ALT-PU-2021-1204-1
Closed vulnerabilities
BDU:2021-00913
Уязвимость графической библиотеки Skia браузера Google Chrome, позволяющая нарушителю проводить спуфинг-атаки
BDU:2021-01022
Уязвимость компонента Fonts браузера Google Chrome, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации
BDU:2021-01043
Уязвимость компонента Extensions браузера Google Chrome, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации
BDU:2021-01048
Уязвимость компонента Tab Groups браузера Google Chrome, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации
BDU:2021-01049
Уязвимость компонента Payments браузера Google Chrome, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации
BDU:2021-01065
Уязвимость компонента Navigation браузера Google Chrome, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации
Modified: 2024-11-21
CVE-2021-21142
Use after free in Payments in Google Chrome on Mac prior to 88.0.4324.146 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
- https://chromereleases.googleblog.com/2021/02/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2021/02/stable-channel-update-for-desktop.html
- https://crbug.com/1169317
- https://crbug.com/1169317
- FEDORA-2021-7fb30b9381
- FEDORA-2021-7fb30b9381
- FEDORA-2021-05afa65d39
- FEDORA-2021-05afa65d39
- GLSA-202104-08
- GLSA-202104-08
Modified: 2024-11-21
CVE-2021-21143
Heap buffer overflow in Extensions in Google Chrome prior to 88.0.4324.146 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension.
- https://chromereleases.googleblog.com/2021/02/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2021/02/stable-channel-update-for-desktop.html
- https://crbug.com/1163504
- https://crbug.com/1163504
- FEDORA-2021-7fb30b9381
- FEDORA-2021-7fb30b9381
- FEDORA-2021-05afa65d39
- FEDORA-2021-05afa65d39
- GLSA-202104-08
- GLSA-202104-08
Modified: 2024-11-21
CVE-2021-21144
Heap buffer overflow in Tab Groups in Google Chrome prior to 88.0.4324.146 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension.
- https://chromereleases.googleblog.com/2021/02/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2021/02/stable-channel-update-for-desktop.html
- https://crbug.com/1163845
- https://crbug.com/1163845
- FEDORA-2021-7fb30b9381
- FEDORA-2021-7fb30b9381
- FEDORA-2021-05afa65d39
- FEDORA-2021-05afa65d39
- GLSA-202104-08
- GLSA-202104-08
Modified: 2024-11-21
CVE-2021-21145
Use after free in Fonts in Google Chrome prior to 88.0.4324.146 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- https://chromereleases.googleblog.com/2021/02/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2021/02/stable-channel-update-for-desktop.html
- https://crbug.com/1154965
- https://crbug.com/1154965
- FEDORA-2021-7fb30b9381
- FEDORA-2021-7fb30b9381
- FEDORA-2021-05afa65d39
- FEDORA-2021-05afa65d39
- GLSA-202104-08
- GLSA-202104-08
Modified: 2024-11-21
CVE-2021-21146
Use after free in Navigation in Google Chrome prior to 88.0.4324.146 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
- https://chromereleases.googleblog.com/2021/02/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2021/02/stable-channel-update-for-desktop.html
- https://crbug.com/1161705
- https://crbug.com/1161705
- FEDORA-2021-7fb30b9381
- FEDORA-2021-7fb30b9381
- FEDORA-2021-05afa65d39
- FEDORA-2021-05afa65d39
- GLSA-202104-08
- GLSA-202104-08
Modified: 2024-11-21
CVE-2021-21147
Inappropriate implementation in Skia in Google Chrome prior to 88.0.4324.146 allowed a local attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
- https://chromereleases.googleblog.com/2021/02/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2021/02/stable-channel-update-for-desktop.html
- https://crbug.com/1162942
- https://crbug.com/1162942
- FEDORA-2021-7fb30b9381
- FEDORA-2021-7fb30b9381
- FEDORA-2021-05afa65d39
- FEDORA-2021-05afa65d39
- GLSA-202104-08
- GLSA-202104-08