rpm package
suse/chromium&distro=SUSE Package Hub 12 SP3
pkg:rpm/suse/chromium&distro=SUSE%20Package%20Hub%2012%20SP3
Vulnerabilities (241)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2019-5797 | — | < 75.0.3770.90-bp150.213.3 | 75.0.3770.90-bp150.213.3 | Sep 29, 2022 | Double free in DOMStorage in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | ||
| CVE-2020-6452 | — | < 80.0.3987.162-44.1 | 80.0.3987.162-44.1 | Apr 13, 2020 | Heap buffer overflow in media in Google Chrome prior to 80.0.3987.162 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | ||
| CVE-2020-6451 | — | < 80.0.3987.162-44.1 | 80.0.3987.162-44.1 | Apr 13, 2020 | Use after free in WebAudio in Google Chrome prior to 80.0.3987.162 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | ||
| CVE-2020-6450 | — | < 80.0.3987.162-44.1 | 80.0.3987.162-44.1 | Apr 13, 2020 | Use after free in WebAudio in Google Chrome prior to 80.0.3987.162 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | ||
| CVE-2020-6425 | — | < 80.0.3987.149-41.1 | 80.0.3987.149-41.1 | Mar 23, 2020 | Insufficient policy enforcement in extensions in Google Chrome prior to 80.0.3987.149 allowed an attacker who convinced a user to install a malicious extension to bypass site isolation via a crafted Chrome Extension. | ||
| CVE-2020-6429 | — | < 80.0.3987.149-41.1 | 80.0.3987.149-41.1 | Mar 20, 2020 | Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | ||
| CVE-2020-6428 | — | < 80.0.3987.149-41.1 | 80.0.3987.149-41.1 | Mar 20, 2020 | Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | ||
| CVE-2020-6427 | — | < 80.0.3987.149-41.1 | 80.0.3987.149-41.1 | Mar 20, 2020 | Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | ||
| CVE-2020-6426 | — | < 80.0.3987.149-41.1 | 80.0.3987.149-41.1 | Mar 20, 2020 | Inappropriate implementation in V8 in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | ||
| CVE-2020-6424 | — | < 80.0.3987.149-41.1 | 80.0.3987.149-41.1 | Mar 20, 2020 | Use after free in media in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | ||
| CVE-2020-6422 | — | < 80.0.3987.149-41.1 | 80.0.3987.149-41.1 | Mar 20, 2020 | Use after free in WebGL in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | ||
| CVE-2020-6420 | — | < 80.0.3987.132-37.1 | 80.0.3987.132-37.1 | Mar 20, 2020 | Insufficient policy enforcement in media in Google Chrome prior to 80.0.3987.132 allowed a remote attacker to bypass same origin policy via a crafted HTML page. | ||
| CVE-2020-6449 | — | < 80.0.3987.149-41.1 | 80.0.3987.149-41.1 | Mar 20, 2020 | Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | ||
| CVE-2019-20503 | — | < 80.0.3987.149-41.1 | 80.0.3987.149-41.1 | Mar 6, 2020 | usrsctp before 2019-12-20 has out-of-bounds reads in sctp_load_addresses_from_init. | ||
| CVE-2020-6418 | — | KEV | < 80.0.3987.122-34.1 | 80.0.3987.122-34.1 | Feb 27, 2020 | Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| CVE-2020-6407 | — | < 80.0.3987.122-34.1 | 80.0.3987.122-34.1 | Feb 27, 2020 | Out of bounds memory access in streams in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | ||
| CVE-2020-6417 | — | < 80.0.3987.87-31.1 | 80.0.3987.87-31.1 | Feb 11, 2020 | Inappropriate implementation in installer in Google Chrome prior to 80.0.3987.87 allowed a local attacker to execute arbitrary code via a crafted registry entry. | ||
| CVE-2020-6416 | — | < 80.0.3987.87-31.1 | 80.0.3987.87-31.1 | Feb 11, 2020 | Insufficient data validation in streams in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | ||
| CVE-2020-6415 | — | < 80.0.3987.87-31.1 | 80.0.3987.87-31.1 | Feb 11, 2020 | Inappropriate implementation in JavaScript in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | ||
