Debian Chromium vulnerabilities

2,176 known vulnerabilities affecting debian/chromium.

Total CVEs
2,176
CISA KEV
65
actively exploited
Public exploits
14
Exploited in wild
56
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW56UNKNOWN8

Vulnerabilities

Page 105 of 109
CVE-2019-13661MEDIUMCVSS 4.3fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-13661 [MEDIUM] CVE-2019-13661: chromium - UI spoofing in Chromium in Google Chrome prior to 77.0.3865.75 allowed a remote ... UI spoofing in Chromium in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to spoof notifications via a crafted HTML page. Scope: local bookworm: resolved (fixed in 78.0.3904.87-1) bullseye: resolved (fixed in 78.0.3904.87-1) forky: resolved (fixed in 78.0.3904.87-1) sid: resolved (fixed in 78.0.3904.87-1) trixie: resolved (fixed in 78.0.3904.87-1)
debian
CVE-2019-5844MEDIUMCVSS 6.5fixed in chromium 73.0.3683.75-1 (bookworm)2019
CVE-2019-5844 [MEDIUM] CVE-2019-5844: chromium - Out of bounds access in SwiftShader in Google Chrome prior to 73.0.3683.75 allow... Out of bounds access in SwiftShader in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 73.0.3683.75-1) bullseye: resolved (fixed in 73.0.3683.75-1) forky: resolved (fixed in 73.0.3683.75-1) sid: resolved (fixed in 73.0.3683.75-1) trixie: resolved
debian
CVE-2019-5861MEDIUMCVSS 4.3fixed in chromium 76.0.3809.87-1 (bookworm)2019
CVE-2019-5861 [MEDIUM] CVE-2019-5861: chromium - Insufficient data validation in Blink in Google Chrome prior to 76.0.3809.87 all... Insufficient data validation in Blink in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to bypass anti-clickjacking policy via a crafted HTML page. Scope: local bookworm: resolved (fixed in 76.0.3809.87-1) bullseye: resolved (fixed in 76.0.3809.87-1) forky: resolved (fixed in 76.0.3809.87-1) sid: resolved (fixed in 76.0.3809.87-1) trixie: resolved (f
debian
CVE-2019-5840MEDIUMCVSS 4.3fixed in chromium 75.0.3770.80-1 (bookworm)2019
CVE-2019-5840 [MEDIUM] CVE-2019-5840: chromium - Incorrect security UI in popup blocker in Google Chrome on iOS prior to 75.0.377... Incorrect security UI in popup blocker in Google Chrome on iOS prior to 75.0.3770.80 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. Scope: local bookworm: resolved (fixed in 75.0.3770.80-1) bullseye: resolved (fixed in 75.0.3770.80-1) forky: resolved (fixed in 75.0.3770.80-1) sid: resolved (fixed in 75.0.3770.80-1) trixie: reso
debian
CVE-2019-13704MEDIUMCVSS 4.3fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-13704 [MEDIUM] CVE-2019-13704: chromium - Insufficient policy enforcement in navigation in Google Chrome prior to 78.0.390... Insufficient policy enforcement in navigation in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to bypass content security policy via a crafted HTML page. Scope: local bookworm: resolved (fixed in 78.0.3904.87-1) bullseye: resolved (fixed in 78.0.3904.87-1) forky: resolved (fixed in 78.0.3904.87-1) sid: resolved (fixed in 78.0.3904.87-1) trixie: re
debian
CVE-2019-13742MEDIUMCVSS 6.5fixed in chromium 79.0.3945.79-1 (bookworm)2019
CVE-2019-13742 [MEDIUM] CVE-2019-13742: chromium - Incorrect security UI in Omnibox in Google Chrome on iOS prior to 79.0.3945.79 a... Incorrect security UI in Omnibox in Google Chrome on iOS prior to 79.0.3945.79 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name. Scope: local bookworm: resolved (fixed in 79.0.3945.79-1) bullseye: resolved (fixed in 79.0.3945.79-1) forky: resolved (fixed in 79.0.3945.79-1) sid: resolved (fixed in 79.0.3945.79-1) t
debian
CVE-2019-13756MEDIUMCVSS 4.3fixed in chromium 79.0.3945.79-1 (bookworm)2019
