cbcvebase.

Debian Chromium vulnerabilities

2,134 known vulnerabilities affecting debian/chromium.

Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8

Vulnerabilities

Page 103 of 107
CVE-2019-13659P4MEDIUMCVSS 4.3fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-13659 [MEDIUM] CVE-2019-13659: chromium - IDN spoofing in Omnibox in Google Chrome prior to 77.0.3865.75 allowed a remote ... IDN spoofing in Omnibox in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name. Scope: local bookworm: resolved (fixed in 78.0.3904.87-1) bullseye: resolved (fixed in 78.0.3904.87-1) forky: resolved (fixed in 78.0.3904.87-1) sid: resolved (fixed in 78.0.3904.87-1) trixie: resolved (
debian
CVE-2019-13663P4MEDIUMCVSS 4.3fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-13663 [MEDIUM] CVE-2019-13663: chromium - IDN spoofing in Omnibox in Google Chrome prior to 77.0.3865.75 allowed a remote ... IDN spoofing in Omnibox in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name. Scope: local bookworm: resolved (fixed in 78.0.3904.87-1) bullseye: resolved (fixed in 78.0.3904.87-1) forky: resolved (fixed in 78.0.3904.87-1) sid: resolved (fixed in 78.0.3904.87-1) trixie: resolved (
debian
CVE-2019-13681P4MEDIUMCVSS 4.3fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-13681 [MEDIUM] CVE-2019-13681: chromium - Insufficient data validation in downloads in Google Chrome prior to 77.0.3865.75... Insufficient data validation in downloads in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to bypass download restrictions via a crafted HTML page. Scope: local bookworm: resolved (fixed in 78.0.3904.87-1) bullseye: resolved (fixed in 78.0.3904.87-1) forky: resolved (fixed in 78.0.3904.87-1) sid: resolved (fixed in 78.0.3904.87-1) trixie: resolved
debian
CVE-2022-3447P4MEDIUMCVSS 4.3fixed in chromium 106.0.5249.119-1 (bookworm)2022
CVE-2022-3447 [MEDIUM] CVE-2022-3447: chromium - Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to... Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to 106.0.5249.119 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 106.0.5249.119-1) bullseye: resolved (fixed in 106.0.5249.119-1~deb11u1) forky: resolved (fixed
debian
CVE-2019-5875P4MEDIUMCVSS 4.3fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-5875 [MEDIUM] CVE-2019-5875: chromium - Insufficient data validation in downloads in Google Chrome prior to 77.0.3865.75... Insufficient data validation in downloads in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. Scope: local bookworm: resolved (fixed in 78.0.3904.87-1) bullseye: resolved (fixed in 78.0.3904.87-1) forky: resolved (fixed in 78.0.3904.87-1) sid: resolved (fixed in 78.0.3904.87-1) tri
debian
CVE-2019-13691P4MEDIUMCVSS 4.3fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-13691 [MEDIUM] CVE-2019-13691: chromium - Insufficient validation of untrusted input in navigation in Google Chrome prior ... Insufficient validation of untrusted input in navigation in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. Scope: local bookworm: resolved (fixed in 78.0.3904.87-1) bullseye: resolved (fixed in 78.0.3904.87-1) forky: resolved (fixed in 78.0.3904.87-1) sid: resolved (fixed in 78
debian
CVE-2023-0141P4MEDIUMCVSS 4.3fixed in chromium 109.0.5414.74-1 (bookworm)2023
CVE-2023-0141 [MEDIUM] CVE-2023-0141: chromium - Insufficient policy enforcement in CORS in Google Chrome prior to 109.0.5414.74 ... Insufficient policy enforcement in CORS in Google Chrome prior to 109.0.5414.74 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low) Scope: local bookworm: resolved (fixed in 109.0.5414.74-1) bullseye: resolved (fixed in 109.0.5414.74-2~deb11u1) forky: resolved (fixed in 109.0.5414.74-1) sid: resolved (fixed
