Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2022:0110-1

Опубликовано: 08 апр. 2022
Источник: suse-cvrf

Описание

Security update for opera

This update for opera fixes the following issues:

Update to 85.0.4341.28

  • CHR-8816 Update chromium on desktop-stable-99-4341 to 99.0.4844.84

  • DNA-98092 Crash at views::MenuItemView::GetMenuController()

  • DNA-98278 Translations for O85

  • DNA-98320 [Mac] Unable to delete recent search entries

  • DNA-98614 Show recent searches for non-BABE users

  • DNA-98615 Allow removal of recent searches

  • DNA-98616 Add recent searches to ‘old’ BABE

  • DNA-98617 Make it possible to disable ad-blocker per-country

  • DNA-98651 Remove Instagram and Facebook Messenger in Russia

  • DNA-98653 Add flag #recent-searches

  • DNA-98696 smoketest PageInfoHistoryDataSourceTest.FormatTimestampString failing

  • DNA-98703 Port Chromium issue 1309225 to Opera Stable

  • The update to chromium 99.0.4844.84 fixes following issues:
    CVE-2022-1096

  • Changes in 85.0.4341.18

    • CHR-8789 Update chromium on desktop-stable-99-4341 to 99.0.4844.51
    • DNA-98059 [Linux] Crash at opera::FreedomSettingsImpl::IsBypassForDotlessDomainsEnabled
    • DNA-98349 [Linux] Crash at bluez::BluezDBusManager::Get()
    • DNA-98126 System crash dialog shown on macOS <= 10.15
    • DNA-98331 [Snap] Meme generator cropping / resizing broken
    • DNA-98394 Audio tab indicator set to 'muted' on videoconferencing sites
    • DNA-98481 Report errors in opauto_collector
  • The update to chromium 99.0.4844.51 fixes following issues: CVE-2022-0789, CVE-2022-0790, CVE-2022-0791, CVE-2022-0792, CVE-2022-0793, CVE-2022-0794, CVE-2022-0795, CVE-2022-0796, CVE-2022-0797, CVE-2022-0798, CVE-2022-0799, CVE-2022-0800, CVE-2022-0801, CVE-2022-0802, CVE-2022-0803, CVE-2022-0804, CVE-2022-0805, CVE-2022-0806, CVE-2022-0807, CVE-2022-0808, CVE-2022-0809

  • Changes in 85.0.4341.13

    • DNA-94119 Upgrade curl to 7.81.0
    • DNA-97849 [Mac monterey] System shortcut interfere with Opera’s ToggleSearchInOpenTabs shortcut
    • DNA-98204 Automatic popout happens when video is paused
    • DNA-98231 Shortcuts are blocked by displayed tab tooltip when triggered quickly after tooltip appears
    • DNA-98321 Add thinlto-cache warnings to suppression list
    • DNA-98395 Promote O85 to stable
  • Complete Opera 85.0 changelog at: https://blogs.opera.com/desktop/changelog-for-85/

  • Update to 84.0.4316.42

    • DNA-94119 Upgrade curl to 7.81.0
    • DNA-98092 Crash at views::MenuItemView::GetMenuController()
    • DNA-98204 Automatic popout happens when video is paused
    • DNA-98231 Shortcuts are blocked by displayed tab tooltip when triggered quickly after tooltip appears
  • Update to 84.0.4316.31

    • CHR-8772 Update chromium on desktop-stable-98-4316 to 98.0.4758.109
    • DNA-97573 [Win][Lin]”Close tab” button is not displayed on tabs playing media when many tabs are open
    • DNA-97729 cancelling the process uploading custom Wallpaper crashes the browser
    • DNA-97871 Google meet tab’s icons don’t fit on pinned tab
    • DNA-97872 Tab is being unpinned when video conferencing button is clicked
    • DNA-98039 Dark theme top sites have black background
    • DNA-98117 Clicking current tab information should hide tooltip
  • Update to 84.0.4316.21

    • CHR-8762 Update chromium on desktop-stable-98-4316 to 98.0.4758.102
    • DNA-97333 ‘Add a site’ label on start page tile barely visible
    • DNA-97691 Opera 84 translations
    • DNA-97767 Wrong string in FR
    • DNA-97855 Crash at ScopedProfileKeepAlive::~ScopedProfileKeepAlive()
    • DNA-97982 Enable #snap-upstream-implementation on all streams
  • The update to chromium 98.0.4758.102 fixes following issues: CVE-2022-0603, CVE-2022-0604, CVE-2022-0605, CVE-2022-0606, CVE-2022-0607, CVE-2022-0608, CVE-2022-0609, CVE-2022-0610

  • Update to 84.0.4316.14

    • CHR-8753 Update chromium on desktop-stable-98-4316 to 98.0.4758.82
    • DNA-97177 Battery saver – the icon looks bad for DPI!=100%
    • DNA-97614 automatic video pop-out for most popular websites broadcasting Winter Olympic Games 2022
    • DNA-97804 Promote O84 to stable
  • The update to chromium 98.0.4758.82 fixes following issues: CVE-2022-0452, CVE-2022-0453, CVE-2022-0454, CVE-2022-0455, CVE-2022-0456, CVE-2022-0457, CVE-2022-0458, CVE-2022-0459, CVE-2022-0460, CVE-2022-0461, CVE-2022-0462, CVE-2022-0463, CVE-2022-0464, CVE-2022-0465, CVE-2022-0466, CVE-2022-0467, CVE-2022-0468, CVE-2022-0469, CVE-2022-0470

  • Complete Opera 84.0 changelog at: https://blogs.opera.com/desktop/changelog-for-84/

  • Update to 83.0.4254.54

    • DNA-96581 Fast tab tooltip doesn’t always show related sites with scrollable tab strip
    • DNA-96608 Cannot drag a tab to create a new window
    • DNA-96657 Do not make tab tooltip hoverable if there’s no list of tabs
    • DNA-97291 Crash at opera::flow::FlowSessionImpl::RegisterDevice(base::OnceCallback)
    • DNA-97468 Incorrect number of restored tabs when video-popout is detached
    • DNA-97476 Add retry to stapling during signing
    • DNA-97609 Failing MetricsReporterTest.TimeSpent* smoketests
  • Update to 83.0.4254.27

