ALT-PU-2021-1667-1
Closed vulnerabilities
BDU:2021-02093
Уязвимость хранилища браузеров Google Chrome и Microsoft Edge, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
BDU:2021-02094
Уязвимость отображения панели «Сеть» браузеров Google Chrome и Microsoft Edge, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
BDU:2021-02095
Уязвимость компонента навигации браузеров Google Chrome и Microsoft Edge, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
BDU:2021-02096
Уязвимость пользовательского интерфейса Network Config UI браузеров Google Chrome и Microsoft Edge, позволяющая нарушителю проводить спуфинг-атаки
BDU:2021-02097
Уязвимость веб-интерфейса для обеспечения поддержки MIDI-устройств Web MIDI браузеров Google Chrome и Microsoft Edge, позволяющая нарушителю оказать воздействие на конфиденциальность защищаемой информации
BDU:2021-02098
Уязвимость программного интерфейса Network API браузеров Google Chrome и Microsoft Edge, позволяющая нарушителю оказать воздействие на конфиденциальность защищаемой информации
BDU:2021-02115
Уязвимость реализации функции автозаполнения Autofill браузеров Google Chrome и Microsoft Edge, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
BDU:2021-02116
Уязвимость реализации функции автозаполнения Autofill браузеров Google Chrome и Microsoft Edge, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
BDU:2021-02118
Уязвимость обработчика PDF-содержимого PDFium браузеров Google Chrome и Microsoft Edge, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2021-02119
Уязвимость обработчика PDF-содержимого PDFium браузеров Google Chrome и Microsoft Edge, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2021-02120
Уязвимость обработчика PDF-содержимого PDFium браузеров Google Chrome и Microsoft Edge, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2021-02121
Уязвимость набора библиотек времени выполнения Mojo браузеров Google Chrome и Microsoft Edge, позволяющая нарушителю выполнить произвольный код
BDU:2021-02162
Уязвимость функции Navigation навигации браузеров Google Chrome и Microsoft Edge, позволяющая нарушителю обойти существующие ограничения безопасности
BDU:2021-02163
Уязвимость компонента IndexedDB браузеров Google Chrome и Microsoft Edge, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
BDU:2021-02164
Уязвимость QR-сканера браузеров Google Chrome и Microsoft Edge, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
BDU:2021-02228
Уязвимость механизма отображения веб-страниц Blink браузера Google Chrome, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации
BDU:2021-02229
Уязвимость механизма отображения веб-страниц Blink браузера Google Chrome, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации
BDU:2021-02230
Уязвимость компонента Extensions браузера Google Chrome, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации
BDU:2021-02231
Уязвимость браузера Google Chrome, связанная с использованием памяти после ее освобождения, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации
BDU:2021-03663
Уязвимость движка Blink браузера Google Chrome, связанная с использованием памяти после её освобождения, позволяющая нарушителю получить доступ к конфиденциальной информации или вызвать отказ в обслуживании
BDU:2021-03664
Уязвимость движка V8 браузера Google Chrome, связанная с выходом операции за границы буфера в памяти, позволяющая нарушителю получить доступ к конфиденциальной информации или вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2021-21201
Use after free in permissions in Google Chrome prior to 90.0.4430.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
- https://chromereleases.googleblog.com/2021/04/stable-channel-update-for-desktop_14.html
- https://chromereleases.googleblog.com/2021/04/stable-channel-update-for-desktop_14.html
- https://crbug.com/1025683
- https://crbug.com/1025683
- FEDORA-2021-ff893e12c5
- FEDORA-2021-ff893e12c5
- FEDORA-2021-35d2bb4627
- FEDORA-2021-35d2bb4627
- FEDORA-2021-c3754414e7
- FEDORA-2021-c3754414e7
- GLSA-202104-08
- GLSA-202104-08
- DSA-4906
- DSA-4906
Modified: 2024-11-21
CVE-2021-21202
Use after free in extensions in Google Chrome prior to 90.0.4430.72 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.
