cbcvebase.

Debian Chromium vulnerabilities

2,134 known vulnerabilities affecting debian/chromium.

Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8

Vulnerabilities

Page 102 of 107
CVE-2019-13708P4MEDIUMCVSS 4.3fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-13708 [MEDIUM] CVE-2019-13708: chromium - Inappropriate implementation in navigation in Google Chrome on iOS prior to 78.0... Inappropriate implementation in navigation in Google Chrome on iOS prior to 78.0.3904.70 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. Scope: local bookworm: resolved (fixed in 78.0.3904.87-1) bullseye: resolved (fixed in 78.0.3904.87-1) forky: resolved (fixed in 78.0.3904.87-1) sid: resolved (fixed in 78.0.3904
debian
CVE-2019-13718P4MEDIUMCVSS 4.3fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-13718 [MEDIUM] CVE-2019-13718: chromium - Insufficient data validation in Omnibox in Google Chrome prior to 78.0.3904.70 a... Insufficient data validation in Omnibox in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name. Scope: local bookworm: resolved (fixed in 78.0.3904.87-1) bullseye: resolved (fixed in 78.0.3904.87-1) forky: resolved (fixed in 78.0.3904.87-1) sid: resolved (fixed in 78.0.3904.87-1) tr
debian
CVE-2023-2463P4MEDIUMCVSS 4.3fixed in chromium 113.0.5672.63-1 (bookworm)2023
CVE-2023-2463 [MEDIUM] CVE-2023-2463: chromium - Inappropriate implementation in Full Screen Mode in Google Chrome on Android pri... Inappropriate implementation in Full Screen Mode in Google Chrome on Android prior to 113.0.5672.63 allowed a remote attacker to hide the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 113.0.5672.63-1) bullseye: resolved (fixed in 113.0.5672.63-1~deb11u1) forky: resolved (fix
debian
CVE-2023-2467P4MEDIUMCVSS 4.3fixed in chromium 113.0.5672.63-1 (bookworm)2023
CVE-2023-2467 [MEDIUM] CVE-2023-2467: chromium - Inappropriate implementation in Prompts in Google Chrome on Android prior to 113... Inappropriate implementation in Prompts in Google Chrome on Android prior to 113.0.5672.63 allowed a remote attacker to bypass permissions restrictions via a crafted HTML page. (Chromium security severity: Low) Scope: local bookworm: resolved (fixed in 113.0.5672.63-1) bullseye: resolved (fixed in 113.0.5672.63-1~deb11u1) forky: resolved (fixed in 113.0.5672.63-1)
debian
CVE-2023-2462P4MEDIUMCVSS 4.3fixed in chromium 113.0.5672.63-1 (bookworm)2023
CVE-2023-2462 [MEDIUM] CVE-2023-2462: chromium - Inappropriate implementation in Prompts in Google Chrome prior to 113.0.5672.63 ... Inappropriate implementation in Prompts in Google Chrome prior to 113.0.5672.63 allowed a remote attacker to obfuscate main origin data via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 113.0.5672.63-1) bullseye: resolved (fixed in 113.0.5672.63-1~deb11u1) forky: resolved (fixed in 113.0.5672.63-1) sid: resolved
debian
CVE-2022-1875P4MEDIUMCVSS 4.3fixed in chromium 102.0.5005.61-1 (bookworm)2022
CVE-2022-1875 [MEDIUM] CVE-2022-1875: chromium - Inappropriate implementation in PDF in Google Chrome prior to 102.0.5005.61 allo... Inappropriate implementation in PDF in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to leak cross-origin data via a crafted HTML page. Scope: local bookworm: resolved (fixed in 102.0.5005.61-1) bullseye: resolved (fixed in 102.0.5005.61-1~deb11u1) forky: resolved (fixed in 102.0.5005.61-1) sid: resolved (fixed in 102.0.5005.61-1) trixie: resolved
debian