    • CHR-8737 Update chromium on desktop-stable-97-4254 to 97.0.4692.99
    • DNA-96336 [Mac] Translate new network installer slogan
    • DNA-96678 Add battery level monitoring capability to powerSavePrivate
    • DNA-96939 Crash at opera::ExternalVideoService::MarkAsManuallyClosed()
    • DNA-97276 Enable #static-tab-audio-indicator on all streams
  • The update to chromium 97.0.4692.99 fixes following issues: CVE-2022-0289, CVE-2022-0290, CVE-2022-0291, CVE-2022-0292, CVE-2022-0293, CVE-2022-0294, CVE-2022-0295, CVE-2022-0296, CVE-2022-0297, CVE-2022-0298, CVE-2022-0300, CVE-2022-0301, CVE-2022-0302, CVE-2022-0304, CVE-2022-0305, CVE-2022-0306, CVE-2022-0307, CVE-2022-0308, CVE-2022-0309, CVE-2022-0310, CVE-2022-0311

  • Update to 83.0.4254.19

    • DNA-96079 Turn on #automatic-video-popout on developer
    • DNA-97070 Opera 83 translations
    • DNA-97119 [LastCard] Stop showing used burner cards
    • DNA-97131 Enable automatic-video-popout on all streams from O84 on
    • DNA-97257 Crash at views::ImageButton::SetMinimumImageSize(gfx::Size const&)
    • DNA-97259 Promote O83 to stable
  • Complete Opera 83.0 changelog at: https://blogs.opera.com/desktop/changelog-for-83/

  • Update to 83.0.4254.16

    • DNA-96968 Fix alignment of the 'Advanced' button in Settings
  • Update to 83.0.4254.14

    • CHR-8701 Update chromium on desktop-stable-97-4254 to 97.0.4692.45
    • CHR-8713 Update chromium on desktop-stable-97-4254 to 97.0.4692.56
    • CHR-8723 Update chromium on desktop-stable-97-4254 to 97.0.4692.71
    • DNA-96780 Crash at ui::NativeTheme::RemoveObserver(ui::NativeThemeObserver*)
    • DNA-96822 Tab close resize behavior change
    • DNA-96861 Create Loomi Options menu
    • DNA-96904 Support Win11 snap layout popup
    • DNA-96951 Tab close animation broken
    • DNA-96991 Tab X button doesn’t work correctly
    • DNA-97027 Incorrect tab size after tab close
  • The update to chromium 97.0.4692.71 fixes following issues: CVE-2022-0096, CVE-2022-0097, CVE-2022-0098, CVE-2022-0099, CVE-2022-0100, CVE-2022-0101, CVE-2022-0102, CVE-2022-0103, CVE-2022-0104, CVE-2022-0105, CVE-2022-0105, CVE-2022-0106, CVE-2022-0107, CVE-2022-0108, CVE-2022-0109, CVE-2022-0110, CVE-2022-0111, CVE-2022-0111, CVE-2022-0112, CVE-2022-0113, CVE-2022-0114, CVE-2022-0115, CVE-2022-0116, CVE-2022-0117, CVE-2022-0118, CVE-2022-0120

  • Update to version 82.0.4227.58

    • DNA-96780 Crash at ui::NativeTheme::RemoveObserver(ui::NativeThemeObserver*)
    • DNA-96890 Settings default browser not working for current user on Windows 7
  • Update to version 82.0.4227.43

    • CHR-8705 Update chromium on desktop-stable-96-4227 to 96.0.4664.110
    • DNA-93284 Unstable obj/opera/desktop/common/installer_rc_generated/installer.res
    • DNA-95908 Interstitial/internal pages shown as NOT SECURE after visiting http site
    • DNA-96404 Opera doesn’t show on main screen when second screen is abruptly disconnected
  • The update to chromium 96.0.4664.110 fixes following issues: CVE-2021-4098, CVE-2021-4099, CVE-2021-4100, CVE-2021-4101, CVE-2021-4102

  • Update to version 82.0.4227.33

    • CHR-8689 Update chromium on desktop-stable-96-4227 to 96.0.4664.93
    • DNA-96559 Tooltip popup looks bad in dark theme
    • DNA-96570 [Player] Tidal logging in via PLAY doesn’t work
    • DNA-96594 Unnecessary extra space in fullscreen mode on M1 Pro MacBooks
    • DNA-96649 Update Meme button
    • DNA-96676 Add Icon in the Sidebar Setup
    • DNA-96677 Add default URL
  • The update to chromium 96.0.4664.93 fixes following issues: CVE-2021-4052, CVE-2021-4053, CVE-2021-4079, CVE-2021-4054, CVE-2021-4078, CVE-2021-4055, CVE-2021-4056, CVE-2021-4057, CVE-2021-4058, CVE-2021-4059, CVE-2021-4061, CVE-2021-4062, CVE-2021-4063, CVE-2021-4064, CVE-2021-4065, CVE-2021-4066, CVE-2021-4067, CVE-2021-4068

  • Update to version 82.0.4227.23

    • DNA-95632 With new au-logic UUID is set with delay and may be not set for pb-builds (when closing fast)
    • DNA-96349 Laggy tooltip animation
    • DNA-96483 [Snap][Linux] Video not working / wrong ffmpeg snap version for Opera 82
    • DNA-96493 Create 'small' enticement in credit card autofill
    • DNA-96533 Opera 82 translations
    • DNA-96535 Make the URL configurable
    • DNA-96553 Add switch to whitelist test pages
    • DNA-96557 Links not opened from panel
    • DNA-96558 AdBlock bloks some trackers inside the panel
    • DNA-96568 [Player] Tidal in sidebar Player opens wrong site when logging in
    • DNA-96659 Siteprefs not applied after network service crash
    • DNA-96593 Promote O82 to stable
  • Complete Opera 82.0 changelog at: https://blogs.opera.com/desktop/changelog-for-82/

  • Update to version 82.0.4227.13

    • CHR-8668 Update chromium on desktop-stable-96-4227 to 96.0.4664.45
    • DNA-76987 [Mac] Update desktop EULA with geolocation split
    • DNA-93388 Problem with symlinks on windows when creating file list
    • DNA-95734 Discarded Recently Closed items get revived after restart
    • DNA-96134 'Your profile has been updated' does not disappear
    • DNA-96190 Opera freezes when trying to drag expanded bookmark folder with nested subfolders
    • DNA-96223 Easy Files not working in Full Screen
    • DNA-96274 Checkout autofill shouldn't show used burner card
    • DNA-96275 Change the notification message for pausing multi-use cards
    • DNA-96295 'Video pop out' setting doesn't sync
    • DNA-96316 Highlight text wrong colour on dark mode
    • DNA-96326 Wrong translation Private Mode > Turkish
    • DNA-96351 macOS window controls are missing in full screen
    • DNA-96440 Update video URL
    • DNA-96448 add option to pin extension via rich hints
    • DNA-96453 Register user-chosen option on client-side, read on hint side
    • DNA-96454 Choosing an option from the settings menu should close the popup
    • DNA-96484 Enable AB test for a new autoupdater logic (for 50%)
    • DNA-96500 Add 'don't show me again' prefs to allowed whitelist
    • DNA-96538 Inline audiocomplete for www.mediaexpert.pl incorrectly suggested
  • The update to chromium 96.0.4664.45 fixes following issues: CVE-2021-38005, CVE-2021-38006, CVE-2021-38007, CVE-2021-38008, CVE-2021-38009, CVE-2021-38010, CVE-2021-38011, CVE-2021-38012, CVE-2021-38013, CVE-2021-38014, CVE-2021-38015, CVE-2021-38016, CVE-2021-38017, CVE-2021-38019, CVE-2021-38020, CVE-2021-38021, CVE-2021-38022