CVE-2019-13756 [MEDIUM] CVE-2019-13756: chromium - Incorrect security UI in printing in Google Chrome prior to 79.0.3945.79 allowed... Incorrect security UI in printing in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via a crafted HTML page. Scope: local bookworm: resolved (fixed in 79.0.3945.79-1) bullseye: resolved (fixed in 79.0.3945.79-1) forky: resolved (fixed in 79.0.3945.79-1) sid: resolved (fixed in 79.0.3945.79-1) trixie: resolved (fixed in 79
debian
CVE-2019-5805MEDIUMCVSS 6.5fixed in chromium 74.0.3729.108-1 (bookworm)2019
CVE-2019-5805 [MEDIUM] CVE-2019-5805: chromium - Use-after-free in PDFium in Google Chrome prior to 74.0.3729.108 allowed a remot... Use-after-free in PDFium in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. Scope: local bookworm: resolved (fixed in 74.0.3729.108-1) bullseye: resolved (fixed in 74.0.3729.108-1) forky: resolved (fixed in 74.0.3729.108-1) sid: resolved (fixed in 74.0.3729.108-1) trixie: resolved (fixed
debian
CVE-2019-13683MEDIUMCVSS 6.5fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-13683 [MEDIUM] CVE-2019-13683: chromium - Insufficient policy enforcement in developer tools in Google Chrome prior to 77.... Insufficient policy enforcement in developer tools in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to leak cross-origin data via a crafted HTML page. Scope: local bookworm: resolved (fixed in 78.0.3904.87-1) bullseye: resolved (fixed in 78.0.3904.87-1) forky: resolved (fixed in 78.0.3904.87-1) sid: resolved (fixed in 78.0.3904.87-1) trixie: resol
debian
CVE-2019-13663MEDIUMCVSS 4.3fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-13663 [MEDIUM] CVE-2019-13663: chromium - IDN spoofing in Omnibox in Google Chrome prior to 77.0.3865.75 allowed a remote ... IDN spoofing in Omnibox in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name. Scope: local bookworm: resolved (fixed in 78.0.3904.87-1) bullseye: resolved (fixed in 78.0.3904.87-1) forky: resolved (fixed in 78.0.3904.87-1) sid: resolved (fixed in 78.0.3904.87-1) trixie: resolved (
debian
CVE-2019-13744MEDIUMCVSS 6.5fixed in chromium 79.0.3945.79-1 (bookworm)2019
CVE-2019-13744 [MEDIUM] CVE-2019-13744: chromium - Insufficient policy enforcement in cookies in Google Chrome prior to 79.0.3945.7... Insufficient policy enforcement in cookies in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to leak cross-origin data via a crafted HTML page. Scope: local bookworm: resolved (fixed in 79.0.3945.79-1) bullseye: resolved (fixed in 79.0.3945.79-1) forky: resolved (fixed in 79.0.3945.79-1) sid: resolved (fixed in 79.0.3945.79-1) trixie: resolved (fix
debian
CVE-2019-13711MEDIUMCVSS 5.3fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-13711 [MEDIUM] CVE-2019-13711: chromium - Insufficient policy enforcement in JavaScript in Google Chrome prior to 78.0.390... Insufficient policy enforcement in JavaScript in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to leak cross-origin data via a crafted HTML page. Scope: local bookworm: resolved (fixed in 78.0.3904.87-1) bullseye: resolved (fixed in 78.0.3904.87-1) forky: resolved (fixed in 78.0.3904.87-1) sid: resolved (fixed in 78.0.3904.87-1) trixie: resolved (
debian
CVE-2019-13718MEDIUMCVSS 4.3fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-13718 [MEDIUM] CVE-2019-13718: chromium - Insufficient data validation in Omnibox in Google Chrome prior to 78.0.3904.70 a... Insufficient data validation in Omnibox in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name. Scope: local bookworm: resolved (fixed in 78.0.3904.87-1) bullseye: resolved (fixed in 78.0.3904.87-1) forky: resolved (fixed in 78.0.3904.87-1) sid: resolved (fixed in 78.0.3904.87-1) tr
