rpm package
opensuse/opera&distro=openSUSE Leap 15.3 NonFree
pkg:rpm/opensuse/opera&distro=openSUSE%20Leap%2015.3%20NonFree
Vulnerabilities (270)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2022-0117 | Med | 6.5 | < 83.0.4254.27-lp153.2.33.1 | 83.0.4254.27-lp153.2.33.1 | Feb 12, 2022 | Policy bypass in Blink in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to leak cross-origin data via a crafted HTML page. | |
| CVE-2022-0116 | Med | 4.3 | < 83.0.4254.27-lp153.2.33.1 | 83.0.4254.27-lp153.2.33.1 | Feb 12, 2022 | Inappropriate implementation in Compositing in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. | |
| CVE-2022-0115 | Hig | 8.8 | < 83.0.4254.27-lp153.2.33.1 | 83.0.4254.27-lp153.2.33.1 | Feb 12, 2022 | Uninitialized use in File API in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. | |
| CVE-2022-0114 | Hig | 8.1 | < 83.0.4254.27-lp153.2.33.1 | 83.0.4254.27-lp153.2.33.1 | Feb 12, 2022 | Out of bounds memory access in Blink Serial API in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page and virtual serial port driver. | |
| CVE-2022-0113 | Med | 6.5 | < 83.0.4254.27-lp153.2.33.1 | 83.0.4254.27-lp153.2.33.1 | Feb 12, 2022 | Inappropriate implementation in Blink in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to leak cross-origin data via a crafted HTML page. | |
| CVE-2022-0112 | Med | 4.3 | < 83.0.4254.27-lp153.2.33.1 | 83.0.4254.27-lp153.2.33.1 | Feb 12, 2022 | Incorrect security UI in Browser UI in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to display missing URL or incorrect URL via a crafted URL. | |
| CVE-2022-0111 | Med | 6.5 | < 83.0.4254.27-lp153.2.33.1 | 83.0.4254.27-lp153.2.33.1 | Feb 12, 2022 | Inappropriate implementation in Navigation in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to incorrectly set origin via a crafted HTML page. | |
| CVE-2022-0110 | Med | 4.3 | < 83.0.4254.27-lp153.2.33.1 | 83.0.4254.27-lp153.2.33.1 | Feb 12, 2022 | Incorrect security UI in Autofill in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. | |
| CVE-2022-0109 | Med | 6.5 | < 83.0.4254.27-lp153.2.33.1 | 83.0.4254.27-lp153.2.33.1 | Feb 12, 2022 | Inappropriate implementation in Autofill in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to obtain potentially sensitive information via a crafted HTML page. | |
| CVE-2022-0108 | Med | 6.5 | < 83.0.4254.27-lp153.2.33.1 | 83.0.4254.27-lp153.2.33.1 | Feb 12, 2022 | Inappropriate implementation in Navigation in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to leak cross-origin data via a crafted HTML page. | |
| CVE-2022-0107 | Hig | 8.8 | < 83.0.4254.27-lp153.2.33.1 | 83.0.4254.27-lp153.2.33.1 | Feb 12, 2022 | Use after free in File Manager API in Google Chrome on Chrome OS prior to 97.0.4692.71 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. | |
| CVE-2022-0106 | Hig | 8.8 | < 83.0.4254.27-lp153.2.33.1 | 83.0.4254.27-lp153.2.33.1 | Feb 12, 2022 | Use after free in Autofill in Google Chrome prior to 97.0.4692.71 allowed a remote attacker who convinced a user to perform specific user gesture to potentially exploit heap corruption via a crafted HTML page. | |
| CVE-2022-0105 | Hig | 8.8 | < 83.0.4254.27-lp153.2.33.1 | 83.0.4254.27-lp153.2.33.1 | Feb 12, 2022 | Use after free in PDF Accessibility in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| CVE-2022-0104 | Hig | 8.8 | < 83.0.4254.27-lp153.2.33.1 | 83.0.4254.27-lp153.2.33.1 | Feb 12, 2022 | Heap buffer overflow in ANGLE in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| CVE-2022-0103 | Hig | 8.8 | < 83.0.4254.27-lp153.2.33.1 | 83.0.4254.27-lp153.2.33.1 | Feb 12, 2022 | Use after free in SwiftShader in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| CVE-2022-0102 | Hig | 8.8 | < 83.0.4254.27-lp153.2.33.1 | 83.0.4254.27-lp153.2.33.1 | Feb 12, 2022 | Type confusion in V8 in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| CVE-2022-0101 | Hig | 8.8 | < 83.0.4254.27-lp153.2.33.1 | 83.0.4254.27-lp153.2.33.1 | Feb 12, 2022 | Heap buffer overflow in Bookmarks in Google Chrome prior to 97.0.4692.71 allowed a remote attacker who convinced a user to perform specific user gesture to potentially exploit heap corruption via specific user gesture. | |
| CVE-2022-0100 | Hig | 8.8 | < 83.0.4254.27-lp153.2.33.1 | 83.0.4254.27-lp153.2.33.1 | Feb 12, 2022 | Heap buffer overflow in Media streams API in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| CVE-2022-0099 | Hig | 8.8 | < 83.0.4254.27-lp153.2.33.1 | 83.0.4254.27-lp153.2.33.1 | Feb 12, 2022 | Use after free in Sign-in in Google Chrome prior to 97.0.4692.71 allowed a remote attacker who convinced a user to perform specific user gestures to potentially exploit heap corruption via specific user gesture. | |