- https://chromereleases.googleblog.com/2021/04/stable-channel-update-for-desktop_14.html
- https://chromereleases.googleblog.com/2021/04/stable-channel-update-for-desktop_14.html
- https://crbug.com/1188889
- https://crbug.com/1188889
- FEDORA-2021-ff893e12c5
- FEDORA-2021-ff893e12c5
- FEDORA-2021-35d2bb4627
- FEDORA-2021-35d2bb4627
- FEDORA-2021-c3754414e7
- FEDORA-2021-c3754414e7
- GLSA-202104-08
- GLSA-202104-08
- DSA-4906
- DSA-4906
Modified: 2024-11-21
CVE-2021-21203
Use after free in Blink in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- https://chromereleases.googleblog.com/2021/04/stable-channel-update-for-desktop_14.html
- https://chromereleases.googleblog.com/2021/04/stable-channel-update-for-desktop_14.html
- https://crbug.com/1192054
- https://crbug.com/1192054
- FEDORA-2021-ff893e12c5
- FEDORA-2021-ff893e12c5
- FEDORA-2021-35d2bb4627
- FEDORA-2021-35d2bb4627
- FEDORA-2021-c3754414e7
- FEDORA-2021-c3754414e7
- GLSA-202104-08
- GLSA-202104-08
- DSA-4906
- DSA-4906
Modified: 2024-11-21
CVE-2021-21204
Use after free in Blink in Google Chrome on OS X prior to 90.0.4430.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- https://chromereleases.googleblog.com/2021/04/stable-channel-update-for-desktop_14.html
- https://chromereleases.googleblog.com/2021/04/stable-channel-update-for-desktop_14.html
- https://crbug.com/1189926
- https://crbug.com/1189926
- FEDORA-2021-ff893e12c5
- FEDORA-2021-ff893e12c5
- FEDORA-2021-35d2bb4627
- FEDORA-2021-35d2bb4627
- FEDORA-2021-c3754414e7
- FEDORA-2021-c3754414e7
- GLSA-202104-08
- GLSA-202104-08
- DSA-4906
- DSA-4906
Modified: 2024-11-21
CVE-2021-21205
Insufficient policy enforcement in navigation in Google Chrome on iOS prior to 90.0.4430.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
- https://chromereleases.googleblog.com/2021/04/stable-channel-update-for-desktop_14.html
- https://chromereleases.googleblog.com/2021/04/stable-channel-update-for-desktop_14.html
- https://crbug.com/1165654
- https://crbug.com/1165654
- FEDORA-2021-ff893e12c5
- FEDORA-2021-ff893e12c5
- FEDORA-2021-35d2bb4627
- FEDORA-2021-35d2bb4627
- FEDORA-2021-c3754414e7
- FEDORA-2021-c3754414e7
- GLSA-202104-08
- GLSA-202104-08
- DSA-4906
- DSA-4906
Modified: 2025-02-05
CVE-2021-21206
Use after free in Blink in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- https://chromereleases.googleblog.com/2021/04/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2021/04/stable-channel-update-for-desktop.html
- https://crbug.com/1196781
- https://crbug.com/1196781
- FEDORA-2021-ff893e12c5
- FEDORA-2021-ff893e12c5
- FEDORA-2021-35d2bb4627
- FEDORA-2021-35d2bb4627
- FEDORA-2021-c3754414e7
- FEDORA-2021-c3754414e7
- GLSA-202104-08
- GLSA-202104-08
Modified: 2024-11-21
CVE-2021-21207
Use after free in IndexedDB in Google Chrome prior to 90.0.4430.72 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.
- https://chromereleases.googleblog.com/2021/04/stable-channel-update-for-desktop_14.html
- https://chromereleases.googleblog.com/2021/04/stable-channel-update-for-desktop_14.html
- https://crbug.com/1185732
- https://crbug.com/1185732
- FEDORA-2021-ff893e12c5
- FEDORA-2021-ff893e12c5
- FEDORA-2021-35d2bb4627
- FEDORA-2021-35d2bb4627
- FEDORA-2021-c3754414e7
- FEDORA-2021-c3754414e7
- GLSA-202104-08
- GLSA-202104-08
- DSA-4906
- DSA-4906
Modified: 2024-11-21
CVE-2021-21208
Insufficient data validation in QR scanner in Google Chrome on iOS prior to 90.0.4430.72 allowed an attacker displaying a QR code to perform domain spoofing via a crafted QR code.
- https://chromereleases.googleblog.com/2021/04/stable-channel-update-for-desktop_14.html
- https://chromereleases.googleblog.com/2021/04/stable-channel-update-for-desktop_14.html
- https://crbug.com/1039539
- https://crbug.com/1039539
- FEDORA-2021-ff893e12c5
- FEDORA-2021-ff893e12c5
- FEDORA-2021-35d2bb4627
- FEDORA-2021-35d2bb4627
- FEDORA-2021-c3754414e7
- FEDORA-2021-c3754414e7
- GLSA-202104-08
- GLSA-202104-08
- DSA-4906
- DSA-4906
Modified: 2024-11-21
CVE-2021-21209
Inappropriate implementation in storage in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
- https://chromereleases.googleblog.com/2021/04/stable-channel-update-for-desktop_14.html
- https://chromereleases.googleblog.com/2021/04/stable-channel-update-for-desktop_14.html
- https://crbug.com/1143526
- https://crbug.com/1143526
- FEDORA-2021-ff893e12c5
- FEDORA-2021-ff893e12c5
- FEDORA-2021-35d2bb4627
- FEDORA-2021-35d2bb4627
- FEDORA-2021-c3754414e7
- FEDORA-2021-c3754414e7
- GLSA-202104-08
- GLSA-202104-08
- DSA-4906
- DSA-4906
Modified: 2024-11-21
CVE-2021-21210
Inappropriate implementation in Network in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to potentially access local UDP ports via a crafted HTML page.
