VYPR

rpm package

suse/chromium&distro=SUSE Package Hub 15 SP3

pkg:rpm/suse/chromium&distro=SUSE%20Package%20Hub%2015%20SP3

Vulnerabilities (505)

  • CVE-2021-38021MedDec 23, 2021
    affected < 96.0.4664.93-bp153.2.45.2fixed 96.0.4664.93-bp153.2.45.2

    Inappropriate implementation in referrer in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

  • CVE-2021-38020MedDec 23, 2021
    affected < 96.0.4664.93-bp153.2.45.2fixed 96.0.4664.93-bp153.2.45.2

    Insufficient policy enforcement in contacts picker in Google Chrome on Android prior to 96.0.4664.45 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

  • CVE-2021-38019MedDec 23, 2021
    affected < 96.0.4664.93-bp153.2.45.2fixed 96.0.4664.93-bp153.2.45.2

    Insufficient policy enforcement in CORS in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2021-38018MedDec 23, 2021
    affected < 96.0.4664.93-bp153.2.45.2fixed 96.0.4664.93-bp153.2.45.2

    Inappropriate implementation in navigation in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to perform domain spoofing via a crafted HTML page.

  • CVE-2021-38017HigDec 23, 2021
    affected < 96.0.4664.93-bp153.2.45.2fixed 96.0.4664.93-bp153.2.45.2

    Insufficient policy enforcement in iframe sandbox in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

  • CVE-2021-38016HigDec 23, 2021
    affected < 96.0.4664.93-bp153.2.45.2fixed 96.0.4664.93-bp153.2.45.2

    Insufficient policy enforcement in background fetch in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to bypass same origin policy via a crafted HTML page.

  • CVE-2021-38015HigDec 23, 2021
    affected < 96.0.4664.93-bp153.2.45.2fixed 96.0.4664.93-bp153.2.45.2

    Inappropriate implementation in input in Google Chrome prior to 96.0.4664.45 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension.

  • CVE-2021-38014HigDec 23, 2021
    affected < 96.0.4664.93-bp153.2.45.2fixed 96.0.4664.93-bp153.2.45.2

    Out of bounds write in Swiftshader in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-38013CriDec 23, 2021
    affected < 96.0.4664.93-bp153.2.45.2fixed 96.0.4664.93-bp153.2.45.2

    Heap buffer overflow in fingerprint recognition in Google Chrome on ChromeOS prior to 96.0.4664.45 allowed a remote attacker who had compromised a WebUI renderer process to potentially perform a sandbox escape via a crafted HTML page.

  • CVE-2021-38012HigDec 23, 2021
    affected < 96.0.4664.93-bp153.2.45.2fixed 96.0.4664.93-bp153.2.45.2

    Type confusion in V8 in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-38011HigDec 23, 2021
    affected < 96.0.4664.93-bp153.2.45.2fixed 96.0.4664.93-bp153.2.45.2

    Use after free in storage foundation in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-38010MedDec 23, 2021
    affected < 96.0.4664.93-bp153.2.45.2fixed 96.0.4664.93-bp153.2.45.2

    Inappropriate implementation in service workers in Google Chrome prior to 96.0.4664.45 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.

  • CVE-2021-38009MedDec 23, 2021
    affected < 96.0.4664.93-bp153.2.45.2fixed 96.0.4664.93-bp153.2.45.2

    Inappropriate implementation in cache in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2021-38008HigDec 23, 2021
    affected < 96.0.4664.93-bp153.2.45.2fixed 96.0.4664.93-bp153.2.45.2

    Use after free in media in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-38007HigDec 23, 2021
    affected < 96.0.4664.93-bp153.2.45.2fixed 96.0.4664.93-bp153.2.45.2

    Type confusion in V8 in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-38006HigDec 23, 2021
    affected < 96.0.4664.93-bp153.2.45.2fixed 96.0.4664.93-bp153.2.45.2

    Use after free in storage foundation in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-38005HigDec 23, 2021
    affected < 96.0.4664.93-bp153.2.45.2fixed 96.0.4664.93-bp153.2.45.2

    Use after free in loader in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-44790CriDec 20, 2021
    affected < 99.0.4844.84-bp153.2.75.1fixed 99.0.4844.84-bp153.2.75.1

    A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache httpd team is not aware of an exploit for the vulnerabilty though it might be possible to craft one. This issue affects Apache HTTP Ser

  • CVE-2021-44224HigDec 20, 2021
    affected < 99.0.4844.84-bp153.2.75.1fixed 99.0.4844.84-bp153.2.75.1

    A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL pointer dereference) or, for configurations mixing forward and reverse proxy declarations, can allow for requests to be directed to a declared Unix Domain Socket endpoint (Server

  • CVE-2021-38003HigKEVNov 23, 2021
    affected < 95.0.4638.69-bp153.2.40.3fixed 95.0.4638.69-bp153.2.40.3

    Inappropriate implementation in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Page 18 of 26