| CVE-2022-0098 | Hig | 8.8 | < 83.0.4254.27-lp153.2.33.1 | 83.0.4254.27-lp153.2.33.1 | Feb 12, 2022 | Use after free in Screen Capture in Google Chrome on Chrome OS prior to 97.0.4692.71 allowed an attacker who convinced a user to perform specific user gestures to potentially exploit heap corruption via specific user gestures. |
- affected < 83.0.4254.27-lp153.2.33.1fixed 83.0.4254.27-lp153.2.33.1
Policy bypass in Blink in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
- affected < 83.0.4254.27-lp153.2.33.1fixed 83.0.4254.27-lp153.2.33.1
Inappropriate implementation in Compositing in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
- affected < 83.0.4254.27-lp153.2.33.1fixed 83.0.4254.27-lp153.2.33.1
Uninitialized use in File API in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
- affected < 83.0.4254.27-lp153.2.33.1fixed 83.0.4254.27-lp153.2.33.1
Out of bounds memory access in Blink Serial API in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page and virtual serial port driver.
- affected < 83.0.4254.27-lp153.2.33.1fixed 83.0.4254.27-lp153.2.33.1
Inappropriate implementation in Blink in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
- affected < 83.0.4254.27-lp153.2.33.1fixed 83.0.4254.27-lp153.2.33.1
Incorrect security UI in Browser UI in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to display missing URL or incorrect URL via a crafted URL.
- affected < 83.0.4254.27-lp153.2.33.1fixed 83.0.4254.27-lp153.2.33.1
Inappropriate implementation in Navigation in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to incorrectly set origin via a crafted HTML page.
- affected < 83.0.4254.27-lp153.2.33.1fixed 83.0.4254.27-lp153.2.33.1
Incorrect security UI in Autofill in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
- affected < 83.0.4254.27-lp153.2.33.1fixed 83.0.4254.27-lp153.2.33.1
Inappropriate implementation in Autofill in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to obtain potentially sensitive information via a crafted HTML page.
- affected < 83.0.4254.27-lp153.2.33.1fixed 83.0.4254.27-lp153.2.33.1
Inappropriate implementation in Navigation in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
- affected < 83.0.4254.27-lp153.2.33.1fixed 83.0.4254.27-lp153.2.33.1
Use after free in File Manager API in Google Chrome on Chrome OS prior to 97.0.4692.71 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.
- affected < 83.0.4254.27-lp153.2.33.1fixed 83.0.4254.27-lp153.2.33.1
Use after free in Autofill in Google Chrome prior to 97.0.4692.71 allowed a remote attacker who convinced a user to perform specific user gesture to potentially exploit heap corruption via a crafted HTML page.
- affected < 83.0.4254.27-lp153.2.33.1fixed 83.0.4254.27-lp153.2.33.1
Use after free in PDF Accessibility in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- affected < 83.0.4254.27-lp153.2.33.1fixed 83.0.4254.27-lp153.2.33.1
Heap buffer overflow in ANGLE in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- affected < 83.0.4254.27-lp153.2.33.1fixed 83.0.4254.27-lp153.2.33.1
Use after free in SwiftShader in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- affected < 83.0.4254.27-lp153.2.33.1fixed 83.0.4254.27-lp153.2.33.1
Type confusion in V8 in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- affected < 83.0.4254.27-lp153.2.33.1fixed 83.0.4254.27-lp153.2.33.1
Heap buffer overflow in Bookmarks in Google Chrome prior to 97.0.4692.71 allowed a remote attacker who convinced a user to perform specific user gesture to potentially exploit heap corruption via specific user gesture.
- affected < 83.0.4254.27-lp153.2.33.1fixed 83.0.4254.27-lp153.2.33.1
Heap buffer overflow in Media streams API in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- affected < 83.0.4254.27-lp153.2.33.1fixed 83.0.4254.27-lp153.2.33.1
Use after free in Sign-in in Google Chrome prior to 97.0.4692.71 allowed a remote attacker who convinced a user to perform specific user gestures to potentially exploit heap corruption via specific user gesture.
- affected < 83.0.4254.27-lp153.2.33.1fixed 83.0.4254.27-lp153.2.33.1
Use after free in Screen Capture in Google Chrome on Chrome OS prior to 97.0.4692.71 allowed an attacker who convinced a user to perform specific user gestures to potentially exploit heap corruption via specific user gestures.
Page 6 of 14