- https://chromereleases.googleblog.com/2021/04/stable-channel-update-for-desktop_14.html
- https://chromereleases.googleblog.com/2021/04/stable-channel-update-for-desktop_14.html
- https://crbug.com/1184562
- https://crbug.com/1184562
- FEDORA-2021-ff893e12c5
- FEDORA-2021-ff893e12c5
- FEDORA-2021-35d2bb4627
- FEDORA-2021-35d2bb4627
- FEDORA-2021-c3754414e7
- FEDORA-2021-c3754414e7
- GLSA-202104-08
- GLSA-202104-08
- DSA-4906
- DSA-4906
Modified: 2024-11-21
CVE-2021-21211
Inappropriate implementation in Navigation in Google Chrome on iOS prior to 90.0.4430.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
- https://chromereleases.googleblog.com/2021/04/stable-channel-update-for-desktop_14.html
- https://chromereleases.googleblog.com/2021/04/stable-channel-update-for-desktop_14.html
- https://crbug.com/1103119
- https://crbug.com/1103119
- FEDORA-2021-ff893e12c5
- FEDORA-2021-ff893e12c5
- FEDORA-2021-35d2bb4627
- FEDORA-2021-35d2bb4627
- FEDORA-2021-c3754414e7
- FEDORA-2021-c3754414e7
- GLSA-202104-08
- GLSA-202104-08
- DSA-4906
- DSA-4906
Modified: 2024-11-21
CVE-2021-21212
Incorrect security UI in Network Config UI in Google Chrome on ChromeOS prior to 90.0.4430.72 allowed a remote attacker to potentially compromise WiFi connection security via a malicious WAP.
- https://chromereleases.googleblog.com/2021/04/stable-channel-update-for-desktop_14.html
- https://chromereleases.googleblog.com/2021/04/stable-channel-update-for-desktop_14.html
- https://crbug.com/1145024
- https://crbug.com/1145024
- FEDORA-2021-ff893e12c5
- FEDORA-2021-ff893e12c5
- FEDORA-2021-35d2bb4627
- FEDORA-2021-35d2bb4627
- FEDORA-2021-c3754414e7
- FEDORA-2021-c3754414e7
- GLSA-202104-08
- GLSA-202104-08
- DSA-4906
- DSA-4906
Modified: 2024-11-21
CVE-2021-21213
Use after free in WebMIDI in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- https://chromereleases.googleblog.com/2021/04/stable-channel-update-for-desktop_14.html
- https://chromereleases.googleblog.com/2021/04/stable-channel-update-for-desktop_14.html
- https://crbug.com/1161806
- https://crbug.com/1161806
- FEDORA-2021-ff893e12c5
- FEDORA-2021-ff893e12c5
- FEDORA-2021-35d2bb4627
- FEDORA-2021-35d2bb4627
- FEDORA-2021-c3754414e7
- FEDORA-2021-c3754414e7
- GLSA-202104-08
- GLSA-202104-08
- DSA-4906
- DSA-4906
Modified: 2024-11-21
CVE-2021-21214
Use after free in Network API in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to potentially exploit heap corruption via a crafted Chrome Extension.
- https://chromereleases.googleblog.com/2021/04/stable-channel-update-for-desktop_14.html
- https://chromereleases.googleblog.com/2021/04/stable-channel-update-for-desktop_14.html
- https://crbug.com/1170148
- https://crbug.com/1170148
- FEDORA-2021-ff893e12c5
- FEDORA-2021-ff893e12c5
- FEDORA-2021-35d2bb4627
- FEDORA-2021-35d2bb4627
- FEDORA-2021-c3754414e7
- FEDORA-2021-c3754414e7
- GLSA-202104-08
- GLSA-202104-08
- DSA-4906
- DSA-4906
Modified: 2024-11-21
CVE-2021-21215
Inappropriate implementation in Autofill in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to spoof security UI via a crafted HTML page.
- https://chromereleases.googleblog.com/2021/04/stable-channel-update-for-desktop_14.html
- https://chromereleases.googleblog.com/2021/04/stable-channel-update-for-desktop_14.html
- https://crbug.com/1172533
- https://crbug.com/1172533
- FEDORA-2021-ff893e12c5
- FEDORA-2021-ff893e12c5
- FEDORA-2021-35d2bb4627
- FEDORA-2021-35d2bb4627
- FEDORA-2021-c3754414e7
- FEDORA-2021-c3754414e7
- GLSA-202104-08
- GLSA-202104-08
- DSA-4906
- DSA-4906
Modified: 2024-11-21
CVE-2021-21216
Inappropriate implementation in Autofill in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to spoof security UI via a crafted HTML page.
