VYPR

rpm package

suse/re2&distro=SUSE Package Hub 12

pkg:rpm/suse/re2&distro=SUSE%20Package%20Hub%2012

Vulnerabilities (63)

  • CVE-2020-6396MedFeb 11, 2020
    affected < 20200101-25.1fixed 20200101-25.1

    Inappropriate implementation in Skia in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

  • CVE-2020-6395MedFeb 11, 2020
    affected < 20200101-25.1fixed 20200101-25.1

    Out of bounds read in JavaScript in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

  • CVE-2020-6394MedFeb 11, 2020
    affected < 20200101-25.1fixed 20200101-25.1

    Insufficient policy enforcement in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass content security policy via a crafted HTML page.

  • CVE-2020-6393MedFeb 11, 2020
    affected < 20200101-25.1fixed 20200101-25.1

    Insufficient policy enforcement in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2020-6392MedFeb 11, 2020
    affected < 20200101-25.1fixed 20200101-25.1

    Insufficient policy enforcement in extensions in Google Chrome prior to 80.0.3987.87 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension.

  • CVE-2020-6391MedFeb 11, 2020
    affected < 20200101-25.1fixed 20200101-25.1

    Insufficient validation of untrusted input in Blink in Google Chrome prior to 80.0.3987.87 allowed a local attacker to bypass content security policy via a crafted HTML page.

  • CVE-2020-6390HigFeb 11, 2020
    affected < 20200101-25.1fixed 20200101-25.1

    Out of bounds memory access in streams in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2020-6389HigFeb 11, 2020
    affected < 20200101-25.1fixed 20200101-25.1

    Out of bounds write in WebRTC in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted video stream.

  • CVE-2020-6388HigFeb 11, 2020
    affected < 20200101-25.1fixed 20200101-25.1

    Out of bounds access in WebAudio in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2020-6387HigFeb 11, 2020
    affected < 20200101-25.1fixed 20200101-25.1

    Out of bounds write in WebRTC in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted video stream.

  • CVE-2020-6385HigFeb 11, 2020
    affected < 20200101-25.1fixed 20200101-25.1

    Insufficient policy enforcement in storage in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass site isolation via a crafted HTML page.

  • CVE-2020-6382HigFeb 11, 2020
    affected < 20200101-25.1fixed 20200101-25.1

    Type confusion in JavaScript in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2020-6381HigFeb 11, 2020
    affected < 20200101-25.1fixed 20200101-25.1

    Integer overflow in JavaScript in Google Chrome on ChromeOS and Android prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2019-19925HigDec 24, 2019
    affected < 20200101-25.1fixed 20200101-25.1

    zipfileUpdate in ext/misc/zipfile.c in SQLite 3.30.1 mishandles a NULL pathname during an update of a ZIP archive.

  • CVE-2019-19923HigDec 24, 2019
    affected < 20200101-25.1fixed 20200101-25.1

    flattenSubquery in select.c in SQLite 3.30.1 mishandles certain uses of SELECT DISTINCT involving a LEFT JOIN in which the right-hand side is a view. This can cause a NULL pointer dereference (or incorrect results).

  • CVE-2019-19926HigDec 23, 2019
    affected < 20200101-25.1fixed 20200101-25.1

    multiSelect in select.c in SQLite 3.30.1 mishandles certain errors during parsing, as demonstrated by errors from sqlite3WindowRewrite() calls. NOTE: this vulnerability exists because of an incomplete fix for CVE-2019-19880.

  • CVE-2019-19880HigDec 18, 2019
    affected < 20200101-25.1fixed 20200101-25.1

    exprListAppendList in window.c in SQLite 3.30.1 allows attackers to trigger an invalid pointer dereference because constant integer values in ORDER BY clauses of window definitions are mishandled.

  • CVE-2019-18197HigOct 18, 2019
    affected < 20200101-25.1fixed 20200101-25.1

    In xsltCopyText in transform.c in libxslt 1.1.33, a pointer variable isn't reset under certain circumstances. If the relevant memory area happened to be freed and reused in a certain way, a bounds check could fail and memory outside a buffer could be written to, or uninitialized

  • CVE-2018-6054HigSep 25, 2018
    affected < 20180101-5.1fixed 20180101-5.1

    Use after free in WebUI in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially exploit heap corruption via a crafted Chrome Extension.

  • CVE-2018-6053LowSep 25, 2018
    affected < 20180101-5.1fixed 20180101-5.1

    Inappropriate implementation in New Tab Page in Google Chrome prior to 64.0.3282.119 allowed a local attacker to view website thumbnail images after clearing browser data via a crafted HTML page.