CVE-2021-37967P4MEDIUMCVSS 4.3fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-37967 [MEDIUM] CVE-2021-37967: chromium - Inappropriate implementation in Background Fetch API in Google Chrome prior to 9... Inappropriate implementation in Background Fetch API in Google Chrome prior to 94.0.4606.54 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. Scope: local bookworm: resolved (fixed in 97.0.4692.71-0.1) bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1) forky: resolved (fixed in 97.0.4692.71-0
debian
CVE-2022-1306P4MEDIUMCVSS 4.3fixed in chromium 100.0.4896.88-1 (bookworm)2022
CVE-2022-1306 [MEDIUM] CVE-2022-1306: chromium - Inappropriate implementation in compositing in Google Chrome prior to 100.0.4896... Inappropriate implementation in compositing in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. Scope: local bookworm: resolved (fixed in 100.0.4896.88-1) bullseye: resolved (fixed in 100.0.4896.88-1~deb11u1) forky: resolved (fixed in 100.0.4896.88-1) sid: resolved (fixed in 100.0
debian
CVE-2022-1307P4MEDIUMCVSS 4.3fixed in chromium 100.0.4896.88-1 (bookworm)2022
CVE-2022-1307 [MEDIUM] CVE-2022-1307: chromium - Inappropriate implementation in full screen in Google Chrome on Android prior to... Inappropriate implementation in full screen in Google Chrome on Android prior to 100.0.4896.88 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. Scope: local bookworm: resolved (fixed in 100.0.4896.88-1) bullseye: resolved (fixed in 100.0.4896.88-1~deb11u1) forky: resolved (fixed in 100.0.4896.88-1) sid: resolved (fix
debian
CVE-2022-4908P4MEDIUMCVSS 4.3fixed in chromium 107.0.5304.68-1 (bookworm)2022
CVE-2022-4908 [MEDIUM] CVE-2022-4908: chromium - Inappropriate implementation in iFrame Sandbox in Google Chrome prior to 107.0.5... Inappropriate implementation in iFrame Sandbox in Google Chrome prior to 107.0.5304.62 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 107.0.5304.68-1) bullseye: resolved (fixed in 107.0.5304.68-1~deb11u1) forky: resolved (fixed in 107.0.5304.68-1) sid: resol
debian
CVE-2023-1234P4MEDIUMCVSS 4.3fixed in chromium 111.0.5563.64-1 (bookworm)2023
CVE-2023-1234 [MEDIUM] CVE-2023-1234: chromium - Inappropriate implementation in Intents in Google Chrome on Android prior to 111... Inappropriate implementation in Intents in Google Chrome on Android prior to 111.0.5563.64 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Low) Scope: local bookworm: resolved (fixed in 111.0.5563.64-1) bullseye: resolved (fixed in 111.0.5563.64-1~deb11u1) forky: resolved (fixed in 111.0.5563.64-1) sid: res
debian
CVE-2020-16033P4MEDIUMCVSS 4.3fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-16033 [MEDIUM] CVE-2020-16033: chromium - Inappropriate implementation in WebUSB in Google Chrome prior to 87.0.4280.66 al... Inappropriate implementation in WebUSB in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to spoof security UI via a crafted HTML page. Scope: local bookworm: resolved (fixed in 87.0.4280.88-0.1) bullseye: resolved (fixed in 87.0.4280.88-0.1) forky: resolved (fixed in 87.0.4280.88-0.1) sid: resolved (fixed in 87.0.4280.88-0.1) trixie: resolved (fixe
debian
CVE-2022-1495P4MEDIUMCVSS 4.3fixed in chromium 101.0.4951.41-1 (bookworm)2022
CVE-2022-1495 [MEDIUM] CVE-2022-1495: chromium - Incorrect security UI in Downloads in Google Chrome on Android prior to 101.0.49... Incorrect security UI in Downloads in Google Chrome on Android prior to 101.0.4951.41 allowed a remote attacker to spoof the APK downloads dialog via a crafted HTML page. Scope: local bookworm: resolved (fixed in 101.0.4951.41-1) bullseye: resolved (fixed in 101.0.4951.41-1~deb11u1) forky: resolved (fixed in 101.0.4951.41-1) sid: resolved (fixed in 101.0.4951.41-1)
debian
