Debian Chromium vulnerabilities

2,176 known vulnerabilities affecting debian/chromium.

Total CVEs
2,176
CISA KEV
65
actively exploited
Public exploits
14
Exploited in wild
56
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW56UNKNOWN8

Vulnerabilities

Page 109 of 109
CVE-2018-20067MEDIUMCVSS 4.3fixed in chromium 71.0.3578.80-1 (bookworm)2018
CVE-2018-20067 [MEDIUM] CVE-2018-20067: chromium - A renderer initiated back navigation was incorrectly allowed to cancel a browser... A renderer initiated back navigation was incorrectly allowed to cancel a browser initiated one in Navigation in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to confuse the user about the origin of the current page via a crafted HTML page. Scope: local bookworm: resolved (fixed in 71.0.3578.80-1) bullseye: resolved (fixed in 71.0.3578.80-1) forky:
debian
CVE-2018-20070MEDIUMCVSS 6.5fixed in chromium 71.0.3578.80-1 (bookworm)2018
CVE-2018-20070 [MEDIUM] CVE-2018-20070: chromium - Incorrect handling of confusable characters in URL Formatter in Google Chrome pr... Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name. Scope: local bookworm: resolved (fixed in 71.0.3578.80-1) bullseye: resolved (fixed in 71.0.3578.80-1) forky: resolved (fixed in 71.0.3578.80-1) sid: resolved (fixed
debian
CVE-2018-18348MEDIUMCVSS 4.3fixed in chromium 71.0.3578.80-1 (bookworm)2018
CVE-2018-18348 [MEDIUM] CVE-2018-18348: chromium - Incorrect handling of bidirectional domain names with RTL characters in Omnibox ... Incorrect handling of bidirectional domain names with RTL characters in Omnibox in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name. Scope: local bookworm: resolved (fixed in 71.0.3578.80-1) bullseye: resolved (fixed in 71.0.3578.80-1) forky: resolved (fixed in 71.0.3578.80-1) s
debian
CVE-2018-18350MEDIUMCVSS 6.5fixed in chromium 71.0.3578.80-1 (bookworm)2018
CVE-2018-18350 [MEDIUM] CVE-2018-18350: chromium - Incorrect handling of CSP enforcement during navigations in Blink in Google Chro... Incorrect handling of CSP enforcement during navigations in Blink in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to bypass content security policy via a crafted HTML page. Scope: local bookworm: resolved (fixed in 71.0.3578.80-1) bullseye: resolved (fixed in 71.0.3578.80-1) forky: resolved (fixed in 71.0.3578.80-1) sid: resolved (fixed in 71.0.3
debian
CVE-2018-18355MEDIUMCVSS 4.3fixed in chromium 71.0.3578.80-1 (bookworm)2018
CVE-2018-18355 [MEDIUM] CVE-2018-18355: chromium - Incorrect handling of confusable characters in URL Formatter in Google Chrome pr... Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name. Scope: local bookworm: resolved (fixed in 71.0.3578.80-1) bullseye: resolved (fixed in 71.0.3578.80-1) forky: resolved (fixed in 71.0.3578.80-1) sid: resolved (fixed
debian
CVE-2018-18344MEDIUMCVSS 6.5fixed in chromium 71.0.3578.80-1 (bookworm)2018
CVE-2018-18344 [MEDIUM] CVE-2018-18344: chromium - Inappropriate allowance of the setDownloadBehavior devtools protocol feature in ... Inappropriate allowance of the setDownloadBehavior devtools protocol feature in Extensions in Google Chrome prior to 71.0.3578.80 allowed a remote attacker with control of an installed extension to access files on the local file system via a crafted Chrome Extension. Scope: local bookworm: resolved (fixed in 71.0.3578.80-1) bullseye: resolved (fixed in 71.0.3578.
debian
CVE-2018-18353MEDIUMCVSS 6.5fixed in chromium 71.0.3578.80-1 (bookworm)2018
CVE-2018-18353 [MEDIUM] CVE-2018-18353: chromium - Failure to dismiss http auth dialogs on navigation in Network Authentication in ... Failure to dismiss http auth dialogs on navigation in Network Authentication in Google Chrome on Android prior to 71.0.3578.80 allowed a remote attacker to confuse the user about the origin of an auto dialog via a crafted HTML page. Scope: local bookworm: resolved (fixed in 71.0.3578.80-1) bullseye: resolved (fixed in 71.0.3578.80-1) forky: resolved (fixed in 71.
debian
CVE-2018-18358MEDIUMCVSS 5.7fixed in chromium 71.0.3578.80-1 (bookworm)2018
CVE-2018-18358 [MEDIUM] CVE-2018-18358: chromium - Lack of special casing of localhost in WPAD files in Google Chrome prior to 71.0... Lack of special casing of localhost in WPAD files in Google Chrome prior to 71.0.3578.80 allowed an attacker on the local network segment to proxy resources on localhost via a crafted WPAD file. Scope: local bookworm: resolved (fixed in 71.0.3578.80-1) bullseye: resolved (fixed in 71.0.3578.80-1) forky: resolved (fixed in 71.0.3578.80-1) sid: resolved (fixed in 7