debian
CVE-2023-3737P4MEDIUMCVSS 4.3fixed in chromium 115.0.5790.98-1~deb12u1 (bookworm)2023
CVE-2023-3737 [MEDIUM] CVE-2023-3737: chromium - Inappropriate implementation in Notifications in Google Chrome prior to 115.0.57... Inappropriate implementation in Notifications in Google Chrome prior to 115.0.5790.98 allowed a remote attacker to spoof the contents of media notifications via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 115.0.5790.98-1~deb12u1) bullseye: resolved (fixed in 115.0.5790.98-1~deb11u1) forky: resolved (fixed in 1
debian
CVE-2022-4182P4MEDIUMCVSS 4.3fixed in chromium 108.0.5359.71-1 (bookworm)2022
CVE-2022-4182 [MEDIUM] CVE-2022-4182: chromium - Inappropriate implementation in Fenced Frames in Google Chrome prior to 108.0.53... Inappropriate implementation in Fenced Frames in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to bypass fenced frame restrictions via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 108.0.5359.71-1) bullseye: resolved (fixed in 108.0.5359.71-2~deb11u1) forky: resolved (fixed in 108.0.5359.71-1) s
debian
CVE-2022-2611P4MEDIUMCVSS 4.3fixed in chromium 104.0.5112.79-1 (bookworm)2022
CVE-2022-2611 [MEDIUM] CVE-2022-2611: chromium - Inappropriate implementation in Fullscreen API in Google Chrome on Android prior... Inappropriate implementation in Fullscreen API in Google Chrome on Android prior to 104.0.5112.79 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. Scope: local bookworm: resolved (fixed in 104.0.5112.79-1) bullseye: resolved (fixed in 104.0.5112.79-1~deb11u1) forky: resolved (fixed in 104.0.5112.79-1) sid: resolved (
debian
CVE-2020-6504P4MEDIUMCVSS 4.3fixed in chromium 74.0.3729.108-1 (bookworm)2020
CVE-2020-6504 [MEDIUM] CVE-2020-6504: chromium - Insufficient policy enforcement in notifications in Google Chrome prior to 74.0.... Insufficient policy enforcement in notifications in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to bypass notification restrictions via a crafted HTML page. Scope: local bookworm: resolved (fixed in 74.0.3729.108-1) bullseye: resolved (fixed in 74.0.3729.108-1) forky: resolved (fixed in 74.0.3729.108-1) sid: resolved (fixed in 74.0.3729.108-1) tr
debian
CVE-2022-3053P4MEDIUMCVSS 4.3fixed in chromium 105.0.5195.52-1 (bookworm)2022
CVE-2022-3053 [MEDIUM] CVE-2022-3053: chromium - Inappropriate implementation in Pointer Lock in Google Chrome on Mac prior to 10... Inappropriate implementation in Pointer Lock in Google Chrome on Mac prior to 105.0.5195.52 allowed a remote attacker to restrict user navigation via a crafted HTML page. Scope: local bookworm: resolved (fixed in 105.0.5195.52-1) bullseye: resolved (fixed in 105.0.5195.52-1~deb11u1) forky: resolved (fixed in 105.0.5195.52-1) sid: resolved (fixed in 105.0.5195.52-1)
debian
CVE-2021-4316P4MEDIUMCVSS 4.3fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-4316 [MEDIUM] CVE-2021-4316: chromium - Inappropriate implementation in Cast UI in Google Chrome prior to 96.0.4664.45 a... Inappropriate implementation in Cast UI in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to spoof browser UI via a crafted HTML page. (Chromium security severity: Low) Scope: local bookworm: resolved (fixed in 97.0.4692.71-0.1) bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1) forky: resolved (fixed in 97.0.4692.71-0.1) sid: resolved (fixed in