CVE-2021-38020P4MEDIUMCVSS 4.3fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-38020 [MEDIUM] CVE-2021-38020: chromium - Insufficient policy enforcement in contacts picker in Google Chrome on Android p... Insufficient policy enforcement in contacts picker in Google Chrome on Android prior to 96.0.4664.45 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. Scope: local bookworm: resolved (fixed in 97.0.4692.71-0.1) bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1) forky: resolved (fixed in 97.0.4692.71-0.1) sid: re
debian
CVE-2019-13674P4MEDIUMCVSS 4.3fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-13674 [MEDIUM] CVE-2019-13674: chromium - IDN spoofing in Omnibox in Google Chrome prior to 77.0.3865.75 allowed a remote ... IDN spoofing in Omnibox in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name. Scope: local bookworm: resolved (fixed in 78.0.3904.87-1) bullseye: resolved (fixed in 78.0.3904.87-1) forky: resolved (fixed in 78.0.3904.87-1) sid: resolved (fixed in 78.0.3904.87-1) trixie: resolved (
debian
CVE-2021-37966P4MEDIUMCVSS 4.3fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-37966 [MEDIUM] CVE-2021-37966: chromium - Inappropriate implementation in Compositing in Google Chrome on Android prior to... Inappropriate implementation in Compositing in Google Chrome on Android prior to 94.0.4606.54 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. Scope: local bookworm: resolved (fixed in 97.0.4692.71-0.1) bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1) forky: resolved (fixed in 97.0.4692.71-0.1) sid: resolved
debian
CVE-2023-4363P4MEDIUMCVSS 4.3fixed in chromium 116.0.5845.96-1~deb12u1 (bookworm)2023
CVE-2023-4363 [MEDIUM] CVE-2023-4363: chromium - Inappropriate implementation in WebShare in Google Chrome on Android prior to 11... Inappropriate implementation in WebShare in Google Chrome on Android prior to 116.0.5845.96 allowed a remote attacker to spoof the contents of a dialog URL via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 116.0.5845.96-1~deb12u1) bullseye: resolved (fixed in 116.0.5845.96-1~deb11u1) forky: resolved (fixed in 11
debian
CVE-2019-13675P4MEDIUMCVSS 4.3fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-13675 [MEDIUM] CVE-2019-13675: chromium - Insufficient data validation in extensions in Google Chrome prior to 77.0.3865.7... Insufficient data validation in extensions in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to disable extensions via a crafted HTML page. Scope: local bookworm: resolved (fixed in 78.0.3904.87-1) bullseye: resolved (fixed in 78.0.3904.87-1) forky: resolved (fixed in 78.0.3904.87-1) sid: resolved (fixed in 78.0.3904.87-1) trixie: resolved (fixed i
debian
CVE-2019-5861P4MEDIUMCVSS 4.3fixed in chromium 76.0.3809.87-1 (bookworm)2019
CVE-2019-5861 [MEDIUM] CVE-2019-5861: chromium - Insufficient data validation in Blink in Google Chrome prior to 76.0.3809.87 all... Insufficient data validation in Blink in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to bypass anti-clickjacking policy via a crafted HTML page. Scope: local bookworm: resolved (fixed in 76.0.3809.87-1) bullseye: resolved (fixed in 76.0.3809.87-1) forky: resolved (fixed in 76.0.3809.87-1) sid: resolved (fixed in 76.0.3809.87-1) trixie: resolved (f
debian
CVE-2023-3736P4MEDIUMCVSS 4.3fixed in chromium 115.0.5790.98-1~deb12u1 (bookworm)2023
CVE-2023-3736 [MEDIUM] CVE-2023-3736: chromium - Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to... Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to 115.0.5790.98 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 115.0.5790.98-1~deb12u1) bullseye: resolved (fixed in 115.0.5790.98-1~deb11u1) forky: resolved (fixed in 115.0.5790.
debian
Debian Chromium vulnerabilities | cvebase