rpm package
suse/chromium&distro=SUSE Package Hub 15 SP3
pkg:rpm/suse/chromium&distro=SUSE%20Package%20Hub%2015%20SP3
Vulnerabilities (505)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2022-0609 | Hig | 8.8 | KEV | < 98.0.4758.102-bp153.2.63.1 | 98.0.4758.102-bp153.2.63.1 | Apr 5, 2022 | Use after free in Animation in Google Chrome prior to 98.0.4758.102 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
| CVE-2022-0608 | Hig | 8.8 | < 98.0.4758.102-bp153.2.63.1 | 98.0.4758.102-bp153.2.63.1 | Apr 5, 2022 | Integer overflow in Mojo in Google Chrome prior to 98.0.4758.102 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| CVE-2022-0607 | Hig | 8.8 | < 98.0.4758.102-bp153.2.63.1 | 98.0.4758.102-bp153.2.63.1 | Apr 5, 2022 | Use after free in GPU in Google Chrome prior to 98.0.4758.102 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| CVE-2022-0606 | Hig | 8.8 | < 98.0.4758.102-bp153.2.63.1 | 98.0.4758.102-bp153.2.63.1 | Apr 5, 2022 | Use after free in ANGLE in Google Chrome prior to 98.0.4758.102 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| CVE-2022-0605 | Hig | 8.8 | < 98.0.4758.102-bp153.2.63.1 | 98.0.4758.102-bp153.2.63.1 | Apr 5, 2022 | Use after free in Webstore API in Google Chrome prior to 98.0.4758.102 allowed an attacker who convinced a user to install a malicious extension and convinced a user to enage in specific user interaction to potentially exploit heap corruption via a crafted HTML page. | |
| CVE-2022-0604 | Hig | 8.8 | < 98.0.4758.102-bp153.2.63.1 | 98.0.4758.102-bp153.2.63.1 | Apr 5, 2022 | Heap buffer overflow in Tab Groups in Google Chrome prior to 98.0.4758.102 allowed an attacker who convinced a user to install a malicious extension and engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page. | |
| CVE-2022-0603 | Hig | 8.8 | < 98.0.4758.102-bp153.2.63.1 | 98.0.4758.102-bp153.2.63.1 | Apr 5, 2022 | Use after free in File Manager in Google Chrome on Chrome OS prior to 98.0.4758.102 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| CVE-2022-21824 | Hig | 8.2 | < 100.0.4896.88-bp153.2.82.1 | 100.0.4896.88-bp153.2.82.1 | Feb 24, 2022 | Due to the formatting logic of the "console.table()" function it was not safe to allow user controlled input to be passed to the "properties" parameter while simultaneously passing a plain object with at least one property as the first parameter, which could be "__proto__". The p | |
| CVE-2021-44533 | Med | 5.3 | < 100.0.4896.88-bp153.2.82.1 | 100.0.4896.88-bp153.2.82.1 | Feb 24, 2022 | Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 did not handle multi-value Relative Distinguished Names correctly. Attackers could craft certificate subjects containing a single-value Relative Distinguished Name that would be interpreted as a multi-value Relative Distinguis | |
| CVE-2021-44532 | Med | 5.3 | < 100.0.4896.88-bp153.2.82.1 | 100.0.4896.88-bp153.2.82.1 | Feb 24, 2022 | Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 converts SANs (Subject Alternative Names) to a string format. It uses this string to check peer certificates against hostnames when validating connections. The string format was subject to an injection vulnerability when name | |
| CVE-2021-44531 | Hig | 7.4 | < 100.0.4896.88-bp153.2.82.1 | 100.0.4896.88-bp153.2.82.1 | Feb 24, 2022 | Accepting arbitrary Subject Alternative Name (SAN) types, unless a PKI is specifically defined to use a particular SAN type, can result in bypassing name-constrained intermediates. Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 was accepting URI SAN types, which PKIs are o | |
| CVE-2022-0311 | Hig | 8.8 | < 97.0.4692.99-bp153.2.57.1 | 97.0.4692.99-bp153.2.57.1 | Feb 12, 2022 | Heap buffer overflow in Task Manager in Google Chrome prior to 97.0.4692.99 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page. | |
| CVE-2022-0310 | Hig | 8.8 | < 97.0.4692.99-bp153.2.57.1 | 97.0.4692.99-bp153.2.57.1 | Feb 12, 2022 | Heap buffer overflow in Task Manager in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to potentially exploit heap corruption via specific user interactions. | |
| CVE-2022-0309 | Med | 6.5 | < 97.0.4692.99-bp153.2.57.1 | 97.0.4692.99-bp153.2.57.1 | Feb 12, 2022 | Inappropriate implementation in Autofill in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. | |
| CVE-2022-0308 | Hig | 8.8 | < 97.0.4692.99-bp153.2.57.1 | 97.0.4692.99-bp153.2.57.1 | Feb 12, 2022 | Use after free in Data Transfer in Google Chrome on Chrome OS prior to 97.0.4692.99 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page. | |
| CVE-2022-0307 | Hig | 8.8 | < 97.0.4692.99-bp153.2.57.1 | 97.0.4692.99-bp153.2.57.1 | Feb 12, 2022 | Use after free in Optimization Guide in Google Chrome prior to 97.0.4692.99 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page. | |
| CVE-2022-0306 | Hig | 8.8 | < 97.0.4692.99-bp153.2.57.1 | 97.0.4692.99-bp153.2.57.1 | Feb 12, 2022 | Heap buffer overflow in PDFium in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| CVE-2022-0305 | Med | 6.5 | < 97.0.4692.99-bp153.2.57.1 | 97.0.4692.99-bp153.2.57.1 | Feb 12, 2022 | Inappropriate implementation in Service Worker API in Google Chrome prior to 97.0.4692.99 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. | |
