Debian Chromium vulnerabilities
2,134 known vulnerabilities affecting debian/chromium.
Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8
Vulnerabilities
Page 102 of 107
CVE-2019-13708P4MEDIUMCVSS 4.3fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-13708 [MEDIUM] CVE-2019-13708: chromium - Inappropriate implementation in navigation in Google Chrome on iOS prior to 78.0...
Inappropriate implementation in navigation in Google Chrome on iOS prior to 78.0.3904.70 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 78.0.3904.87-1)
bullseye: resolved (fixed in 78.0.3904.87-1)
forky: resolved (fixed in 78.0.3904.87-1)
sid: resolved (fixed in 78.0.3904
debian
CVE-2019-13718P4MEDIUMCVSS 4.3fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-13718 [MEDIUM] CVE-2019-13718: chromium - Insufficient data validation in Omnibox in Google Chrome prior to 78.0.3904.70 a...
Insufficient data validation in Omnibox in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
Scope: local
bookworm: resolved (fixed in 78.0.3904.87-1)
bullseye: resolved (fixed in 78.0.3904.87-1)
forky: resolved (fixed in 78.0.3904.87-1)
sid: resolved (fixed in 78.0.3904.87-1)
tr
debian
CVE-2023-2463P4MEDIUMCVSS 4.3fixed in chromium 113.0.5672.63-1 (bookworm)2023
CVE-2023-2463 [MEDIUM] CVE-2023-2463: chromium - Inappropriate implementation in Full Screen Mode in Google Chrome on Android pri...
Inappropriate implementation in Full Screen Mode in Google Chrome on Android prior to 113.0.5672.63 allowed a remote attacker to hide the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 113.0.5672.63-1)
bullseye: resolved (fixed in 113.0.5672.63-1~deb11u1)
forky: resolved (fix
debian
CVE-2023-2467P4MEDIUMCVSS 4.3fixed in chromium 113.0.5672.63-1 (bookworm)2023
CVE-2023-2467 [MEDIUM] CVE-2023-2467: chromium - Inappropriate implementation in Prompts in Google Chrome on Android prior to 113...
Inappropriate implementation in Prompts in Google Chrome on Android prior to 113.0.5672.63 allowed a remote attacker to bypass permissions restrictions via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 113.0.5672.63-1)
bullseye: resolved (fixed in 113.0.5672.63-1~deb11u1)
forky: resolved (fixed in 113.0.5672.63-1)
debian
CVE-2023-2462P4MEDIUMCVSS 4.3fixed in chromium 113.0.5672.63-1 (bookworm)2023
CVE-2023-2462 [MEDIUM] CVE-2023-2462: chromium - Inappropriate implementation in Prompts in Google Chrome prior to 113.0.5672.63 ...
Inappropriate implementation in Prompts in Google Chrome prior to 113.0.5672.63 allowed a remote attacker to obfuscate main origin data via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 113.0.5672.63-1)
bullseye: resolved (fixed in 113.0.5672.63-1~deb11u1)
forky: resolved (fixed in 113.0.5672.63-1)
sid: resolved
debian
CVE-2022-1875P4MEDIUMCVSS 4.3fixed in chromium 102.0.5005.61-1 (bookworm)2022
CVE-2022-1875 [MEDIUM] CVE-2022-1875: chromium - Inappropriate implementation in PDF in Google Chrome prior to 102.0.5005.61 allo...
Inappropriate implementation in PDF in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 102.0.5005.61-1)
bullseye: resolved (fixed in 102.0.5005.61-1~deb11u1)
forky: resolved (fixed in 102.0.5005.61-1)
sid: resolved (fixed in 102.0.5005.61-1)
trixie: resolved
debian
CVE-2021-37967P4MEDIUMCVSS 4.3fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-37967 [MEDIUM] CVE-2021-37967: chromium - Inappropriate implementation in Background Fetch API in Google Chrome prior to 9...
Inappropriate implementation in Background Fetch API in Google Chrome prior to 94.0.4606.54 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 97.0.4692.71-0.1)
bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1)
forky: resolved (fixed in 97.0.4692.71-0
debian
CVE-2022-1306P4MEDIUMCVSS 4.3fixed in chromium 100.0.4896.88-1 (bookworm)2022
CVE-2022-1306 [MEDIUM] CVE-2022-1306: chromium - Inappropriate implementation in compositing in Google Chrome prior to 100.0.4896...
Inappropriate implementation in compositing in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 100.0.4896.88-1)
bullseye: resolved (fixed in 100.0.4896.88-1~deb11u1)
forky: resolved (fixed in 100.0.4896.88-1)
sid: resolved (fixed in 100.0
debian
CVE-2022-1307P4MEDIUMCVSS 4.3fixed in chromium 100.0.4896.88-1 (bookworm)2022
CVE-2022-1307 [MEDIUM] CVE-2022-1307: chromium - Inappropriate implementation in full screen in Google Chrome on Android prior to...
Inappropriate implementation in full screen in Google Chrome on Android prior to 100.0.4896.88 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 100.0.4896.88-1)
bullseye: resolved (fixed in 100.0.4896.88-1~deb11u1)
forky: resolved (fixed in 100.0.4896.88-1)
sid: resolved (fix
debian
CVE-2022-4908P4MEDIUMCVSS 4.3fixed in chromium 107.0.5304.68-1 (bookworm)2022
CVE-2022-4908 [MEDIUM] CVE-2022-4908: chromium - Inappropriate implementation in iFrame Sandbox in Google Chrome prior to 107.0.5...