  • Update to version 81.0.4196.54

    • CHR-8644 Update chromium on desktop-stable-95-4196 to 95.0.4638.69
    • DNA-95773 ExtensionWebRequestApiTest crashes on mac
    • DNA-96062 Opera 81 translations
    • DNA-96134 “Your profile has been updated’ does not disappear
    • DNA-96274 Checkout autofill shouldn’t show used burner card
    • DNA-96275 Change the notification message for pausing multi-use cards
    • DNA-96440 Update video URL
  • The update to chromium 95.0.4638.69 fixes following issues: CVE-2021-37997, CVE-2021-37998, CVE-2021-37999, CVE-2021-37980, CVE-2021-38001, CVE-2021-38002, CVE-2021-38003, CVE-2021-38004

  • Update to version 81.0.4196.37

    • DNA-96008 Crash at content::WebContentsImpl::OpenURL(content::OpenURLParams const&)
    • DNA-96032 Closing the videoconference pop-up force leaving the meeting
    • DNA-96092 Crash at void opera::ModalDialogViews::OnWidgetClosing(opera::ModalDialog::Result)
    • DNA-96142 [Yat] Emoji icon cut off in URL for Yat
  • Update to version 81.0.4196.31

    • DNA-95733 Implement the “Manage” menu in card details view
    • DNA-95736 Update UI for paused card
    • DNA-95791 Crash at base::operator<
    • DNA-95794 Sometimes the sidebar UI fails to load
    • DNA-95812 Retrieve cards info when showing autofill
    • DNA-96035 Cannot create virtual card on Sandbox environment
    • DNA-96147 “Buy” button does not work
    • DNA-96168 Update contributors list
    • DNA-96211 Enable #fast-tab-tooltip on all streams
    • DNA-96231 Promote O81 to stable
  • Complete Opera 80.1 changelog at: https://blogs.opera.com/desktop/changelog-for-81/

  • Update to version 81.0.4196.27

    • CHR-8623 Update chromium on desktop-stable-95-4196 to 95.0.4638.54
    • DNA-92384 Better segmenting of hint users
    • DNA-95523 Allow sorting in multi-card view
    • DNA-95659 Flow of Lastcard on first login
    • DNA-95735 Implement the button that reveals full card details
    • DNA-95747 Better way to handle expired funding card
    • DNA-95949 [Mac Retina] Clicking active tab should scroll to the top
    • DNA-95993 Update icon used for Yat in address bar dropdown
    • DNA-96021 Cleared download item view is never deleted
    • DNA-96036 Occupation field in 'Account – Edit' is shown twice
    • DNA-96127 Upgrade plan button does nothing
    • DNA-96138 'Add Card' button does not change to 'Upgrade Plan' after adding card
  • The update to chromium 95.0.4638.54 fixes following issues: CVE-2021-37981, CVE-2021-37982, CVE-2021-37983, CVE-2021-37984, CVE-2021-37985, CVE-2021-37986, CVE-2021-37987, CVE-2021-37988, CVE-2021-37989, CVE-2021-37990, CVE-2021-37991, CVE-2021-37992, CVE-2021-37993, CVE-2021-37994, CVE-2021-37995, CVE-2021-37996

  • Update to version 80.0.4170.72

    • DNA-95522 Change card view to show all types of cards
    • DNA-95523 Allow sorting in multi-card view
    • DNA-95524 Allow searching for cards by name
    • DNA-95658 Allow user to add a card
    • DNA-95659 Flow of Lastcard on first login
    • DNA-95660 Implement editing card details
    • DNA-95699 Add card details view
    • DNA-95733 Implement the “Manage” menu in card details view
    • DNA-95735 Implement the button that reveals full card details
    • DNA-95736 Update UI for paused card
    • DNA-95747 Better way to handle expired funding card
    • DNA-95794 Sometimes the sidebar UI fails to load
    • DNA-95812 Retrieve cards info when showing autofill
    • DNA-96036 Occupation field in ‘Account – Edit’ is shown twice
    • DNA-96127 Upgrade plan button does nothing
    • DNA-96138 “Add Card” button does not change to “Upgrade Plan” after adding card
  • Update to version 80.0.4170.63

    • CHR-8612 Update chromium on desktop-stable-94-4170 to 94.0.4606.81
    • DNA-95434 Crash at opera::ThemesService::UpdateCurrentTheme()
  • The update to chromium 94.0.4606.81 fixes following issues: CVE-2021-37977, CVE-2021-37978, CVE-2021-37979, CVE-2021-37980

  • Update to version 80.0.4170.40

    • CHR-8598 Update chromium on desktop-stable-94-4170 to 94.0.4606.71
    • DNA-95221 Emoji button stuck in address bar
    • DNA-95325 Make y.at navigations to be reported with page_views events
    • DNA-95327 Add “Emojis” context menu option in address bar field
    • DNA-95339 Add YAT emoji url suggestion to search© dialog
    • DNA-95416 Remove emoji button from address bar
    • DNA-95439 Enable #yat-emoji-addresses on developer stream
    • DNA-95441 [Mac big sur] Emoji are not shown in address bar url
    • DNA-95514 Crash at resource_coordinator::TabLifecycleUnitSource ::TabLifecycleUnit::OnLifecycleUnitStateChanged(mojom:: LifecycleUnitState, mojom::LifecycleUnitStateChangeReason)
    • DNA-95746 Enable #reader-mode everywhere
    • DNA-95865 Numbers are recognized as emojis
    • DNA-95866 Change Yat text in selection popup
    • DNA-95867 Show that buttons are clickable in selection popup
  • The update to chromium 94.0.4606.71 fixes following issues: CVE-2021-37974, CVE-2021-37975, CVE-2021-37976