debian
CVE-2019-5868MEDIUMCVSS 5.5fixed in chromium 76.0.3809.100-1 (bookworm)2019
CVE-2019-5868 [MEDIUM] CVE-2019-5868: chromium - Use after free in PDFium in Google Chrome prior to 76.0.3809.100 allowed a remot... Use after free in PDFium in Google Chrome prior to 76.0.3809.100 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. Scope: local bookworm: resolved (fixed in 76.0.3809.100-1) bullseye: resolved (fixed in 76.0.3809.100-1) forky: resolved (fixed in 76.0.3809.100-1) sid: resolved (fixed in 76.0.3809.100-1) trixie: resolved (fixed
debian
CVE-2019-13754MEDIUMCVSS 4.3fixed in chromium 79.0.3945.79-1 (bookworm)2019
CVE-2019-13754 [MEDIUM] CVE-2019-13754: chromium - Insufficient policy enforcement in extensions in Google Chrome prior to 79.0.394... Insufficient policy enforcement in extensions in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. Scope: local bookworm: resolved (fixed in 79.0.3945.79-1) bullseye: resolved (fixed in 79.0.3945.79-1) forky: resolved (fixed in 79.0.3945.79-1) sid: resolved (fixed in 79.0.3945.79-1) trixie: re
debian
CVE-2019-13737MEDIUMCVSS 6.5fixed in chromium 79.0.3945.79-1 (bookworm)2019
CVE-2019-13737 [MEDIUM] CVE-2019-13737: chromium - Insufficient policy enforcement in autocomplete in Google Chrome prior to 79.0.3... Insufficient policy enforcement in autocomplete in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. Scope: local bookworm: resolved (fixed in 79.0.3945.79-1) bullseye: resolved (fixed in 79.0.3945.79-1) forky: resolved (fixed in 79.0.3945.79-1) sid: resolved (fix
debian
CVE-2019-5857MEDIUMCVSS 6.5fixed in chromium 76.0.3809.87-1 (bookworm)2019
CVE-2019-5857 [MEDIUM] CVE-2019-5857: chromium - Inappropriate implementation in JavaScript in Google Chrome prior to 76.0.3809.8... Inappropriate implementation in JavaScript in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 76.0.3809.87-1) bullseye: resolved (fixed in 76.0.3809.87-1) forky: resolved (fixed in 76.0.3809.87-1) sid: resolved (fixed in 76.0.3809.87-1) trixie:
debian
CVE-2019-13660MEDIUMCVSS 5.3fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-13660 [MEDIUM] CVE-2019-13660: chromium - UI spoofing in Chromium in Google Chrome prior to 77.0.3865.75 allowed a remote ... UI spoofing in Chromium in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to spoof notifications via a crafted HTML page. Scope: local bookworm: resolved (fixed in 78.0.3904.87-1) bullseye: resolved (fixed in 78.0.3904.87-1) forky: resolved (fixed in 78.0.3904.87-1) sid: resolved (fixed in 78.0.3904.87-1) trixie: resolved (fixed in 78.0.3904.87-1)
debian
CVE-2019-5846MEDIUMCVSS 6.5fixed in chromium 73.0.3683.75-1 (bookworm)2019
CVE-2019-5846 [MEDIUM] CVE-2019-5846: chromium - Out of bounds access in SwiftShader in Google Chrome prior to 73.0.3683.75 allow... Out of bounds access in SwiftShader in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 73.0.3683.75-1) bullseye: resolved (fixed in 73.0.3683.75-1) forky: resolved (fixed in 73.0.3683.75-1) sid: resolved (fixed in 73.0.3683.75-1) trixie: resolved
debian
CVE-2019-5803MEDIUMCVSS 6.5fixed in chromium 73.0.3683.75-1 (bookworm)2019
CVE-2019-5803 [MEDIUM] CVE-2019-5803: chromium - Insufficient policy enforcement in Content Security Policy in Google Chrome prio... Insufficient policy enforcement in Content Security Policy in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to bypass content security policy via a crafted HTML page. Scope: local bookworm: resolved (fixed in 73.0.3683.75-1) bullseye: resolved (fixed in 73.0.3683.75-1) forky: resolved (fixed in 73.0.3683.75-1) sid: resolved (fixed in 73.0.3683.75-1)
debian