| CVE-2020-6414 | — | < 80.0.3987.87-31.1 | 80.0.3987.87-31.1 | Feb 11, 2020 | Insufficient policy enforcement in Safe Browsing in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. |
- CVE-2019-5797Sep 29, 2022affected < 75.0.3770.90-bp150.213.3fixed 75.0.3770.90-bp150.213.3
Double free in DOMStorage in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2020-6452Apr 13, 2020affected < 80.0.3987.162-44.1fixed 80.0.3987.162-44.1
Heap buffer overflow in media in Google Chrome prior to 80.0.3987.162 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2020-6451Apr 13, 2020affected < 80.0.3987.162-44.1fixed 80.0.3987.162-44.1
Use after free in WebAudio in Google Chrome prior to 80.0.3987.162 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2020-6450Apr 13, 2020affected < 80.0.3987.162-44.1fixed 80.0.3987.162-44.1
Use after free in WebAudio in Google Chrome prior to 80.0.3987.162 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2020-6425Mar 23, 2020affected < 80.0.3987.149-41.1fixed 80.0.3987.149-41.1
Insufficient policy enforcement in extensions in Google Chrome prior to 80.0.3987.149 allowed an attacker who convinced a user to install a malicious extension to bypass site isolation via a crafted Chrome Extension.
- CVE-2020-6429Mar 20, 2020affected < 80.0.3987.149-41.1fixed 80.0.3987.149-41.1
Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2020-6428Mar 20, 2020affected < 80.0.3987.149-41.1fixed 80.0.3987.149-41.1
Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2020-6427Mar 20, 2020affected < 80.0.3987.149-41.1fixed 80.0.3987.149-41.1
Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2020-6426Mar 20, 2020affected < 80.0.3987.149-41.1fixed 80.0.3987.149-41.1
Inappropriate implementation in V8 in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2020-6424Mar 20, 2020affected < 80.0.3987.149-41.1fixed 80.0.3987.149-41.1
Use after free in media in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2020-6422Mar 20, 2020affected < 80.0.3987.149-41.1fixed 80.0.3987.149-41.1
Use after free in WebGL in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2020-6420Mar 20, 2020affected < 80.0.3987.132-37.1fixed 80.0.3987.132-37.1
Insufficient policy enforcement in media in Google Chrome prior to 80.0.3987.132 allowed a remote attacker to bypass same origin policy via a crafted HTML page.
- CVE-2020-6449Mar 20, 2020affected < 80.0.3987.149-41.1fixed 80.0.3987.149-41.1
Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2019-20503Mar 6, 2020affected < 80.0.3987.149-41.1fixed 80.0.3987.149-41.1
usrsctp before 2019-12-20 has out-of-bounds reads in sctp_load_addresses_from_init.
- affected < 80.0.3987.122-34.1fixed 80.0.3987.122-34.1
Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2020-6407Feb 27, 2020affected < 80.0.3987.122-34.1fixed 80.0.3987.122-34.1
Out of bounds memory access in streams in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2020-6417Feb 11, 2020affected < 80.0.3987.87-31.1fixed 80.0.3987.87-31.1
Inappropriate implementation in installer in Google Chrome prior to 80.0.3987.87 allowed a local attacker to execute arbitrary code via a crafted registry entry.
- CVE-2020-6416Feb 11, 2020affected < 80.0.3987.87-31.1fixed 80.0.3987.87-31.1
Insufficient data validation in streams in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2020-6415Feb 11, 2020affected < 80.0.3987.87-31.1fixed 80.0.3987.87-31.1
Inappropriate implementation in JavaScript in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2020-6414Feb 11, 2020affected < 80.0.3987.87-31.1fixed 80.0.3987.87-31.1
Insufficient policy enforcement in Safe Browsing in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
Page 1 of 13