| CVE-2022-0304 | Hig | 8.8 | < 97.0.4692.99-bp153.2.57.1 | 97.0.4692.99-bp153.2.57.1 | Feb 12, 2022 | Use after free in Bookmarks in Google Chrome prior to 97.0.4692.99 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via a crafted HTML page. | |
| CVE-2022-0302 | Hig | 8.8 | < 97.0.4692.99-bp153.2.57.1 | 97.0.4692.99-bp153.2.57.1 | Feb 12, 2022 | Use after free in Omnibox in Google Chrome prior to 97.0.4692.99 allowed an attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via a crafted HTML page. |
- affected < 98.0.4758.102-bp153.2.63.1fixed 98.0.4758.102-bp153.2.63.1
Use after free in Animation in Google Chrome prior to 98.0.4758.102 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- affected < 98.0.4758.102-bp153.2.63.1fixed 98.0.4758.102-bp153.2.63.1
Integer overflow in Mojo in Google Chrome prior to 98.0.4758.102 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- affected < 98.0.4758.102-bp153.2.63.1fixed 98.0.4758.102-bp153.2.63.1
Use after free in GPU in Google Chrome prior to 98.0.4758.102 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- affected < 98.0.4758.102-bp153.2.63.1fixed 98.0.4758.102-bp153.2.63.1
Use after free in ANGLE in Google Chrome prior to 98.0.4758.102 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- affected < 98.0.4758.102-bp153.2.63.1fixed 98.0.4758.102-bp153.2.63.1
Use after free in Webstore API in Google Chrome prior to 98.0.4758.102 allowed an attacker who convinced a user to install a malicious extension and convinced a user to enage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.
- affected < 98.0.4758.102-bp153.2.63.1fixed 98.0.4758.102-bp153.2.63.1
Heap buffer overflow in Tab Groups in Google Chrome prior to 98.0.4758.102 allowed an attacker who convinced a user to install a malicious extension and engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.
- affected < 98.0.4758.102-bp153.2.63.1fixed 98.0.4758.102-bp153.2.63.1
Use after free in File Manager in Google Chrome on Chrome OS prior to 98.0.4758.102 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- affected < 100.0.4896.88-bp153.2.82.1fixed 100.0.4896.88-bp153.2.82.1
Due to the formatting logic of the "console.table()" function it was not safe to allow user controlled input to be passed to the "properties" parameter while simultaneously passing a plain object with at least one property as the first parameter, which could be "__proto__". The p
- affected < 100.0.4896.88-bp153.2.82.1fixed 100.0.4896.88-bp153.2.82.1
Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 did not handle multi-value Relative Distinguished Names correctly. Attackers could craft certificate subjects containing a single-value Relative Distinguished Name that would be interpreted as a multi-value Relative Distinguis
- affected < 100.0.4896.88-bp153.2.82.1fixed 100.0.4896.88-bp153.2.82.1
Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 converts SANs (Subject Alternative Names) to a string format. It uses this string to check peer certificates against hostnames when validating connections. The string format was subject to an injection vulnerability when name
- affected < 100.0.4896.88-bp153.2.82.1fixed 100.0.4896.88-bp153.2.82.1
Accepting arbitrary Subject Alternative Name (SAN) types, unless a PKI is specifically defined to use a particular SAN type, can result in bypassing name-constrained intermediates. Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 was accepting URI SAN types, which PKIs are o
- affected < 97.0.4692.99-bp153.2.57.1fixed 97.0.4692.99-bp153.2.57.1
Heap buffer overflow in Task Manager in Google Chrome prior to 97.0.4692.99 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.
- affected < 97.0.4692.99-bp153.2.57.1fixed 97.0.4692.99-bp153.2.57.1
Heap buffer overflow in Task Manager in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to potentially exploit heap corruption via specific user interactions.
- affected < 97.0.4692.99-bp153.2.57.1fixed 97.0.4692.99-bp153.2.57.1
Inappropriate implementation in Autofill in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
- affected < 97.0.4692.99-bp153.2.57.1fixed 97.0.4692.99-bp153.2.57.1
Use after free in Data Transfer in Google Chrome on Chrome OS prior to 97.0.4692.99 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.
- affected < 97.0.4692.99-bp153.2.57.1fixed 97.0.4692.99-bp153.2.57.1
Use after free in Optimization Guide in Google Chrome prior to 97.0.4692.99 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.
- affected < 97.0.4692.99-bp153.2.57.1fixed 97.0.4692.99-bp153.2.57.1
Heap buffer overflow in PDFium in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- affected < 97.0.4692.99-bp153.2.57.1fixed 97.0.4692.99-bp153.2.57.1
Inappropriate implementation in Service Worker API in Google Chrome prior to 97.0.4692.99 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.
- affected < 97.0.4692.99-bp153.2.57.1fixed 97.0.4692.99-bp153.2.57.1
Use after free in Bookmarks in Google Chrome prior to 97.0.4692.99 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via a crafted HTML page.
- affected < 97.0.4692.99-bp153.2.57.1fixed 97.0.4692.99-bp153.2.57.1
Use after free in Omnibox in Google Chrome prior to 97.0.4692.99 allowed an attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via a crafted HTML page.
Page 14 of 26