  • Update to version 80.0.4170.16

    • CHR-8590 Update chromium on desktop-stable-94-4170 to 94.0.4606.61
    • DNA-95347 Make InstallerStep::Run async
    • DNA-95420 First suggestion in address field is often not highlighted
    • DNA-95613 Browser closing itself after closing SD/first tab and last opened tab
    • DNA-95725 Promote O80 to stable
    • DNA-95781 Import fixes for CVE-2021-37975, CVE-2021-37976 and CVE-2021-37974 to desktop-stable-94-4170
  • Complete Opera 80.0 changelog at: https://blogs.opera.com/desktop/changelog-for-80/

  • Drop Provides/Obsoletes for opera-gtk and opera-kde4 opera-gtk and opera-kde4 were last used in openSUSE 13.1

  • Drop post/postun for desktop_database_post and icon_theme_cache_post because were last used before openSUSE 15.0

  • Update to version 79.0.4143.72

    • DNA-94933 Add emoji panel to address bar
    • DNA-95210 Add emoji YAT address bar suggestions
    • DNA-95221 Emoji button stuck in address bar
    • DNA-95325 Make y.at navigations to be reported with page_views events
    • DNA-95327 Add “Emojis” context menu option in address bar field
    • DNA-95339 Add YAT emoji url suggestion to search© dialog
    • DNA-95364 Add browser feature flag
    • DNA-95416 Remove emoji button from address bar
    • DNA-95439 Enable #yat-emoji-addresses on developer stream
    • DNA-95441 [Mac big sur] Emoji are not shown in address bar url
    • DNA-95445 Crash when removing unsynced pinboard bookmark with sync enabled
    • DNA-95512 Allow to show title and timer for simple banners
    • DNA-95516 Wrong label in settings for themes
    • DNA-95679 Temporarily disable AB test for a new autoupdater logic
  • Update to version 79.0.4143.50

    • CHR-8571 Update chromium on desktop-stable-93-4143 to 93.0.4577.82
    • DNA-94104 ContinueShoppingOnEbayBrowserTest.ShouldDisplayOffers TilesStartingWithMostActiveOnes fails
    • DNA-94894 [Rich Hint] Agent API permissions
    • DNA-94989 Wrong color and appearance of subpages in the settings
    • DNA-95241 “Switch to tab” button is visible only on hover
    • DNA-95286 Add unit tests to pinboard sync related logic in browser
    • DNA-95372 [Mac retina screen] Snapshot doesnt capture cropped area
    • DNA-95526 Some webstore extensions are not verified properly
  • The update to chromium 93.0.4577.82 fixes following issues: CVE-2021-30625, CVE-2021-30626, CVE-2021-30627, CVE-2021-30628, CVE-2021-30629, CVE-2021-30630, CVE-2021-30631, CVE-2021-30632, CVE-2021-30633

  • Update to version 79.0.4143.22

    • CHR-8550 Update chromium on desktop-stable-93-4143 to 93.0.4577.58
    • CHR-8557 Update chromium on desktop-stable-93-4143 to 93.0.4577.63
    • DNA-94641 [Linux] Proprietary media codecs not working in snap builds
    • DNA-95076 [Linux] Page crash with media content
    • DNA-95084 [Mac] Cannot quit through menu with snapshot editor open
    • DNA-95138 Add setting to synchronize Pinboards
    • DNA-95157 Crash at -[OperaCrApplication sendEvent:]
    • DNA-95204 Opera 79 translations
    • DNA-95240 The pinboard thumbnail cannot be generated anymore
    • DNA-95278 Existing Pinboards might be missing
    • DNA-95292 Enable #bookmarks-trash-cleaner on all streams
    • DNA-95293 Enable #easy-files-downloads-folder on all streams
    • DNA-95383 Promote O79 to stable
  • Complete Opera 79.0 changelog at: https://blogs.opera.com/desktop/changelog-for-79/

  • The update to chromium 93.0.4577.58 fixes following issues: CVE-2021-30606, CVE-2021-30607, CVE-2021-30608, CVE-2021-30609, CVE-2021-30610, CVE-2021-30611, CVE-2021-30612, CVE-2021-30613, CVE-2021-30614, CVE-2021-30615, CVE-2021-30616, CVE-2021-30617, CVE-2021-30618, CVE-2021-30619, CVE-2021-30620, CVE-2021-30621, CVE-2021-30622, CVE-2021-30623, CVE-2021-30624

  • Update to version 78.0.4093.184

    • CHR-8533 Update chromium on desktop-stable-92-4093 to 92.0.4515.159
    • DNA-93472 Reattaching to other browsers
    • DNA-93741 Multiple hint slots
    • DNA-93742 Allow displaying unobtrusive external hints
    • DNA-93744 Add slots in toolbar action view
    • DNA-94230 Improve text contrast for Speed Dials
    • DNA-94724 [Mac] Add macOS dark theme wallpaper with easy setup
    • DNA-94786 Crash at base::SupportsUserData:: SetUserData(void const*, std::__1::unique_ptr)
    • DNA-94807 Allow scripts access opera version and product info
    • DNA-94862 Continue on shopping Amazon doesn’t work correct
    • DNA-94870 Add an addonsPrivate function to install with permissions dialog first
    • DNA-95064 Revert DNA-93714 on stable
  • The update to chromium 92.0.4515.159 fixes following issues: CVE-2021-30598, CVE-2021-30599, CVE-2021-30600, CVE-2021-30601, CVE-2021-30602, CVE-2021-30603, CVE-2021-30604

  • Update to version 78.0.4093.147

    • CHR-8251 Update chromium on desktop-stable-92-4093 to 92.0.4515.131
    • DNA-93036 Opera not starting after closing window. Processes still working.
    • DNA-94516 Add ‘Detach tab’ entry to tab menu
    • DNA-94584 [Mac] Sidebar setup not closed after press ‘Add extensions’ button
    • DNA-94761 Crash when trying to record “Chrome developer” trace
    • DNA-94790 Crash at opera::VideoConferenceTabDetachController:: OnBrowserAboutToStartClosing(Browser*)
  • The update to chromium 92.0.4515.131 fixes following issues: CVE-2021-30590, CVE-2021-30591, CVE-2021-30592, CVE-2021-30593, CVE-2021-30594, CVE-2021-30596, CVE-2021-30597

  • Update to version 78.0.4093.112

    • DNA-94466 Implement sorting Pinboards in overview
    • DNA-94582 Add access to APIs for showing pinboard icon in sidebar
    • DNA-94603 Suspicious pinboards events
    • DNA-94625 Disable opr.pinboardPrivate.getThumbnail() for local files
    • DNA-94640 Promote O78 to stable
    • DNA-94661 Missing translations for some languages
  • Complete Opera 78.0 changelog at: https://blogs.opera.com/desktop/changelog-for-78/

