cbcvebase.

Debian Chromium vulnerabilities

2,134 known vulnerabilities affecting debian/chromium.

Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8

Vulnerabilities

Page 17 of 107
CVE-2020-15964P3HIGHCVSS 8.8fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-15964 [HIGH] CVE-2020-15964: chromium - Insufficient data validation in media in Google Chrome prior to 85.0.4183.121 al... Insufficient data validation in media in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 87.0.4280.88-0.1) bullseye: resolved (fixed in 87.0.4280.88-0.1) forky: resolved (fixed in 87.0.4280.88-0.1) sid: resolved (fixed in 87.0.4280.88-0.1) trixie
debian
CVE-2021-30590P3HIGHCVSS 8.8fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30590 [HIGH] CVE-2021-30590: chromium - Heap buffer overflow in Bookmarks in Google Chrome prior to 92.0.4515.131 allowe... Heap buffer overflow in Bookmarks in Google Chrome prior to 92.0.4515.131 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 93.0.4577.82-1) bullseye: resolved (fixed in 93.0.4577.82-1) forky: resolved (fixed in 93.0.4577.82-1) sid: resolved (fixed in 93.0.4577.82-1) trixie: resolved (
debian
CVE-2022-4920P3CRITICALCVSS 9.6fixed in chromium 101.0.4951.41-1 (bookworm)2022
CVE-2022-4920 [CRITICAL] CVE-2022-4920: chromium - Heap buffer overflow in Blink in Google Chrome prior to 101.0.4951.41 allowed a ... Heap buffer overflow in Blink in Google Chrome prior to 101.0.4951.41 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 101.0.4951.41-1) bullseye: resolved (fixed in 101.0.4951.41-1~deb11u1) f
debian
CVE-2022-4924P3CRITICALCVSS 9.6fixed in chromium 97.0.4692.71-0.1 (bookworm)2022
CVE-2022-4924 [CRITICAL] CVE-2022-4924: chromium - Use after free in WebRTC in Google Chrome prior to 97.0.4692.71 allowed a remote... Use after free in WebRTC in Google Chrome prior to 97.0.4692.71 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 97.0.4692.71-0.1) bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1) forky: resolved (fi
debian
CVE-2018-18342P3HIGHCVSS 8.8fixed in chromium 71.0.3578.80-1 (bookworm)2018
CVE-2018-18342 [HIGH] CVE-2018-18342: chromium - Execution of user supplied Javascript during object deserialization can update o... Execution of user supplied Javascript during object deserialization can update object length leading to an out of bounds write in V8 in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. Scope: local bookworm: resolved (fixed in 71.0.3578.80-1) bullseye: resolved (fixed in 71.0.3578.80-1
debian
CVE-2022-2852P3HIGHCVSS 8.8fixed in chromium 104.0.5112.101-1 (bookworm)2022
CVE-2022-2852 [HIGH] CVE-2022-2852: chromium - Use after free in FedCM in Google Chrome prior to 104.0.5112.101 allowed a remot... Use after free in FedCM in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 104.0.5112.101-1) bullseye: resolved (fixed in 104.0.5112.101-1~deb11u1) forky: resolved (fixed in 104.0.5112.101-1) sid: resolved (fixed in 104.0.5112.101-1) trixie: resol
debian
CVE-2021-30600P3HIGHCVSS 8.8fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30600 [HIGH] CVE-2021-30600: chromium - Use after free in Printing in Google Chrome prior to 92.0.4515.159 allowed a rem... Use after free in Printing in Google Chrome prior to 92.0.4515.159 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 93.0.4577.82-1) bullseye: resolved (fixed in 93.0.4577.82-1) forky: resolved (fixed in 93.0.4577.82-1) sid: resolved (fixed in
debian
CVE-2021-30517P3HIGHCVSS 8.8fixed in chromium 90.0.4430.212-1 (bookworm)2021
CVE-2021-30517 [HIGH] CVE-2021-30517: chromium - Type confusion in V8 in Google Chrome prior to 90.0.4430.212 allowed a remote at... Type confusion in V8 in Google Chrome prior to 90.0.4430.212 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 90.0.4430.212-1) bullseye: resolved (fixed in 90.0.4430.212-1) forky: resolved (fixed in 90.0.4430.212-1) sid: resolved (fixed in 90.0.4430.212-1) trixie: resolved (fixed in
debian
CVE-2023-4860P3CRITICALCVSS 9.6fixed in chromium 115.0.5790.98-1~deb12u1 (bookworm)2023
CVE-2023-4860 [CRITICAL] CVE-2023-4860: chromium - Inappropriate implementation in Skia in Google Chrome prior to 115.0.5790.98 all... Inappropriate implementation in Skia in Google Chrome prior to 115.0.5790.98 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 115.0.5790.98-1~deb12u1) bullseye: resolved (fixed in 115.0.5790.98-1~deb11u1)
debian
CVE-2026-5883P3UNKNOWNfixed in chromium 147.0.7727.55-1 (sid)2026
CVE-2026-5883 CVE-2026-5883: chromium - Use after free in Media in Google Chrome prior to 147.0.7727.55 allowed a remote... Use after free in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: open bullseye: open forky: open sid: resolved (fixed in 147.0.7727.55-1) trixie: open
debian
CVE-2019-13726P3HIGHCVSS 8.8fixed in chromium 79.0.3945.79-1 (bookworm)2019
