rpm package
suse/chromium&distro=SUSE Package Hub 15 SP1
pkg:rpm/suse/chromium&distro=SUSE%20Package%20Hub%2015%20SP1
Vulnerabilities (431)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2020-16020 | Hig | 8.8 | < 87.0.4280.66-bp151.3.131.1 | 87.0.4280.66-bp151.3.131.1 | Jan 8, 2021 | Inappropriate implementation in cryptohome in Google Chrome on ChromeOS prior to 87.0.4280.66 allowed a remote attacker who had compromised the browser process to bypass discretionary access control via a malicious file. | |
| CVE-2020-16019 | Hig | 8.8 | < 87.0.4280.66-bp151.3.131.1 | 87.0.4280.66-bp151.3.131.1 | Jan 8, 2021 | Inappropriate implementation in filesystem in Google Chrome on ChromeOS prior to 87.0.4280.66 allowed a remote attacker who had compromised the browser process to bypass noexec restrictions via a malicious file. | |
| CVE-2020-16018 | Cri | 9.6 | < 87.0.4280.66-bp151.3.131.1 | 87.0.4280.66-bp151.3.131.1 | Jan 8, 2021 | Use after free in payments in Google Chrome prior to 87.0.4280.66 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | |
| CVE-2020-16017 | Cri | 9.6 | KEV | < 86.0.4240.198-bp152.2.29.1 | 86.0.4240.198-bp152.2.29.1 | Jan 8, 2021 | Use after free in site isolation in Google Chrome prior to 86.0.4240.198 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. |
| CVE-2020-16016 | Cri | 9.6 | < 86.0.4240.198-bp152.2.29.1 | 86.0.4240.198-bp152.2.29.1 | Jan 8, 2021 | Inappropriate implementation in base in Google Chrome prior to 86.0.4240.193 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | |
| CVE-2020-16015 | Hig | 8.8 | < 87.0.4280.66-bp151.3.131.1 | 87.0.4280.66-bp151.3.131.1 | Jan 8, 2021 | Insufficient data validation in WASM in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| CVE-2020-16014 | Cri | 9.6 | < 87.0.4280.66-bp151.3.131.1 | 87.0.4280.66-bp151.3.131.1 | Jan 8, 2021 | Use after free in PPAPI in Google Chrome prior to 87.0.4280.66 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | |
| CVE-2020-16013 | Hig | 8.8 | KEV | < 86.0.4240.198-bp152.2.29.1 | 86.0.4240.198-bp152.2.29.1 | Jan 8, 2021 | Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.198 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
| CVE-2020-16012 | Med | 4.3 | < 87.0.4280.66-bp151.3.131.1 | 87.0.4280.66-bp151.3.131.1 | Jan 8, 2021 | Side-channel information leakage in graphics in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to leak cross-origin data via a crafted HTML page. | |
| CVE-2020-6557 | Med | 6.5 | < 86.0.4240.75-bp151.3.113.1 | 86.0.4240.75-bp151.3.113.1 | Nov 3, 2020 | Inappropriate implementation in networking in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to perform domain spoofing via a crafted HTML page. | |
| CVE-2020-16011 | Cri | 9.6 | < 86.0.4240.183-bp151.3.119.1 | 86.0.4240.183-bp151.3.119.1 | Nov 3, 2020 | Heap buffer overflow in UI in Google Chrome on Windows prior to 86.0.4240.183 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | |
| CVE-2020-16009 | Hig | 8.8 | KEV | < 86.0.4240.183-bp151.3.119.1 | 86.0.4240.183-bp151.3.119.1 | Nov 3, 2020 | Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
| CVE-2020-16008 | Hig | 8.8 | < 86.0.4240.183-bp151.3.119.1 | 86.0.4240.183-bp151.3.119.1 | Nov 3, 2020 | Stack buffer overflow in WebRTC in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit stack corruption via a crafted WebRTC packet. | |
| CVE-2020-16007 | Hig | 7.8 | < 86.0.4240.183-bp151.3.119.1 | 86.0.4240.183-bp151.3.119.1 | Nov 3, 2020 | Insufficient data validation in installer in Google Chrome prior to 86.0.4240.183 allowed a local attacker to potentially elevate privilege via a crafted filesystem. | |
| CVE-2020-16006 | Hig | 8.8 | < 86.0.4240.183-bp151.3.119.1 | 86.0.4240.183-bp151.3.119.1 | Nov 3, 2020 | Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| CVE-2020-16005 | Hig | 8.8 | < 86.0.4240.183-bp151.3.119.1 | 86.0.4240.183-bp151.3.119.1 | Nov 3, 2020 | Insufficient policy enforcement in ANGLE in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| CVE-2020-16004 | Hig | 8.8 | < 86.0.4240.183-bp151.3.119.1 | 86.0.4240.183-bp151.3.119.1 | Nov 3, 2020 | Use after free in user interface in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| CVE-2020-16003 | Hig | 8.8 | < 86.0.4240.111-bp151.3.116.1 | 86.0.4240.111-bp151.3.116.1 | Nov 3, 2020 | Use after free in printing in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| CVE-2020-16002 | Hig | 8.8 | < 86.0.4240.111-bp151.3.116.1 | 86.0.4240.111-bp151.3.116.1 | Nov 3, 2020 | Use after free in PDFium in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. | |
| CVE-2020-16001 | Hig | 8.8 | < 86.0.4240.111-bp151.3.116.1 | 86.0.4240.111-bp151.3.116.1 | Nov 3, 2020 | Use after free in media in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
- affected < 87.0.4280.66-bp151.3.131.1fixed 87.0.4280.66-bp151.3.131.1
Inappropriate implementation in cryptohome in Google Chrome on ChromeOS prior to 87.0.4280.66 allowed a remote attacker who had compromised the browser process to bypass discretionary access control via a malicious file.