debian
CVE-2023-1236P4MEDIUMCVSS 4.3fixed in chromium 111.0.5563.64-1 (bookworm)2023
CVE-2023-1236 [MEDIUM] CVE-2023-1236: chromium - Inappropriate implementation in Internals in Google Chrome prior to 111.0.5563.6... Inappropriate implementation in Internals in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to spoof the origin of an iframe via a crafted HTML page. (Chromium security severity: Low) Scope: local bookworm: resolved (fixed in 111.0.5563.64-1) bullseye: resolved (fixed in 111.0.5563.64-1~deb11u1) forky: resolved (fixed in 111.0.5563.64-1) sid: resolv
debian
CVE-2024-7978P4MEDIUMCVSS 4.3fixed in chromium 128.0.6613.84-1~deb12u1 (bookworm)2024
CVE-2024-7978 [MEDIUM] CVE-2024-7978: chromium - Insufficient policy enforcement in Data Transfer in Google Chrome prior to 128.0... Insufficient policy enforcement in Data Transfer in Google Chrome prior to 128.0.6613.84 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 128.0.6613.84-1~deb12u1) bullseye: open forky: resolved (fixed in 1
debian
CVE-2024-7975P4MEDIUMCVSS 4.3fixed in chromium 128.0.6613.84-1~deb12u1 (bookworm)2024
CVE-2024-7975 [MEDIUM] CVE-2024-7975: chromium - Inappropriate implementation in Permissions in Google Chrome prior to 128.0.6613... Inappropriate implementation in Permissions in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 128.0.6613.84-1~deb12u1) bullseye: open forky: resolved (fixed in 128.0.6613.84-1) sid: resolved (fixed in 128.0.6613.84-1) trixie
debian
CVE-2022-4186P4MEDIUMCVSS 4.3fixed in chromium 108.0.5359.71-1 (bookworm)2022
CVE-2022-4186 [MEDIUM] CVE-2022-4186: chromium - Insufficient validation of untrusted input in Downloads in Google Chrome prior t... Insufficient validation of untrusted input in Downloads in Google Chrome prior to 108.0.5359.71 allowed an attacker who convinced a user to install a malicious extension to bypass Downloads restrictions via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 108.0.5359.71-1) bullseye: resolved (fixed in 108.0.5359.71-
debian
CVE-2024-7981P4MEDIUMCVSS 4.3fixed in chromium 128.0.6613.84-1~deb12u1 (bookworm)2024
CVE-2024-7981 [MEDIUM] CVE-2024-7981: chromium - Inappropriate implementation in Views in Google Chrome prior to 128.0.6613.84 al... Inappropriate implementation in Views in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low) Scope: local bookworm: resolved (fixed in 128.0.6613.84-1~deb12u1) bullseye: open forky: resolved (fixed in 128.0.6613.84-1) sid: resolved (fixed in 128.0.6613.84-1) trixie: resolve
debian
CVE-2025-13634P4MEDIUMCVSS 4.4fixed in chromium 143.0.7499.40-1~deb12u1 (bookworm)2025
CVE-2025-13634 [MEDIUM] CVE-2025-13634: chromium - Inappropriate implementation in Downloads in Google Chrome on Windows prior to 1... Inappropriate implementation in Downloads in Google Chrome on Windows prior to 143.0.7499.41 allowed a local attacker to bypass mark of the web via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 143.0.7499.40-1~deb12u1) bullseye: open forky: resolved (fixed in 143.0.7499.40-1) sid: resolved (fixed in 143.0.7499
debian
CVE-2022-4189P4MEDIUMCVSS 4.3fixed in chromium 108.0.5359.71-1 (bookworm)2022
CVE-2022-4189 [MEDIUM] CVE-2022-4189: chromium - Insufficient policy enforcement in DevTools in Google Chrome prior to 108.0.5359... Insufficient policy enforcement in DevTools in Google Chrome prior to 108.0.5359.71 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 108.0.5359.71-1) bullseye: resolved (fixed in 108.0.5359.71-2~de
debian
Debian Chromium vulnerabilities | cvebase