rpm package
opensuse/opera&distro=openSUSE Leap 15.4 NonFree
pkg:rpm/opensuse/opera&distro=openSUSE%20Leap%2015.4%20NonFree
Vulnerabilities (432)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2021-30608 | Hig | 8.8 | < 85.0.4341.28-lp154.2.5.1 | 85.0.4341.28-lp154.2.5.1 | Sep 3, 2021 | Chromium: CVE-2021-30608 Use after free in Web Share | |
| CVE-2021-30607 | Hig | 8.8 | < 85.0.4341.28-lp154.2.5.1 | 85.0.4341.28-lp154.2.5.1 | Sep 3, 2021 | Chromium: CVE-2021-30607 Use after free in Permissions | |
| CVE-2021-30606 | Hig | 8.8 | < 85.0.4341.28-lp154.2.5.1 | 85.0.4341.28-lp154.2.5.1 | Sep 3, 2021 | Chromium: CVE-2021-30606 Use after free in Blink | |
| CVE-2021-30604 | Hig | 8.8 | < 85.0.4341.28-lp154.2.5.1 | 85.0.4341.28-lp154.2.5.1 | Aug 26, 2021 | Use after free in ANGLE in Google Chrome prior to 92.0.4515.159 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| CVE-2021-30603 | Hig | 7.5 | < 85.0.4341.28-lp154.2.5.1 | 85.0.4341.28-lp154.2.5.1 | Aug 26, 2021 | Data race in WebAudio in Google Chrome prior to 92.0.4515.159 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| CVE-2021-30602 | Hig | 8.8 | < 85.0.4341.28-lp154.2.5.1 | 85.0.4341.28-lp154.2.5.1 | Aug 26, 2021 | Use after free in WebRTC in Google Chrome prior to 92.0.4515.159 allowed an attacker who convinced a user to visit a malicious website to potentially exploit heap corruption via a crafted HTML page. | |
| CVE-2021-30601 | Hig | 8.8 | < 85.0.4341.28-lp154.2.5.1 | 85.0.4341.28-lp154.2.5.1 | Aug 26, 2021 | Use after free in Extensions API in Google Chrome prior to 92.0.4515.159 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. | |
| CVE-2021-30600 | Hig | 8.8 | < 85.0.4341.28-lp154.2.5.1 | 85.0.4341.28-lp154.2.5.1 | Aug 26, 2021 | Use after free in Printing in Google Chrome prior to 92.0.4515.159 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. | |
| CVE-2021-30599 | Hig | 8.8 | < 85.0.4341.28-lp154.2.5.1 | 85.0.4341.28-lp154.2.5.1 | Aug 26, 2021 | Type confusion in V8 in Google Chrome prior to 92.0.4515.159 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. | |
| CVE-2021-30598 | Hig | 8.8 | < 85.0.4341.28-lp154.2.5.1 | 85.0.4341.28-lp154.2.5.1 | Aug 26, 2021 | Type confusion in V8 in Google Chrome prior to 92.0.4515.159 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. | |
| CVE-2021-30597 | Med | 6.8 | < 85.0.4341.28-lp154.2.5.1 | 85.0.4341.28-lp154.2.5.1 | Aug 26, 2021 | Use after free in Browser UI in Google Chrome on Chrome prior to 92.0.4515.131 allowed a remote attacker to potentially exploit heap corruption via physical access to the device. | |
| CVE-2021-30596 | Med | 4.3 | < 85.0.4341.28-lp154.2.5.1 | 85.0.4341.28-lp154.2.5.1 | Aug 26, 2021 | Incorrect security UI in Navigation in Google Chrome on Android prior to 92.0.4515.131 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. | |
| CVE-2021-30594 | Med | 6.8 | < 85.0.4341.28-lp154.2.5.1 | 85.0.4341.28-lp154.2.5.1 | Aug 26, 2021 | Use after free in Page Info UI in Google Chrome prior to 92.0.4515.131 allowed a remote attacker to potentially exploit heap corruption via physical access to the device. | |
| CVE-2021-30593 | Hig | 8.1 | < 85.0.4341.28-lp154.2.5.1 | 85.0.4341.28-lp154.2.5.1 | Aug 26, 2021 | Out of bounds read in Tab Strip in Google Chrome prior to 92.0.4515.131 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory read via a crafted HTML page. | |
| CVE-2021-30592 | Hig | 8.8 | < 85.0.4341.28-lp154.2.5.1 | 85.0.4341.28-lp154.2.5.1 | Aug 26, 2021 | Out of bounds write in Tab Groups in Google Chrome prior to 92.0.4515.131 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory write via a crafted HTML page. | |
| CVE-2021-30591 | Hig | 8.8 | < 85.0.4341.28-lp154.2.5.1 | 85.0.4341.28-lp154.2.5.1 | Aug 26, 2021 | Use after free in File System API in Google Chrome prior to 92.0.4515.131 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| CVE-2021-30590 | Hig | 8.8 | < 85.0.4341.28-lp154.2.5.1 | 85.0.4341.28-lp154.2.5.1 | Aug 26, 2021 | Heap buffer overflow in Bookmarks in Google Chrome prior to 92.0.4515.131 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| CVE-2021-30564 | Hig | 8.8 | < 85.0.4341.28-lp154.2.5.1 | 85.0.4341.28-lp154.2.5.1 | Aug 3, 2021 | Heap buffer overflow in WebXR in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| CVE-2021-30563 | Hig | 8.8 | KEV | < 85.0.4341.28-lp154.2.5.1 | 85.0.4341.28-lp154.2.5.1 | Aug 3, 2021 | Type Confusion in V8 in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