  • Update to version 77.0.4054.277

    • CHR-8502 Update chromium on desktop-stable-91-4054 to 91.0.4472.164
    • DNA-94291 Video conference popout doesnt remember its size after resizing
    • DNA-94399 Incorrect icon for wp.pl in address bar dropdown
    • DNA-94462 Low quality of default wallpaper on windows
  • The update to chromium 91.0.4472.164 fixes following issues: CVE-2021-30541, CVE-2021-30560, CVE-2021-30561, CVE-2021-30562, CVE-2021-30563, CVE-2021-30564

  • Update to version 77.0.4054.254

    • DNA-92344 Windows 10 Implementation
    • DNA-92486 Replace ⓧ icon with “settings” icon
    • DNA-92487 Close individual item
    • DNA-92496 Create separate entry in settings for BABE
    • DNA-93275 Implement cycles size according to design
    • DNA-93280 The system theme has only half a checkmark
    • DNA-93728 Whatsapp notification is not refreshed
    • DNA-94047 Remove pinboard WebUI integration
    • DNA-94118 Write test for ThumbnailTabHelper changes in DNA-94100
    • DNA-94120 Fix Welcome popup layout
    • DNA-94140 Crash at base::TaskRunner ::PostTask(base::Location const&, base::OnceCallback)
    • DNA-94205 Consider setting pinboard display URL in address_field_helper.cc
    • DNA-94211 Easy Files don’t show thumbnails
    • DNA-94309 Pinboards URLs don’t get lighter color treatment
    • DNA-94318 Wrong ‘Transparency’ word translation in Swedish
    • DNA-94321 AB test: google suggestions on top – bigger test
    • DNA-94341 Make pinboard popup testable on web page
    • DNA-94381 Disabling Pinboards doesn’t remove item from menu / sidebar
    • DNA-94392 Add u2f-devices interface to snap packages
    • DNA-94461 Enable #system-theme on all streams
  • Update to version 77.0.4054.203

    • CHR-8475 Update chromium on desktop-stable-91-4054 to 91.0.4472.124
    • DNA-93523 Crash at extensions::TabHelper::WebContentsDestroyed()
    • DNA-93917 Upload snap to edge while preparing repository package
    • DNA-94157 Crash at gfx::ICCProfile::operator=(gfx::ICCProfile const&)
    • DNA-94159 Crash at opera::auth::AuthAccountServiceImpl::GetAuthAccount()
    • DNA-94161 [Add tabs]Unexpected symbols instead of Workspace name
    • DNA-94241 Implement better process killing for timeout
    • DNA-94248 Allow retry on tests that timed-out
    • DNA-94251 heap-use-after-free in VideoConference
    • DNA-94315 Crash at class std::__1::basic_string ui::ResourceBundle:: LoadLocaleResources(const class std::__1::basic_string& const, bool)
    • DNA-94357 Fix issue in scripts
  • Update to version 77.0.4054.172

    • DNA-93078 Do not display ‘share tab’ sliding toolbar on detached tab
    • DNA-93358 The red underline extends beyond the Google meets conference tab outline
    • DNA-93404 Crash in test when destroying BABE’s webcontents
    • DNA-93637 ctrl+9 shortcut is inconsistent with other browsers
    • DNA-93661 Add opauto test to cover new shortcut from DNA-93637
    • DNA-93867 Use version from package instead of repository
    • DNA-93993 Pinboard translations from Master
    • DNA-94099 Increase new-autoupdater-logic AB test to cover 50% of new installations
    • DNA-94100 Thumbnail doesn’t update
    • DNA-94178 Automatic popout should not happen after manually closing a popout
  • Update to version 77.0.4054.146

    • CHR-8458 Update chromium on desktop-stable-91-4054 to 91.0.4472.114
    • DNA-92171 Create active linkdiscovery service
    • DNA-92388 Fix and unskip WorkspacesEmoji.testChooseEmojiAsWorkspaceIcon when possible
    • DNA-93101 Tabs are being snoozed when tab snoozing is disabled
    • DNA-93386 Update pinboard view when item changes
    • DNA-93448 Make browser ready for Developer release
    • DNA-93491 Fix failing tests after enabling #pinboard flag
    • DNA-93498 Add additional music services
    • DNA-93503 Blank popup on clicking toolbar icon with popup open
    • DNA-93561 Do not allow zoom different from 100% in Pinboard popup
    • DNA-93637 ctrl+9 shortcut is inconsistent with other browsers
    • DNA-93644 Create route for import open tabs to pinboard
    • DNA-93664 Adapt popup to design
    • DNA-93702 Turn on flags on developer
    • DNA-93737 [Pinboard] Remove Mock API
    • DNA-93745 Unable to open the popup after opening it several times
    • DNA-93776 Popup closes and reopens when clicking the toolbar button
    • DNA-93786 DCHECK after opening popup
    • DNA-93802 Crash at views::Widget::GetNativeView() const
    • DNA-93810 Add pinboard icon to sidebar
    • DNA-93825 Add pinboard to Opera menu
    • DNA-93833 [Player] Implement seeking for new services
    • DNA-93845 Do not log output of snapcraft on console
    • DNA-93864 Create feature flag for start page sync banner
    • DNA-93865 Implement start page banner
    • DNA-93867 Use version from package instead of repository
    • DNA-93878 [Player] Crash when current player service becomes unavailable when user location changes
    • DNA-93953 ‘Send image to Pinboard’ has the wrong position in the context menu
    • DNA-93987 Disable zooming popup contents like in other popups
    • DNA-93989 Change internal URL to opera://pinboards
    • DNA-93990 Update strings to reflect new standards
    • DNA-93992 Add Pinboards to Opera settings
    • DNA-93993 Pinboard translations from Master
    • DNA-94011 Enable feature flags for Reborn 5 on stable
    • DNA-94019 Add a direct link to settings
    • DNA-94088 Internal pages provoke not saving other pages to the Pinboard
    • DNA-94111 [O77] Sidebar setup does not open
    • DNA-94139 Crash at opera::(anonymous namespace)::PinboardPopupWebView::RemovedFromWidget()
  • The update to chromium 91.0.4472.114 fixes following issues: CVE-2021-30554, CVE-2021-30555, CVE-2021-30556, CVE-2021-30557

  • Update to version 77.0.4054.90

    • CHR-8446 Update chromium on desktop-stable-91-4054 to 91.0.4472.101
  • The update to chromium 91.0.4472.101 fixes following issues:
    CVE-2021-30544, CVE-2021-30545, CVE-2021-30546, CVE-2021-30547, CVE-2021-30548, CVE-2021-30549, CVE-2021-30550, CVE-2021-30551, CVE-2021-30552, CVE-2021-30553

