rpm package
suse/chromium&distro=SUSE Package Hub 15 SP3
pkg:rpm/suse/chromium&distro=SUSE%20Package%20Hub%2015%20SP3
Vulnerabilities (505)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2021-4098 | Hig | 7.4 | < 96.0.4664.110-bp153.2.48.1 | 96.0.4664.110-bp153.2.48.1 | Feb 11, 2022 | Insufficient data validation in Mojo in Google Chrome prior to 96.0.4664.110 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | |
| CVE-2021-4079 | Hig | 8.8 | < 96.0.4664.93-bp153.2.45.2 | 96.0.4664.93-bp153.2.45.2 | Dec 23, 2021 | Out of bounds write in WebRTC in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via crafted WebRTC packets. | |
| CVE-2021-4078 | Hig | 8.8 | < 96.0.4664.93-bp153.2.45.2 | 96.0.4664.93-bp153.2.45.2 | Dec 23, 2021 | Type confusion in V8 in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| CVE-2021-4068 | Med | 6.5 | < 96.0.4664.93-bp153.2.45.2 | 96.0.4664.93-bp153.2.45.2 | Dec 23, 2021 | Insufficient data validation in new tab page in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to leak cross-origin data via a crafted HTML page. | |
| CVE-2021-4067 | Hig | 8.8 | < 96.0.4664.93-bp153.2.45.2 | 96.0.4664.93-bp153.2.45.2 | Dec 23, 2021 | Use after free in window manager in Google Chrome on ChromeOS prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| CVE-2021-4066 | Hig | 8.8 | < 96.0.4664.93-bp153.2.45.2 | 96.0.4664.93-bp153.2.45.2 | Dec 23, 2021 | Integer underflow in ANGLE in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| CVE-2021-4065 | Hig | 8.8 | < 96.0.4664.93-bp153.2.45.2 | 96.0.4664.93-bp153.2.45.2 | Dec 23, 2021 | Use after free in autofill in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| CVE-2021-4064 | Hig | 8.8 | < 96.0.4664.93-bp153.2.45.2 | 96.0.4664.93-bp153.2.45.2 | Dec 23, 2021 | Use after free in screen capture in Google Chrome on ChromeOS prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| CVE-2021-4063 | Hig | 8.8 | < 96.0.4664.93-bp153.2.45.2 | 96.0.4664.93-bp153.2.45.2 | Dec 23, 2021 | Use after free in developer tools in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| CVE-2021-4062 | Hig | 8.8 | < 96.0.4664.93-bp153.2.45.2 | 96.0.4664.93-bp153.2.45.2 | Dec 23, 2021 | Heap buffer overflow in BFCache in Google Chrome prior to 96.0.4664.93 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. | |
| CVE-2021-4061 | Hig | 8.8 | < 96.0.4664.93-bp153.2.45.2 | 96.0.4664.93-bp153.2.45.2 | Dec 23, 2021 | Type confusion in V8 in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| CVE-2021-4059 | Med | 6.5 | < 96.0.4664.93-bp153.2.45.2 | 96.0.4664.93-bp153.2.45.2 | Dec 23, 2021 | Insufficient data validation in loader in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to leak cross-origin data via a crafted HTML page. | |
| CVE-2021-4058 | Hig | 8.8 | < 96.0.4664.93-bp153.2.45.2 | 96.0.4664.93-bp153.2.45.2 | Dec 23, 2021 | Heap buffer overflow in ANGLE in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| CVE-2021-4057 | Hig | 8.8 | < 96.0.4664.93-bp153.2.45.2 | 96.0.4664.93-bp153.2.45.2 | Dec 23, 2021 | Use after free in file API in Google Chrome prior to 96.0.4664.93 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. | |
| CVE-2021-4056 | Hig | 8.8 | < 96.0.4664.93-bp153.2.45.2 | 96.0.4664.93-bp153.2.45.2 | Dec 23, 2021 | Type confusion in loader in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| CVE-2021-4055 | Hig | 8.8 | < 96.0.4664.93-bp153.2.45.2 | 96.0.4664.93-bp153.2.45.2 | Dec 23, 2021 | Heap buffer overflow in extensions in Google Chrome prior to 96.0.4664.93 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. | |
| CVE-2021-4054 | Med | 6.5 | < 96.0.4664.93-bp153.2.45.2 | 96.0.4664.93-bp153.2.45.2 | Dec 23, 2021 | Incorrect security UI in autofill in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to perform domain spoofing via a crafted HTML page. | |