CVE-2019-13726 [HIGH] CVE-2019-13726: chromium - Buffer overflow in password manager in Google Chrome prior to 79.0.3945.79 allow... Buffer overflow in password manager in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to execute arbitrary code via a crafted HTML page. Scope: local bookworm: resolved (fixed in 79.0.3945.79-1) bullseye: resolved (fixed in 79.0.3945.79-1) forky: resolved (fixed in 79.0.3945.79-1) sid: resolved (fixed in 79.0.3945.79-1) trixie: resolved (fixed in 79.
debian
CVE-2021-30588P3HIGHCVSS 8.8fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30588 [HIGH] CVE-2021-30588: chromium - Type confusion in V8 in Google Chrome prior to 92.0.4515.107 allowed a remote at... Type confusion in V8 in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 93.0.4577.82-1) bullseye: resolved (fixed in 93.0.4577.82-1) forky: resolved (fixed in 93.0.4577.82-1) sid: resolved (fixed in 93.0.4577.82-1) trixie: resolved (fixed in 93.0
debian
CVE-2019-13725P3HIGHCVSS 8.8fixed in chromium 79.0.3945.79-1 (bookworm)2019
CVE-2019-13725 [HIGH] CVE-2019-13725: chromium - Use-after-free in Bluetooth in Google Chrome prior to 79.0.3945.79 allowed a rem... Use-after-free in Bluetooth in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to execute arbitrary code via a crafted HTML page. Scope: local bookworm: resolved (fixed in 79.0.3945.79-1) bullseye: resolved (fixed in 79.0.3945.79-1) forky: resolved (fixed in 79.0.3945.79-1) sid: resolved (fixed in 79.0.3945.79-1) trixie: resolved (fixed in 79.0.3945.7
debian
CVE-2019-13735P3HIGHCVSS 8.8fixed in chromium 79.0.3945.79-1 (bookworm)2019
CVE-2019-13735 [HIGH] CVE-2019-13735: chromium - Out of bounds write in JavaScript in Google Chrome prior to 79.0.3945.79 allowed... Out of bounds write in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. Scope: local bookworm: resolved (fixed in 79.0.3945.79-1) bullseye: resolved (fixed in 79.0.3945.79-1) forky: resolved (fixed in 79.0.3945.79-1) sid: resolved (fixed in 79.0.3945.79-1) trixie: resolve
debian
CVE-2023-4354P3HIGHCVSS 8.8fixed in chromium 116.0.5845.96-1~deb12u1 (bookworm)2023
CVE-2023-4354 [HIGH] CVE-2023-4354: chromium - Heap buffer overflow in Skia in Google Chrome prior to 116.0.5845.96 allowed a r... Heap buffer overflow in Skia in Google Chrome prior to 116.0.5845.96 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 116.0.5845.96-1~deb12u1) bullseye: resolved (fixed in 116.0.5845.96-1~deb11u1) forky: resolv
debian
CVE-2023-5857P3HIGHCVSS 8.8fixed in chromium 119.0.6045.105-1~deb12u1 (bookworm)2023
CVE-2023-5857 [HIGH] CVE-2023-5857: chromium - Inappropriate implementation in Downloads in Google Chrome prior to 119.0.6045.1... Inappropriate implementation in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to potentially execute arbitrary code via a malicious file. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 119.0.6045.105-1~deb12u1) bullseye: resolved (fixed in 119.0.6045.105-1~deb11u1) forky: resolved (fixed in 119.0.6045.105
debian
CVE-2024-2176P3HIGHCVSS 8.8fixed in chromium 122.0.6261.111-1~deb12u1 (bookworm)2024
CVE-2024-2176 [HIGH] CVE-2024-2176: chromium - Use after free in FedCM in Google Chrome prior to 122.0.6261.111 allowed a remot... Use after free in FedCM in Google Chrome prior to 122.0.6261.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 122.0.6261.111-1~deb12u1) bullseye: open forky: resolved (fixed in 122.0.6261.111-1) sid: resolved (fixed in 122.0.6261.111-1) trixie: re
debian
CVE-2023-5472P3HIGHCVSS 8.8fixed in chromium 118.0.5993.117-1~deb12u1 (bookworm)2023
CVE-2023-5472 [HIGH] CVE-2023-5472: chromium - Use after free in Profiles in Google Chrome prior to 118.0.5993.117 allowed a re... Use after free in Profiles in Google Chrome prior to 118.0.5993.117 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 118.0.5993.117-1~deb12u1) bullseye: resolved (fixed in 118.0.5993.117-1~deb11u1) forky: resolved (fixed in 118.0.5993.117-1) sid: reso
debian
CVE-2024-2885P3HIGHCVSS 8.8fixed in chromium 123.0.6312.86-1~deb12u1 (bookworm)2024
CVE-2024-2885 [HIGH] CVE-2024-2885: chromium - Use after free in Dawn in Google Chrome prior to 123.0.6312.86 allowed a remote ... Use after free in Dawn in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 123.0.6312.86-1~deb12u1) bullseye: open forky: resolved (fixed in 123.0.6312.86-1) sid: resolved (fixed in 123.0.6312.86-1) trixie: resolve
debian
CVE-2024-6100P3HIGHCVSS 8.8fixed in chromium 126.0.6478.114-1~deb12u1 (bookworm)2024
CVE-2024-6100 [HIGH] CVE-2024-6100: chromium - Type Confusion in V8 in Google Chrome prior to 126.0.6478.114 allowed a remote a... Type Confusion in V8 in Google Chrome prior to 126.0.6478.114 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 126.0.6478.114-1~deb12u1) bullseye: open forky: resolved (fixed in 126.0.6478.114-1) sid: resolved (fixed in 126.0.6478.114-1) trixie: resolved (fixed in
debian
Debian Chromium vulnerabilities | cvebase