  • Update to version 77.0.4054.80

    • DNA-93656 Active cards in checkout Auto-fill
    • DNA-93805 Create snap packages in buildsign
    • DNA-93823 archive_opera_snap failures on Linux
    • DNA-93844 Fix AttributeError in package_type.py
  • Update to version 77.0.4054.64

    • DNA-93159 Implement image(preview) of each created pinboard
    • DNA-93273 ‘Send image to Pinboard’ doesn’t work correct on staging server
    • DNA-93277 Add/update opauto tests for the System Theme WP1 implementation p.1
    • DNA-93286 [BigSur] YT not being reloaded when opened from link
    • DNA-93296 Opera 77 translations
    • DNA-93372 Build new edition for Axel Springer
    • DNA-93376 Write unittests for PinboardImageCollector
    • DNA-93401 [LastCard] Do not change user state if not needed
    • DNA-93409 Animation with hat and glasses is missing in Private mode
    • DNA-93443 API opr.pinboardPrivate.getThumbnail() returns old thumbnail image
    • DNA-93509 Add Opera switch for pinboard staging backend and use it for tests
    • DNA-93519 [Sidebar] WhatsApp ‘Log out’ doesn’t work
    • DNA-93634 Fix errors in Slovak translations
    • DNA-93724 Some webstore extensions are not verified properly
  • Complete Opera 77.0 changelog at: https://blogs.opera.com/desktop/changelog-for-77/

  • Update to version 76.0.4017.177

    • DNA-92597 Sound controller doesn’t work after pressing ‘Next’ button
    • DNA-93405 Import vmp_signer instead of starting new python process
    • DNA-93406 [Mac] Import plist_util instead of calling script in _generateAppEntitlements
    • DNA-93442 Make GX Control panel attachable by webdriver
    • DNA-93554 [AdBlock] Find a fix for blocking ‘new’ YouTube ads
    • DNA-93587 Pre-refactor solution
  • Update to version 76.0.4017.154

    • CHR-8420 Update chromium on desktop-stable-90-4017 to 90.0.4430.212
    • DNA-92411 Bookmarks breadcrumbs wrong color when pressed in dark mode
    • DNA-92587 Sync settings: “Use old password” button doesn’t work
    • DNA-92672 Make it possible for agent to inject scripts into startpage
    • DNA-92712 Add SD reload API
    • DNA-93190 The bookmark can’t be opened in Workspace 5-6
    • DNA-93247 Reopen last closed tab shortcut opens random tab on new window
    • DNA-93294 Binary diff for opera_browser.dll is not created on 32-bit builds
    • DNA-93313 Add opauto test to cover DNA-93190
    • DNA-93368 Fix an error in Polish translation
    • DNA-93408 [Windows] widevine_cdm_component_installer does not compile on desktop-stable-90-4017
  • The update to chromium 90.0.4430.212 fixes following issues:
    CVE-2021-30506, CVE-2021-30507, CVE-2021-30508, CVE-2021-30509, CVE-2021-30510, CVE-2021-30511, CVE-2021-30512, CVE-2021-30513, CVE-2021-30514, CVE-2021-30515, CVE-2021-30516, CVE-2021-30517, CVE-2021-30518, CVE-2021-30519, CVE-2021-30520

Список пакетов

openSUSE Leap 15.4 NonFree
opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Incorrect security UI in Web App Installs in Google Chrome on Android prior to 90.0.4430.212 allowed an attacker who convinced a user to install a web application to inject scripts or HTML into a privileged page via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Inappropriate implementation in Offline in Google Chrome on Android prior to 90.0.4430.212 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Heap buffer overflow in Media Feeds in Google Chrome prior to 90.0.4430.212 allowed an attacker who convinced a user to enable certain features in Chrome to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Out of bounds write in Tab Strip in Google Chrome prior to 90.0.4430.212 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory write via a crafted HTML page and a crafted Chrome extension.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in Aura in Google Chrome prior to 90.0.4430.212 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Out of bounds read in Tab Groups in Google Chrome prior to 90.0.4430.212 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory read via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in Notifications in Google Chrome prior to 90.0.4430.212 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Type confusion in V8 in Google Chrome prior to 90.0.4430.212 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in Autofill in Google Chrome prior to 90.0.4430.212 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in File API in Google Chrome prior to 90.0.4430.212 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Heap buffer overflow in History in Google Chrome prior to 90.0.4430.212 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Type confusion in V8 in Google Chrome prior to 90.0.4430.212 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Heap buffer overflow in Reader Mode in Google Chrome prior to 90.0.4430.212 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in Payments in Google Chrome prior to 90.0.4430.212 allowed an attacker who convinced a user to install a malicious payments app to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in Tab Strip in Google Chrome prior to 90.0.4430.212 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in V8 in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in BFCache in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in Extensions in Google Chrome prior to 91.0.4472.101 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in Autofill in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Out of bounds write in ANGLE in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in Loader in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in Spell check in Google Chrome prior to 91.0.4472.101 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in Accessibility in Google Chrome prior to 91.0.4472.101 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Type confusion in V8 in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in Extensions in Google Chrome prior to 91.0.4472.101 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in Network service in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in WebGL in Google Chrome prior to 91.0.4472.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in Sharing in Google Chrome prior to 91.0.4472.114 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page and user gesture.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in WebAudio in Google Chrome prior to 91.0.4472.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in TabGroups in Google Chrome prior to 91.0.4472.114 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in Blink XSLT in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Type Confusion in V8 in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in WebSerial in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Type Confusion in V8 in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Heap buffer overflow in WebXR in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Heap buffer overflow in Bookmarks in Google Chrome prior to 92.0.4515.131 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in File System API in Google Chrome prior to 92.0.4515.131 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Out of bounds write in Tab Groups in Google Chrome prior to 92.0.4515.131 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory write via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Out of bounds read in Tab Strip in Google Chrome prior to 92.0.4515.131 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory read via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in Page Info UI in Google Chrome prior to 92.0.4515.131 allowed a remote attacker to potentially exploit heap corruption via physical access to the device.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Incorrect security UI in Navigation in Google Chrome on Android prior to 92.0.4515.131 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in Browser UI in Google Chrome on Chrome prior to 92.0.4515.131 allowed a remote attacker to potentially exploit heap corruption via physical access to the device.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Type confusion in V8 in Google Chrome prior to 92.0.4515.159 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Type confusion in V8 in Google Chrome prior to 92.0.4515.159 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in Printing in Google Chrome prior to 92.0.4515.159 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in Extensions API in Google Chrome prior to 92.0.4515.159 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in WebRTC in Google Chrome prior to 92.0.4515.159 allowed an attacker who convinced a user to visit a malicious website to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Data race in WebAudio in Google Chrome prior to 92.0.4515.159 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in ANGLE in Google Chrome prior to 92.0.4515.159 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Chromium: CVE-2021-30606 Use after free in Blink