- affected < 87.0.4280.66-bp151.3.131.1fixed 87.0.4280.66-bp151.3.131.1
Inappropriate implementation in filesystem in Google Chrome on ChromeOS prior to 87.0.4280.66 allowed a remote attacker who had compromised the browser process to bypass noexec restrictions via a malicious file.
- affected < 87.0.4280.66-bp151.3.131.1fixed 87.0.4280.66-bp151.3.131.1
Use after free in payments in Google Chrome prior to 87.0.4280.66 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
- affected < 86.0.4240.198-bp152.2.29.1fixed 86.0.4240.198-bp152.2.29.1
Use after free in site isolation in Google Chrome prior to 86.0.4240.198 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
- affected < 86.0.4240.198-bp152.2.29.1fixed 86.0.4240.198-bp152.2.29.1
Inappropriate implementation in base in Google Chrome prior to 86.0.4240.193 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
- affected < 87.0.4280.66-bp151.3.131.1fixed 87.0.4280.66-bp151.3.131.1
Insufficient data validation in WASM in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- affected < 87.0.4280.66-bp151.3.131.1fixed 87.0.4280.66-bp151.3.131.1
Use after free in PPAPI in Google Chrome prior to 87.0.4280.66 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
- affected < 86.0.4240.198-bp152.2.29.1fixed 86.0.4240.198-bp152.2.29.1
Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.198 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- affected < 87.0.4280.66-bp151.3.131.1fixed 87.0.4280.66-bp151.3.131.1
Side-channel information leakage in graphics in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
- affected < 86.0.4240.75-bp151.3.113.1fixed 86.0.4240.75-bp151.3.113.1
Inappropriate implementation in networking in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
- affected < 86.0.4240.183-bp151.3.119.1fixed 86.0.4240.183-bp151.3.119.1
Heap buffer overflow in UI in Google Chrome on Windows prior to 86.0.4240.183 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
- affected < 86.0.4240.183-bp151.3.119.1fixed 86.0.4240.183-bp151.3.119.1
Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- affected < 86.0.4240.183-bp151.3.119.1fixed 86.0.4240.183-bp151.3.119.1
Stack buffer overflow in WebRTC in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit stack corruption via a crafted WebRTC packet.
- affected < 86.0.4240.183-bp151.3.119.1fixed 86.0.4240.183-bp151.3.119.1
Insufficient data validation in installer in Google Chrome prior to 86.0.4240.183 allowed a local attacker to potentially elevate privilege via a crafted filesystem.
- affected < 86.0.4240.183-bp151.3.119.1fixed 86.0.4240.183-bp151.3.119.1
Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- affected < 86.0.4240.183-bp151.3.119.1fixed 86.0.4240.183-bp151.3.119.1
Insufficient policy enforcement in ANGLE in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- affected < 86.0.4240.183-bp151.3.119.1fixed 86.0.4240.183-bp151.3.119.1
Use after free in user interface in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- affected < 86.0.4240.111-bp151.3.116.1fixed 86.0.4240.111-bp151.3.116.1
Use after free in printing in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- affected < 86.0.4240.111-bp151.3.116.1fixed 86.0.4240.111-bp151.3.116.1
Use after free in PDFium in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
- affected < 86.0.4240.111-bp151.3.116.1fixed 86.0.4240.111-bp151.3.116.1
Use after free in media in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Page 4 of 22