| CVE-2021-30562 | Hig | 8.8 | < 85.0.4341.28-lp154.2.5.1 | 85.0.4341.28-lp154.2.5.1 | Aug 3, 2021 | Use after free in WebSerial in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
- affected < 85.0.4341.28-lp154.2.5.1fixed 85.0.4341.28-lp154.2.5.1
Chromium: CVE-2021-30608 Use after free in Web Share
- affected < 85.0.4341.28-lp154.2.5.1fixed 85.0.4341.28-lp154.2.5.1
Chromium: CVE-2021-30607 Use after free in Permissions
- affected < 85.0.4341.28-lp154.2.5.1fixed 85.0.4341.28-lp154.2.5.1
Chromium: CVE-2021-30606 Use after free in Blink
- affected < 85.0.4341.28-lp154.2.5.1fixed 85.0.4341.28-lp154.2.5.1
Use after free in ANGLE in Google Chrome prior to 92.0.4515.159 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- affected < 85.0.4341.28-lp154.2.5.1fixed 85.0.4341.28-lp154.2.5.1
Data race in WebAudio in Google Chrome prior to 92.0.4515.159 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- affected < 85.0.4341.28-lp154.2.5.1fixed 85.0.4341.28-lp154.2.5.1
Use after free in WebRTC in Google Chrome prior to 92.0.4515.159 allowed an attacker who convinced a user to visit a malicious website to potentially exploit heap corruption via a crafted HTML page.
- affected < 85.0.4341.28-lp154.2.5.1fixed 85.0.4341.28-lp154.2.5.1
Use after free in Extensions API in Google Chrome prior to 92.0.4515.159 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.
- affected < 85.0.4341.28-lp154.2.5.1fixed 85.0.4341.28-lp154.2.5.1
Use after free in Printing in Google Chrome prior to 92.0.4515.159 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
- affected < 85.0.4341.28-lp154.2.5.1fixed 85.0.4341.28-lp154.2.5.1
Type confusion in V8 in Google Chrome prior to 92.0.4515.159 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
- affected < 85.0.4341.28-lp154.2.5.1fixed 85.0.4341.28-lp154.2.5.1
Type confusion in V8 in Google Chrome prior to 92.0.4515.159 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
- affected < 85.0.4341.28-lp154.2.5.1fixed 85.0.4341.28-lp154.2.5.1
Use after free in Browser UI in Google Chrome on Chrome prior to 92.0.4515.131 allowed a remote attacker to potentially exploit heap corruption via physical access to the device.
- affected < 85.0.4341.28-lp154.2.5.1fixed 85.0.4341.28-lp154.2.5.1
Incorrect security UI in Navigation in Google Chrome on Android prior to 92.0.4515.131 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
- affected < 85.0.4341.28-lp154.2.5.1fixed 85.0.4341.28-lp154.2.5.1
Use after free in Page Info UI in Google Chrome prior to 92.0.4515.131 allowed a remote attacker to potentially exploit heap corruption via physical access to the device.
- affected < 85.0.4341.28-lp154.2.5.1fixed 85.0.4341.28-lp154.2.5.1
Out of bounds read in Tab Strip in Google Chrome prior to 92.0.4515.131 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory read via a crafted HTML page.
- affected < 85.0.4341.28-lp154.2.5.1fixed 85.0.4341.28-lp154.2.5.1
Out of bounds write in Tab Groups in Google Chrome prior to 92.0.4515.131 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory write via a crafted HTML page.
- affected < 85.0.4341.28-lp154.2.5.1fixed 85.0.4341.28-lp154.2.5.1
Use after free in File System API in Google Chrome prior to 92.0.4515.131 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- affected < 85.0.4341.28-lp154.2.5.1fixed 85.0.4341.28-lp154.2.5.1
Heap buffer overflow in Bookmarks in Google Chrome prior to 92.0.4515.131 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- affected < 85.0.4341.28-lp154.2.5.1fixed 85.0.4341.28-lp154.2.5.1
Heap buffer overflow in WebXR in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- affected < 85.0.4341.28-lp154.2.5.1fixed 85.0.4341.28-lp154.2.5.1
Type Confusion in V8 in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- affected < 85.0.4341.28-lp154.2.5.1fixed 85.0.4341.28-lp154.2.5.1
Use after free in WebSerial in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Page 20 of 22