VYPR

rpm package

suse/chromium&distro=SUSE Package Hub 15 SP1

pkg:rpm/suse/chromium&distro=SUSE%20Package%20Hub%2015%20SP1

Vulnerabilities (431)

  • CVE-2021-21121Feb 9, 2021
    affected < 88.0.4324.96-bp151.3.156.1fixed 88.0.4324.96-bp151.3.156.1

    Use after free in Omnibox in Google Chrome on Linux prior to 88.0.4324.96 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.

  • CVE-2021-21120Feb 9, 2021
    affected < 88.0.4324.96-bp151.3.156.1fixed 88.0.4324.96-bp151.3.156.1

    Use after free in WebSQL in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-21119Feb 9, 2021
    affected < 88.0.4324.96-bp151.3.156.1fixed 88.0.4324.96-bp151.3.156.1

    Use after free in Media in Google Chrome prior to 88.0.4324.96 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-21118Feb 9, 2021
    affected < 88.0.4324.96-bp151.3.156.1fixed 88.0.4324.96-bp151.3.156.1

    Insufficient data validation in V8 in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.

  • CVE-2021-21117Feb 9, 2021
    affected < 88.0.4324.96-bp151.3.156.1fixed 88.0.4324.96-bp151.3.156.1

    Insufficient policy enforcement in Cryptohome in Google Chrome prior to 88.0.4324.96 allowed a local attacker to perform OS-level privilege escalation via a crafted file.

  • CVE-2020-16044Feb 9, 2021
    affected < 88.0.4324.96-bp151.3.156.1fixed 88.0.4324.96-bp151.3.156.1

    Use after free in WebRTC in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap corruption via a crafted SCTP packet.

  • CVE-2021-21116Jan 8, 2021
    affected < 87.0.4280.141-bp151.3.150.1fixed 87.0.4280.141-bp151.3.150.1

    Heap buffer overflow in audio in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-21115Jan 8, 2021
    affected < 87.0.4280.141-bp151.3.150.1fixed 87.0.4280.141-bp151.3.150.1

    User after free in safe browsing in Google Chrome prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

  • CVE-2021-21114Jan 8, 2021
    affected < 87.0.4280.141-bp151.3.150.1fixed 87.0.4280.141-bp151.3.150.1

    Use after free in audio in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-21113Jan 8, 2021
    affected < 87.0.4280.141-bp151.3.150.1fixed 87.0.4280.141-bp151.3.150.1

    Heap buffer overflow in Skia in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-21112Jan 8, 2021
    affected < 87.0.4280.141-bp151.3.150.1fixed 87.0.4280.141-bp151.3.150.1

    Use after free in Blink in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-21111Jan 8, 2021
    affected < 87.0.4280.141-bp151.3.150.1fixed 87.0.4280.141-bp151.3.150.1

    Insufficient policy enforcement in WebUI in Google Chrome prior to 87.0.4280.141 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.

  • CVE-2021-21110Jan 8, 2021
    affected < 87.0.4280.141-bp151.3.150.1fixed 87.0.4280.141-bp151.3.150.1

    Use after free in safe browsing in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.

  • CVE-2021-21109Jan 8, 2021
    affected < 87.0.4280.141-bp151.3.150.1fixed 87.0.4280.141-bp151.3.150.1

    Use after free in payments in Google Chrome prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

  • CVE-2021-21108Jan 8, 2021
    affected < 87.0.4280.141-bp151.3.150.1fixed 87.0.4280.141-bp151.3.150.1

    Use after free in media in Google Chrome prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

  • CVE-2021-21107Jan 8, 2021
    affected < 87.0.4280.141-bp151.3.150.1fixed 87.0.4280.141-bp151.3.150.1

    Use after free in drag and drop in Google Chrome on Linux prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

  • CVE-2021-21106Jan 8, 2021
    affected < 87.0.4280.141-bp151.3.150.1fixed 87.0.4280.141-bp151.3.150.1

    Use after free in autofill in Google Chrome prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

  • CVE-2020-16043Jan 8, 2021
    affected < 87.0.4280.141-bp151.3.150.1fixed 87.0.4280.141-bp151.3.150.1

    Insufficient data validation in networking in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to bypass discretionary access control via malicious network traffic.

  • CVE-2020-16042Jan 8, 2021
    affected < 87.0.4280.88-bp151.3.147.1fixed 87.0.4280.88-bp151.3.147.1

    Uninitialized Use in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

  • CVE-2020-16041Jan 8, 2021
    affected < 87.0.4280.88-bp151.3.147.1fixed 87.0.4280.88-bp151.3.147.1

    Out of bounds read in networking in Google Chrome prior to 87.0.4280.88 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page.

Page 2 of 22