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Chromium: CVE-2021-30607 Use after free in Permissions


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Chromium: CVE-2021-30608 Use after free in Web Share


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Chromium: CVE-2021-30609 Use after free in Sign-In


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Chromium: CVE-2021-30610 Use after free in Extensions API


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Chromium: CVE-2021-30611 Use after free in WebRTC


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Chromium: CVE-2021-30612 Use after free in WebRTC


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Chromium: CVE-2021-30613 Use after free in Base internals


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Chromium: CVE-2021-30614 Heap buffer overflow in TabStrip


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Chromium: CVE-2021-30615 Cross-origin data leak in Navigation


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Chromium: CVE-2021-30616 Use after free in Media


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Chromium: CVE-2021-30617 Policy bypass in Blink


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Chromium: CVE-2021-30618 Inappropriate implementation in DevTools


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Chromium: CVE-2021-30619 UI Spoofing in Autofill


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Chromium: CVE-2021-30620 Insufficient policy enforcement in Blink


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Chromium: CVE-2021-30621 UI Spoofing in Autofill


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Chromium: CVE-2021-30622 Use after free in WebApp Installs


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Chromium: CVE-2021-30623 Use after free in Bookmarks


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Chromium: CVE-2021-30624 Use after free in Autofill


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in Selection API in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who convinced the user the visit a malicious website to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Out of bounds memory access in ANGLE in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Type confusion in Blink layout in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Stack buffer overflow in ANGLE in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit stack corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in Permissions in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Inappropriate implementation in Blink in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Out of bounds write in V8 in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in Indexed DB API in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in Safebrowsing in Google Chrome prior to 94.0.4606.71 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in V8 in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Inappropriate implementation in Memory in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in Garbage Collection in Google Chrome prior to 94.0.4606.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Heap buffer overflow in Blink in Google Chrome prior to 94.0.4606.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

