VYPR

rpm package

suse/chromium&distro=SUSE Package Hub 15 SP2

pkg:rpm/suse/chromium&distro=SUSE%20Package%20Hub%2015%20SP2

Vulnerabilities (243)

  • CVE-2021-21181MedMar 9, 2021
    affected < 89.0.4389.72-bp152.2.62.1fixed 89.0.4389.72-bp152.2.62.1

    Side-channel information leakage in autofill in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

  • CVE-2021-21180HigMar 9, 2021
    affected < 89.0.4389.72-bp152.2.62.1fixed 89.0.4389.72-bp152.2.62.1

    Use after free in tab search in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-21179HigMar 9, 2021
    affected < 89.0.4389.72-bp152.2.62.1fixed 89.0.4389.72-bp152.2.62.1

    Use after free in Network Internals in Google Chrome on Linux prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-21178MedMar 9, 2021
    affected < 89.0.4389.72-bp152.2.62.1fixed 89.0.4389.72-bp152.2.62.1

    Inappropriate implementation in Compositing in Google Chrome on Linux and Windows prior to 89.0.4389.72 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

  • CVE-2021-21177MedMar 9, 2021
    affected < 89.0.4389.72-bp152.2.62.1fixed 89.0.4389.72-bp152.2.62.1

    Insufficient policy enforcement in Autofill in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

  • CVE-2021-21176MedMar 9, 2021
    affected < 89.0.4389.72-bp152.2.62.1fixed 89.0.4389.72-bp152.2.62.1

    Inappropriate implementation in full screen mode in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

  • CVE-2021-21175MedMar 9, 2021
    affected < 89.0.4389.72-bp152.2.62.1fixed 89.0.4389.72-bp152.2.62.1

    Inappropriate implementation in Site isolation in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2021-21174HigMar 9, 2021
    affected < 89.0.4389.72-bp152.2.62.1fixed 89.0.4389.72-bp152.2.62.1

    Inappropriate implementation in Referrer in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

  • CVE-2021-21173MedMar 9, 2021
    affected < 89.0.4389.72-bp152.2.62.1fixed 89.0.4389.72-bp152.2.62.1

    Side-channel information leakage in Network Internals in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2021-21172HigMar 9, 2021
    affected < 89.0.4389.72-bp152.2.62.1fixed 89.0.4389.72-bp152.2.62.1

    Insufficient policy enforcement in File System API in Google Chrome on Windows prior to 89.0.4389.72 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page.

  • CVE-2021-21171MedMar 9, 2021
    affected < 89.0.4389.72-bp152.2.62.1fixed 89.0.4389.72-bp152.2.62.1

    Incorrect security UI in TabStrip and Navigation in Google Chrome on Android prior to 89.0.4389.72 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

  • CVE-2021-21170MedMar 9, 2021
    affected < 89.0.4389.72-bp152.2.62.1fixed 89.0.4389.72-bp152.2.62.1

    Incorrect security UI in Loader in Google Chrome prior to 89.0.4389.72 allowed a remote attacker who had compromised the renderer process to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

  • CVE-2021-21169HigMar 9, 2021
    affected < 89.0.4389.72-bp152.2.62.1fixed 89.0.4389.72-bp152.2.62.1

    Out of bounds memory access in V8 in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.

  • CVE-2021-21168MedMar 9, 2021
    affected < 89.0.4389.72-bp152.2.62.1fixed 89.0.4389.72-bp152.2.62.1

    Insufficient policy enforcement in appcache in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

  • CVE-2021-21167HigMar 9, 2021
    affected < 89.0.4389.72-bp152.2.62.1fixed 89.0.4389.72-bp152.2.62.1

    Use after free in bookmarks in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-21166HigKEVMar 9, 2021
    affected < 89.0.4389.72-bp152.2.62.1fixed 89.0.4389.72-bp152.2.62.1

    Data race in audio in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-21165HigMar 9, 2021
    affected < 89.0.4389.72-bp152.2.62.1fixed 89.0.4389.72-bp152.2.62.1

    Data race in audio in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-21164MedMar 9, 2021
    affected < 89.0.4389.72-bp152.2.62.1fixed 89.0.4389.72-bp152.2.62.1

    Insufficient data validation in Chrome on iOS in Google Chrome on iOS prior to 89.0.4389.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2021-21163MedMar 9, 2021
    affected < 89.0.4389.72-bp152.2.62.1fixed 89.0.4389.72-bp152.2.62.1

    Insufficient data validation in Reader Mode in Google Chrome on iOS prior to 89.0.4389.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page and a malicious server.

  • CVE-2021-21162HigMar 9, 2021
    affected < 89.0.4389.72-bp152.2.62.1fixed 89.0.4389.72-bp152.2.62.1

    Use after free in WebRTC in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Page 2 of 13