| CVE-2021-4053 | Hig | 8.8 | < 96.0.4664.93-bp153.2.45.2 | 96.0.4664.93-bp153.2.45.2 | Dec 23, 2021 | Use after free in UI in Google Chrome on Linux prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| CVE-2021-4052 | Hig | 8.8 | < 96.0.4664.93-bp153.2.45.2 | 96.0.4664.93-bp153.2.45.2 | Dec 23, 2021 | Use after free in web apps in Google Chrome prior to 96.0.4664.93 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. | |
| CVE-2021-38022 | Med | 6.5 | < 96.0.4664.93-bp153.2.45.2 | 96.0.4664.93-bp153.2.45.2 | Dec 23, 2021 | Inappropriate implementation in WebAuthentication in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to leak cross-origin data via a crafted HTML page. |
- affected < 96.0.4664.110-bp153.2.48.1fixed 96.0.4664.110-bp153.2.48.1
Insufficient data validation in Mojo in Google Chrome prior to 96.0.4664.110 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
- affected < 96.0.4664.93-bp153.2.45.2fixed 96.0.4664.93-bp153.2.45.2
Out of bounds write in WebRTC in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via crafted WebRTC packets.
- affected < 96.0.4664.93-bp153.2.45.2fixed 96.0.4664.93-bp153.2.45.2
Type confusion in V8 in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- affected < 96.0.4664.93-bp153.2.45.2fixed 96.0.4664.93-bp153.2.45.2
Insufficient data validation in new tab page in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
- affected < 96.0.4664.93-bp153.2.45.2fixed 96.0.4664.93-bp153.2.45.2
Use after free in window manager in Google Chrome on ChromeOS prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- affected < 96.0.4664.93-bp153.2.45.2fixed 96.0.4664.93-bp153.2.45.2
Integer underflow in ANGLE in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- affected < 96.0.4664.93-bp153.2.45.2fixed 96.0.4664.93-bp153.2.45.2
Use after free in autofill in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- affected < 96.0.4664.93-bp153.2.45.2fixed 96.0.4664.93-bp153.2.45.2
Use after free in screen capture in Google Chrome on ChromeOS prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- affected < 96.0.4664.93-bp153.2.45.2fixed 96.0.4664.93-bp153.2.45.2
Use after free in developer tools in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- affected < 96.0.4664.93-bp153.2.45.2fixed 96.0.4664.93-bp153.2.45.2
Heap buffer overflow in BFCache in Google Chrome prior to 96.0.4664.93 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
- affected < 96.0.4664.93-bp153.2.45.2fixed 96.0.4664.93-bp153.2.45.2
Type confusion in V8 in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- affected < 96.0.4664.93-bp153.2.45.2fixed 96.0.4664.93-bp153.2.45.2
Insufficient data validation in loader in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
- affected < 96.0.4664.93-bp153.2.45.2fixed 96.0.4664.93-bp153.2.45.2
Heap buffer overflow in ANGLE in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- affected < 96.0.4664.93-bp153.2.45.2fixed 96.0.4664.93-bp153.2.45.2
Use after free in file API in Google Chrome prior to 96.0.4664.93 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
- affected < 96.0.4664.93-bp153.2.45.2fixed 96.0.4664.93-bp153.2.45.2
Type confusion in loader in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- affected < 96.0.4664.93-bp153.2.45.2fixed 96.0.4664.93-bp153.2.45.2
Heap buffer overflow in extensions in Google Chrome prior to 96.0.4664.93 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension.
- affected < 96.0.4664.93-bp153.2.45.2fixed 96.0.4664.93-bp153.2.45.2
Incorrect security UI in autofill in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
- affected < 96.0.4664.93-bp153.2.45.2fixed 96.0.4664.93-bp153.2.45.2
Use after free in UI in Google Chrome on Linux prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- affected < 96.0.4664.93-bp153.2.45.2fixed 96.0.4664.93-bp153.2.45.2
Use after free in web apps in Google Chrome prior to 96.0.4664.93 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension.
- affected < 96.0.4664.93-bp153.2.45.2fixed 96.0.4664.93-bp153.2.45.2
Inappropriate implementation in WebAuthentication in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Page 17 of 26