 87.0.4390.25-lp153.2.48.1fixed 87.0.4390.25-lp153.2.48.1

    Use after free in Performance APIs in Google Chrome prior to 101.0.4951.64 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-1635HigJul 26, 2022
    affected < 87.0.4390.25-lp153.2.48.1fixed 87.0.4390.25-lp153.2.48.1

    Use after free in Permission Prompts in Google Chrome prior to 101.0.4951.64 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via specific user interactions.

  • CVE-2022-1634HigJul 26, 2022
    affected < 87.0.4390.25-lp153.2.48.1fixed 87.0.4390.25-lp153.2.48.1

    Use after free in Browser UI in Google Chrome prior to 101.0.4951.64 allowed a remote attacker who had convinced a user to engage in specific UI interaction to potentially exploit heap corruption via specific user interactions.

  • CVE-2022-1633HigJul 26, 2022
    affected < 87.0.4390.25-lp153.2.48.1fixed 87.0.4390.25-lp153.2.48.1

    Use after free in Sharesheet in Google Chrome on Chrome OS prior to 101.0.4951.64 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via specific user interactions.

  • CVE-2022-1364HigKEVJul 26, 2022
    affected < 86.0.4363.23-lp153.2.45.1fixed 86.0.4363.23-lp153.2.45.1

    Type confusion in V8 Turbofan in Google Chrome prior to 100.0.4896.127 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-1096HigKEVJul 23, 2022
    affected < 85.0.4341.28-lp153.2.42.1fixed 85.0.4341.28-lp153.2.42.1

    Type confusion in V8 in Google Chrome prior to 99.0.4844.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-0809HigApr 5, 2022
    affected < 85.0.4341.28-lp153.2.42.1fixed 85.0.4341.28-lp153.2.42.1

    Out of bounds memory access in WebXR in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-0808HigApr 5, 2022
    affected < 85.0.4341.28-lp153.2.42.1fixed 85.0.4341.28-lp153.2.42.1

    Use after free in Chrome OS Shell in Google Chrome on Chrome OS prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in a series of user interaction to potentially exploit heap corruption via user interactions.

  • CVE-2022-0807MedApr 5, 2022
    affected < 85.0.4341.28-lp153.2.42.1fixed 85.0.4341.28-lp153.2.42.1

    Inappropriate implementation in Autofill in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

  • CVE-2022-0806MedApr 5, 2022
    affected < 85.0.4341.28-lp153.2.42.1fixed 85.0.4341.28-lp153.2.42.1

    Data leak in Canvas in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in screen sharing to potentially leak cross-origin data via a crafted HTML page.

  • CVE-2022-0805HigApr 5, 2022
    affected < 85.0.4341.28-lp153.2.42.1fixed 85.0.4341.28-lp153.2.42.1

    Use after free in Browser Switcher in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via user interaction.

  • CVE-2022-0804MedApr 5, 2022
    affected < 85.0.4341.28-lp153.2.42.1fixed 85.0.4341.28-lp153.2.42.1

    Inappropriate implementation in Full screen mode in Google Chrome on Android prior to 99.0.4844.51 allowed a remote attacker to hide the contents of the Omnibox (URL bar) via a crafted HTML page.

  • CVE-2022-0803MedApr 5, 2022
    affected < 85.0.4341.28-lp153.2.42.1fixed 85.0.4341.28-lp153.2.42.1

    Inappropriate implementation in Permissions in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to tamper with the contents of the Omnibox (URL bar) via a crafted HTML page.

  • CVE-2022-0802MedApr 5, 2022
    affected < 85.0.4341.28-lp153.2.42.1fixed 85.0.4341.28-lp153.2.42.1

    Inappropriate implementation in Full screen mode in Google Chrome on Android prior to 99.0.4844.51 allowed a remote attacker to hide the contents of the Omnibox (URL bar) via a crafted HTML page.

  • CVE-2022-0800HigApr 5, 2022
    affected < 85.0.4341.28-lp153.2.42.1fixed 85.0.4341.28-lp153.2.42.1

    Heap buffer overflow in Cast UI in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-0799HigApr 5, 2022
    affected < 85.0.4341.28-lp153.2.42.1fixed 85.0.4341.28-lp153.2.42.1

    Insufficient policy enforcement in Installer in Google Chrome on Windows prior to 99.0.4844.51 allowed a remote attacker to perform local privilege escalation via a crafted offline installer file.

  • CVE-2022-0798HigApr 5, 2022
    affected < 85.0.4341.28-lp153.2.42.1fixed 85.0.4341.28-lp153.2.42.1

    Use after free in MediaStream in Google Chrome prior to 99.0.4844.51 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension.

Page 3 of 14