Inappropriate implementation in iFrame Sandbox in Google Chrome prior to 107.0.5304.62 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 107.0.5304.68-1)
bullseye: resolved (fixed in 107.0.5304.68-1~deb11u1)
forky: resolved (fixed in 107.0.5304.68-1)
sid: resol
debian
CVE-2023-1234P4MEDIUMCVSS 4.3fixed in chromium 111.0.5563.64-1 (bookworm)2023
CVE-2023-1234 [MEDIUM] CVE-2023-1234: chromium - Inappropriate implementation in Intents in Google Chrome on Android prior to 111...
Inappropriate implementation in Intents in Google Chrome on Android prior to 111.0.5563.64 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 111.0.5563.64-1)
bullseye: resolved (fixed in 111.0.5563.64-1~deb11u1)
forky: resolved (fixed in 111.0.5563.64-1)
sid: res
debian
CVE-2020-16033P4MEDIUMCVSS 4.3fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-16033 [MEDIUM] CVE-2020-16033: chromium - Inappropriate implementation in WebUSB in Google Chrome prior to 87.0.4280.66 al...
Inappropriate implementation in WebUSB in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to spoof security UI via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (fixed in 87.0.4280.88-0.1)
trixie: resolved (fixe
debian
CVE-2022-1495P4MEDIUMCVSS 4.3fixed in chromium 101.0.4951.41-1 (bookworm)2022
CVE-2022-1495 [MEDIUM] CVE-2022-1495: chromium - Incorrect security UI in Downloads in Google Chrome on Android prior to 101.0.49...
Incorrect security UI in Downloads in Google Chrome on Android prior to 101.0.4951.41 allowed a remote attacker to spoof the APK downloads dialog via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 101.0.4951.41-1)
bullseye: resolved (fixed in 101.0.4951.41-1~deb11u1)
forky: resolved (fixed in 101.0.4951.41-1)
sid: resolved (fixed in 101.0.4951.41-1)
debian
CVE-2021-38020P4MEDIUMCVSS 4.3fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-38020 [MEDIUM] CVE-2021-38020: chromium - Insufficient policy enforcement in contacts picker in Google Chrome on Android p...
Insufficient policy enforcement in contacts picker in Google Chrome on Android prior to 96.0.4664.45 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 97.0.4692.71-0.1)
bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1)
forky: resolved (fixed in 97.0.4692.71-0.1)
sid: re
debian
CVE-2019-13674P4MEDIUMCVSS 4.3fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-13674 [MEDIUM] CVE-2019-13674: chromium - IDN spoofing in Omnibox in Google Chrome prior to 77.0.3865.75 allowed a remote ...
IDN spoofing in Omnibox in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
Scope: local
bookworm: resolved (fixed in 78.0.3904.87-1)
bullseye: resolved (fixed in 78.0.3904.87-1)
forky: resolved (fixed in 78.0.3904.87-1)
sid: resolved (fixed in 78.0.3904.87-1)
trixie: resolved (
debian
CVE-2021-37966P4MEDIUMCVSS 4.3fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-37966 [MEDIUM] CVE-2021-37966: chromium - Inappropriate implementation in Compositing in Google Chrome on Android prior to...
Inappropriate implementation in Compositing in Google Chrome on Android prior to 94.0.4606.54 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 97.0.4692.71-0.1)
bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1)
forky: resolved (fixed in 97.0.4692.71-0.1)
sid: resolved
debian
CVE-2023-4363P4MEDIUMCVSS 4.3fixed in chromium 116.0.5845.96-1~deb12u1 (bookworm)2023
CVE-2023-4363 [MEDIUM] CVE-2023-4363: chromium - Inappropriate implementation in WebShare in Google Chrome on Android prior to 11...
Inappropriate implementation in WebShare in Google Chrome on Android prior to 116.0.5845.96 allowed a remote attacker to spoof the contents of a dialog URL via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 116.0.5845.96-1~deb12u1)
bullseye: resolved (fixed in 116.0.5845.96-1~deb11u1)
forky: resolved (fixed in 11
debian
CVE-2019-13675P4MEDIUMCVSS 4.3fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-13675 [MEDIUM] CVE-2019-13675: chromium - Insufficient data validation in extensions in Google Chrome prior to 77.0.3865.7...
Insufficient data validation in extensions in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to disable extensions via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 78.0.3904.87-1)
bullseye: resolved (fixed in 78.0.3904.87-1)
forky: resolved (fixed in 78.0.3904.87-1)
sid: resolved (fixed in 78.0.3904.87-1)
trixie: resolved (fixed i
debian
CVE-2019-5861P4MEDIUMCVSS 4.3fixed in chromium 76.0.3809.87-1 (bookworm)2019
CVE-2019-5861 [MEDIUM] CVE-2019-5861: chromium - Insufficient data validation in Blink in Google Chrome prior to 76.0.3809.87 all...
Insufficient data validation in Blink in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to bypass anti-clickjacking policy via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 76.0.3809.87-1)
bullseye: resolved (fixed in 76.0.3809.87-1)
forky: resolved (fixed in 76.0.3809.87-1)
sid: resolved (fixed in 76.0.3809.87-1)
trixie: resolved (f
debian
CVE-2023-3736P4MEDIUMCVSS 4.3fixed in chromium 115.0.5790.98-1~deb12u1 (bookworm)2023
CVE-2023-3736 [MEDIUM] CVE-2023-3736: chromium - Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to...
Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to 115.0.5790.98 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 115.0.5790.98-1~deb12u1)
bullseye: resolved (fixed in 115.0.5790.98-1~deb11u1)
forky: resolved (fixed in 115.0.5790.
debian