debian
CVE-2018-18357MEDIUMCVSS 4.3fixed in chromium 71.0.3578.80-1 (bookworm)2018
CVE-2018-18357 [MEDIUM] CVE-2018-18357: chromium - Incorrect handling of confusable characters in URL Formatter in Google Chrome pr... Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name. Scope: local bookworm: resolved (fixed in 71.0.3578.80-1) bullseye: resolved (fixed in 71.0.3578.80-1) forky: resolved (fixed in 71.0.3578.80-1) sid: resolved (fixed
debian
CVE-2018-18346MEDIUMCVSS 6.5fixed in chromium 71.0.3578.80-1 (bookworm)2018
CVE-2018-18346 [MEDIUM] CVE-2018-18346: chromium - Incorrect handling of alert box display in Blink in Google Chrome prior to 71.0.... Incorrect handling of alert box display in Blink in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to present confusing browser UI via a crafted HTML page. Scope: local bookworm: resolved (fixed in 71.0.3578.80-1) bullseye: resolved (fixed in 71.0.3578.80-1) forky: resolved (fixed in 71.0.3578.80-1) sid: resolved (fixed in 71.0.3578.80-1) trixie: r
debian
CVE-2018-18351MEDIUMCVSS 6.5fixed in chromium 71.0.3578.80-1 (bookworm)2018
CVE-2018-18351 [MEDIUM] CVE-2018-18351: chromium - Lack of proper validation of ancestor frames site when sending lax cookies in Na... Lack of proper validation of ancestor frames site when sending lax cookies in Navigation in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to bypass SameSite cookie policy via a crafted HTML page. Scope: local bookworm: resolved (fixed in 71.0.3578.80-1) bullseye: resolved (fixed in 71.0.3578.80-1) forky: resolved (fixed in 71.0.3578.80-1) sid: res
debian
CVE-2018-18349MEDIUMCVSS 6.5fixed in chromium 71.0.3578.80-1 (bookworm)2018
CVE-2018-18349 [MEDIUM] CVE-2018-18349: chromium - Remote frame navigations was incorrectly permitted to local resources in Blink i... Remote frame navigations was incorrectly permitted to local resources in Blink in Google Chrome prior to 71.0.3578.80 allowed an attacker who convinced a user to install a malicious extension to access files on the local file system via a crafted Chrome Extension. Scope: local bookworm: resolved (fixed in 71.0.3578.80-1) bullseye: resolved (fixed in 71.0.3578.80-
debian
CVE-2018-18345MEDIUMCVSS 6.5fixed in chromium 71.0.3578.80-1 (bookworm)2018
CVE-2018-18345 [MEDIUM] CVE-2018-18345: chromium - Incorrect handling of blob URLS in Site Isolation in Google Chrome prior to 71.0... Incorrect handling of blob URLS in Site Isolation in Google Chrome prior to 71.0.3578.80 allowed a remote attacker who had compromised the renderer process to bypass site isolation protections via a crafted HTML page. Scope: local bookworm: resolved (fixed in 71.0.3578.80-1) bullseye: resolved (fixed in 71.0.3578.80-1) forky: resolved (fixed in 71.0.3578.80-1) si
debian
CVE-2018-20068MEDIUMCVSS 4.3fixed in chromium 71.0.3578.80-1 (bookworm)2018
CVE-2018-20068 [MEDIUM] CVE-2018-20068: chromium - Incorrect handling of 304 status codes in Navigation in Google Chrome prior to 7... Incorrect handling of 304 status codes in Navigation in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to confuse the user about the origin of the current page via a crafted HTML page. Scope: local bookworm: resolved (fixed in 71.0.3578.80-1) bullseye: resolved (fixed in 71.0.3578.80-1) forky: resolved (fixed in 71.0.3578.80-1) sid: resolved (fixed
debian
CVE-2018-20069LOWCVSS 4.32018
CVE-2018-20069 [MEDIUM] CVE-2018-20069: chromium - Failure to prevent navigation to top frame to data URLs in Navigation in Google ... Failure to prevent navigation to top frame to data URLs in Navigation in Google Chrome on iOS prior to 71.0.3578.80 allowed a remote attacker to confuse the user about the origin of the current page via a crafted HTML page. Scope: local bookworm: resolved bullseye: resolved forky: resolved sid: resolved trixie: resolved
debian
CVE-2018-20073LOWCVSS 5.5fixed in chromium 72.0.3626.81-1 (bookworm)2018
CVE-2018-20073 [MEDIUM] CVE-2018-20073: chromium - Use of extended attributes in downloads in Google Chrome prior to 72.0.3626.81 a... Use of extended attributes in downloads in Google Chrome prior to 72.0.3626.81 allowed a local attacker to read download URLs via the filesystem. Scope: local bookworm: resolved (fixed in 72.0.3626.81-1) bullseye: resolved (fixed in 72.0.3626.81-1) forky: resolved (fixed in 72.0.3626.81-1) sid: resolved (fixed in 72.0.3626.81-1) trixie: resolved (fixed in 72.0.36
debian
← Previous109 / 109