- https://chromereleases.googleblog.com/2021/04/stable-channel-update-for-desktop_14.html
- https://chromereleases.googleblog.com/2021/04/stable-channel-update-for-desktop_14.html
- https://crbug.com/1173297
- https://crbug.com/1173297
- FEDORA-2021-ff893e12c5
- FEDORA-2021-ff893e12c5
- FEDORA-2021-35d2bb4627
- FEDORA-2021-35d2bb4627
- FEDORA-2021-c3754414e7
- FEDORA-2021-c3754414e7
- GLSA-202104-08
- GLSA-202104-08
- DSA-4906
- DSA-4906
Modified: 2024-11-21
CVE-2021-21217
Uninitialized data in PDFium in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted PDF file.
- https://chromereleases.googleblog.com/2021/04/stable-channel-update-for-desktop_14.html
- https://chromereleases.googleblog.com/2021/04/stable-channel-update-for-desktop_14.html
- https://crbug.com/1166462
- https://crbug.com/1166462
- FEDORA-2021-ff893e12c5
- FEDORA-2021-ff893e12c5
- FEDORA-2021-35d2bb4627
- FEDORA-2021-35d2bb4627
- FEDORA-2021-c3754414e7
- FEDORA-2021-c3754414e7
- GLSA-202104-08
- GLSA-202104-08
- DSA-4906
- DSA-4906
Modified: 2024-11-21
CVE-2021-21218
Uninitialized data in PDFium in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted PDF file.
- https://chromereleases.googleblog.com/2021/04/stable-channel-update-for-desktop_14.html
- https://chromereleases.googleblog.com/2021/04/stable-channel-update-for-desktop_14.html
- https://crbug.com/1166478
- https://crbug.com/1166478
- FEDORA-2021-ff893e12c5
- FEDORA-2021-ff893e12c5
- FEDORA-2021-35d2bb4627
- FEDORA-2021-35d2bb4627
- FEDORA-2021-c3754414e7
- FEDORA-2021-c3754414e7
- GLSA-202104-08
- GLSA-202104-08
- DSA-4906
- DSA-4906
Modified: 2024-11-21
CVE-2021-21219
Uninitialized data in PDFium in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted PDF file.
- https://chromereleases.googleblog.com/2021/04/stable-channel-update-for-desktop_14.html
- https://chromereleases.googleblog.com/2021/04/stable-channel-update-for-desktop_14.html
- https://crbug.com/1166972
- https://crbug.com/1166972
- FEDORA-2021-ff893e12c5
- FEDORA-2021-ff893e12c5
- FEDORA-2021-35d2bb4627
- FEDORA-2021-35d2bb4627
- FEDORA-2021-c3754414e7
- FEDORA-2021-c3754414e7
- GLSA-202104-08
- GLSA-202104-08
- DSA-4906
- DSA-4906
Modified: 2025-02-05
CVE-2021-21220
Insufficient validation of untrusted input in V8 in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- http://packetstormsecurity.com/files/162437/Google-Chrome-XOR-Typer-Out-Of-Bounds-Access-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/162437/Google-Chrome-XOR-Typer-Out-Of-Bounds-Access-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/176210/Chrome-V8-JIT-XOR-Arbitrary-Code-Execution.html
- http://packetstormsecurity.com/files/176210/Chrome-V8-JIT-XOR-Arbitrary-Code-Execution.html
- https://chromereleases.googleblog.com/2021/04/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2021/04/stable-channel-update-for-desktop.html
- https://crbug.com/1196683
- https://crbug.com/1196683
- FEDORA-2021-ff893e12c5
- FEDORA-2021-ff893e12c5
- FEDORA-2021-35d2bb4627
- FEDORA-2021-35d2bb4627
- FEDORA-2021-c3754414e7
- FEDORA-2021-c3754414e7
- GLSA-202104-08
- GLSA-202104-08
Modified: 2024-11-21
CVE-2021-21221
Insufficient validation of untrusted input in Mojo in Google Chrome prior to 90.0.4430.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page.
- https://chromereleases.googleblog.com/2021/04/stable-channel-update-for-desktop_14.html
- https://chromereleases.googleblog.com/2021/04/stable-channel-update-for-desktop_14.html
- https://crbug.com/1195333
- https://crbug.com/1195333
- FEDORA-2021-ff893e12c5
- FEDORA-2021-ff893e12c5
- FEDORA-2021-35d2bb4627
- FEDORA-2021-35d2bb4627
- FEDORA-2021-c3754414e7
- FEDORA-2021-c3754414e7
- GLSA-202104-08
- GLSA-202104-08
- DSA-4906
- DSA-4906