heap buffer overflow in WebRTC in Google Chrome prior to 94.0.4606.81 allowed a remote attacker who convinced a user to browse to a malicious website to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Inappropriate implementation in Sandbox in Google Chrome prior to 94.0.4606.81 allowed a remote attacker to potentially bypass site isolation via Windows.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Heap buffer overflow in Skia in Google Chrome prior to 95.0.4638.54 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in Incognito in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in Dev Tools in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Heap buffer overflow in PDFium in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in V8 in Google Chrome prior to 95.0.4638.54 allowed a remote attacker who had convinced a user to allow for connection to debugger to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Heap buffer overflow in Settings in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to engage with Dev Tools to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in Network APIs in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in Profiles in Google Chrome prior to 95.0.4638.54 allowed a remote attacker who convinced a user to engage in specific gestures to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Inappropriate implementation in Blink in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to abuse content security policy via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Inappropriate implementation in WebView in Google Chrome on Android prior to 95.0.4638.54 allowed a remote attacker to leak cross-origin data via a crafted app.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Race in V8 in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Out of bounds read in WebAudio in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in PDF Accessibility in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Inappropriate implementation in iFrame Sandbox in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Inappropriate implementation in WebApp Installer in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to potentially overlay and spoof the contents of the Omnibox (URL bar) via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Insufficient validation of untrusted input Downloads in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to bypass navigation restrictions via a malicious file.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in Sign-In in Google Chrome prior to 95.0.4638.69 allowed a remote attacker who convinced a user to sign into Chrome to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in Garbage Collection in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Insufficient data validation in New Tab Page in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to inject arbitrary scripts or HTML in a new browser tab via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Type confusion in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in Web Transport in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Inappropriate implementation in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Insufficient policy enforcement in Autofill in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to leak cross-origin data via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in loader in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in storage foundation in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Type confusion in V8 in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in media in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Inappropriate implementation in cache in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to leak cross-origin data via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Inappropriate implementation in service workers in Google Chrome prior to 96.0.4664.45 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in storage foundation in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Type confusion in V8 in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Heap buffer overflow in fingerprint recognition in Google Chrome on ChromeOS prior to 96.0.4664.45 allowed a remote attacker who had compromised a WebUI renderer process to potentially perform a sandbox escape via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Out of bounds write in Swiftshader in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Inappropriate implementation in input in Google Chrome prior to 96.0.4664.45 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Insufficient policy enforcement in background fetch in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to bypass same origin policy via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Insufficient policy enforcement in iframe sandbox in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Insufficient policy enforcement in CORS in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to leak cross-origin data via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Insufficient policy enforcement in contacts picker in Google Chrome on Android prior to 96.0.4664.45 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Inappropriate implementation in referrer in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Inappropriate implementation in WebAuthentication in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to leak cross-origin data via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in web apps in Google Chrome prior to 96.0.4664.93 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in UI in Google Chrome on Linux prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Incorrect security UI in autofill in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to perform domain spoofing via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Heap buffer overflow in extensions in Google Chrome prior to 96.0.4664.93 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Type confusion in loader in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in file API in Google Chrome prior to 96.0.4664.93 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Heap buffer overflow in ANGLE in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Insufficient data validation in loader in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to leak cross-origin data via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Type confusion in V8 in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Heap buffer overflow in BFCache in Google Chrome prior to 96.0.4664.93 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in developer tools in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in screen capture in Google Chrome on ChromeOS prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in autofill in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Integer underflow in ANGLE in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in window manager in Google Chrome on ChromeOS prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Insufficient data validation in new tab page in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to leak cross-origin data via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Type confusion in V8 in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Out of bounds write in WebRTC in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via crafted WebRTC packets.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Insufficient data validation in Mojo in Google Chrome prior to 96.0.4664.110 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in Swiftshader in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Object lifecycle issue in ANGLE in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Heap buffer overflow in Swiftshader in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in V8 in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in Storage in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Inappropriate implementation in DevTools in Google Chrome prior to 97.0.4692.71 allowed an attacker who convinced a user to install a malicious extension to to potentially allow extension to escape the sandbox via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in Screen Capture in Google Chrome on Chrome OS prior to 97.0.4692.71 allowed an attacker who convinced a user to perform specific user gestures to potentially exploit heap corruption via specific user gestures.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in Sign-in in Google Chrome prior to 97.0.4692.71 allowed a remote attacker who convinced a user to perform specific user gestures to potentially exploit heap corruption via specific user gesture.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Heap buffer overflow in Media streams API in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Heap buffer overflow in Bookmarks in Google Chrome prior to 97.0.4692.71 allowed a remote attacker who convinced a user to perform specific user gesture to potentially exploit heap corruption via specific user gesture.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Type confusion in V8 in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in SwiftShader in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Heap buffer overflow in ANGLE in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in PDF Accessibility in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in Autofill in Google Chrome prior to 97.0.4692.71 allowed a remote attacker who convinced a user to perform specific user gesture to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in File Manager API in Google Chrome on Chrome OS prior to 97.0.4692.71 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Inappropriate implementation in Navigation in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to leak cross-origin data via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Inappropriate implementation in Autofill in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to obtain potentially sensitive information via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Incorrect security UI in Autofill in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Inappropriate implementation in Navigation in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to incorrectly set origin via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Incorrect security UI in Browser UI in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to display missing URL or incorrect URL via a crafted URL.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Inappropriate implementation in Blink in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to leak cross-origin data via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Out of bounds memory access in Blink Serial API in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page and virtual serial port driver.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Uninitialized use in File API in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Inappropriate implementation in Compositing in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Policy bypass in Blink in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to leak cross-origin data via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Inappropriate implementation in WebShare in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially hide the contents of the Omnibox (URL bar) via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Inappropriate implementation in Passwords in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially leak cross-origin data via a malicious website.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in Safe browsing in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in Site isolation in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Inappropriate implementation in Storage in Google Chrome prior to 97.0.4692.99 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Inappropriate implementation in Fenced Frames in Google Chrome prior to 97.0.4692.99 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in Web packaging in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Inappropriate implementation in Push messaging in Google Chrome prior to 97.0.4692.99 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in Omnibox in Google Chrome prior to 97.0.4692.99 allowed a remote attacker who convinced the user to engage is specific user interactions to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in Printing in Google Chrome prior to 97.0.4692.99 allowed a remote attacker who convinced the user to engage is specific user interactions to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in Vulkan in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in Scheduling in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in Text Input Method Editor in Google Chrome on Android prior to 97.0.4692.99 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Heap buffer overflow in DevTools in Google Chrome prior to 97.0.4692.99 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in Omnibox in Google Chrome prior to 97.0.4692.99 allowed an attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in Bookmarks in Google Chrome prior to 97.0.4692.99 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Inappropriate implementation in Service Worker API in Google Chrome prior to 97.0.4692.99 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Heap buffer overflow in PDFium in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in Optimization Guide in Google Chrome prior to 97.0.4692.99 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in Data Transfer in Google Chrome on Chrome OS prior to 97.0.4692.99 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Inappropriate implementation in Autofill in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Heap buffer overflow in Task Manager in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to potentially exploit heap corruption via specific user interactions.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Heap buffer overflow in Task Manager in Google Chrome prior to 97.0.4692.99 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in Safe Browsing in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in Reader Mode in Google Chrome prior to 98.0.4758.80 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Heap buffer overflow in ANGLE in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Inappropriate implementation in Full Screen Mode in Google Chrome on Android prior to 98.0.4758.80 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in Web Search in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to potentially exploit heap corruption via profile destruction.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Type confusion in V8 in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in Thumbnail Tab Strip in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in Screen Capture in Google Chrome prior to 98.0.4758.80 allowed a remote attacker who had compromised the renderer process and convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in Window Dialogue in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Policy bypass in COOP in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to bypass iframe sandbox via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Inappropriate implementation in Scroll in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to leak cross-origin data via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in Accessibility in Google Chrome prior to 98.0.4758.80 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via user interaction.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in Accessibility in Google Chrome prior to 98.0.4758.80 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via user interaction.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in Extensions in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to potentially exploit heap corruption via user interaction.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Inappropriate implementation in Extensions Platform in Google Chrome prior to 98.0.4758.80 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Inappropriate implementation in Pointer Lock in Google Chrome on Windows prior to 98.0.4758.80 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in Payments in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in Cast in Google Chrome prior to 98.0.4758.80 allowed a remote attacker who convinced a user to engage in specific interactions to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Out of bounds memory access in V8 in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in File Manager in Google Chrome on Chrome OS prior to 98.0.4758.102 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Heap buffer overflow in Tab Groups in Google Chrome prior to 98.0.4758.102 allowed an attacker who convinced a user to install a malicious extension and engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in Webstore API in Google Chrome prior to 98.0.4758.102 allowed an attacker who convinced a user to install a malicious extension and convinced a user to enage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in ANGLE in Google Chrome prior to 98.0.4758.102 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in GPU in Google Chrome prior to 98.0.4758.102 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Integer overflow in Mojo in Google Chrome prior to 98.0.4758.102 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in Animation in Google Chrome prior to 98.0.4758.102 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Inappropriate implementation in Gamepad API in Google Chrome prior to 98.0.4758.102 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Heap buffer overflow in ANGLE in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in Cast UI in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially perform a sandbox escape via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in Omnibox in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via user interactions.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Out of bounds read in ANGLE in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in Cast in Google Chrome prior to 99.0.4844.51 allowed an attacker who convinced a user to install a malicious extension and engage in specific user interaction to potentially exploit heap corruption via a crafted Chrome Extension.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in WebShare in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Type confusion in Blink Layout in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in Media in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Out of bounds memory access in Mojo in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in MediaStream in Google Chrome prior to 99.0.4844.51 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Insufficient policy enforcement in Installer in Google Chrome on Windows prior to 99.0.4844.51 allowed a remote attacker to perform local privilege escalation via a crafted offline installer file.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Heap buffer overflow in Cast UI in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Inappropriate implementation in HTML parser in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to bypass XSS preventions via a crafted HTML page. (Chrome security severity: Medium)


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Inappropriate implementation in Full screen mode in Google Chrome on Android prior to 99.0.4844.51 allowed a remote attacker to hide the contents of the Omnibox (URL bar) via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Inappropriate implementation in Permissions in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to tamper with the contents of the Omnibox (URL bar) via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Inappropriate implementation in Full screen mode in Google Chrome on Android prior to 99.0.4844.51 allowed a remote attacker to hide the contents of the Omnibox (URL bar) via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in Browser Switcher in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via user interaction.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Data leak in Canvas in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in screen sharing to potentially leak cross-origin data via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Inappropriate implementation in Autofill in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Use after free in Chrome OS Shell in Google Chrome on Chrome OS prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in a series of user interaction to potentially exploit heap corruption via user interactions.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Out of bounds memory access in WebXR in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки

Описание

Type confusion in V8 in Google Chrome prior to 99.0.4844.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.4 NonFree:opera-85.0.4341.28-lp154.2.5.1

Ссылки
Уязвимость openSUSE-SU-2022:0110-1