cbcvebase.

Debian Chromium vulnerabilities

2,134 known vulnerabilities affecting debian/chromium.

Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8

Vulnerabilities

Page 20 of 107
CVE-2022-0452P3CRITICALCVSS 9.6fixed in chromium 98.0.4758.80-1 (bookworm)2022
CVE-2022-0452 [CRITICAL] CVE-2022-0452: chromium - Use after free in Safe Browsing in Google Chrome prior to 98.0.4758.80 allowed a... Use after free in Safe Browsing in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. Scope: local bookworm: resolved (fixed in 98.0.4758.80-1) bullseye: resolved (fixed in 98.0.4758.80-1~deb11u1) forky: resolved (fixed in 98.0.4758.80-1) sid: resolved (fixed in 98.0.4758.80-1) trixie: re
debian
CVE-2021-21156P3HIGHCVSS 8.8fixed in chromium 88.0.4324.182-1 (bookworm)2021
CVE-2021-21156 [HIGH] CVE-2021-21156: chromium - Heap buffer overflow in V8 in Google Chrome prior to 88.0.4324.182 allowed a rem... Heap buffer overflow in V8 in Google Chrome prior to 88.0.4324.182 allowed a remote attacker to potentially exploit heap corruption via a crafted script. Scope: local bookworm: resolved (fixed in 88.0.4324.182-1) bullseye: resolved (fixed in 88.0.4324.182-1) forky: resolved (fixed in 88.0.4324.182-1) sid: resolved (fixed in 88.0.4324.182-1) trixie: resolved (fixed
debian
CVE-2020-6492P3CRITICALCVSS 9.6fixed in chromium 83.0.4103.106-1 (bookworm)2020
CVE-2020-6492 [CRITICAL] CVE-2020-6492: chromium - Use after free in ANGLE in Google Chrome prior to 83.0.4103.97 allowed a remote ... Use after free in ANGLE in Google Chrome prior to 83.0.4103.97 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. Scope: local bookworm: resolved (fixed in 83.0.4103.106-1) bullseye: resolved (fixed in 83.0.4103.106-1) forky: resolved (fixed in 83.0.4103.106-1) sid: resolved (fixed in 83.0.4103.106-1) trixie: resolved (fixe
debian
CVE-2019-5756P3HIGHCVSS 8.8fixed in chromium 72.0.3626.81-1 (bookworm)2019
CVE-2019-5756 [HIGH] CVE-2019-5756: chromium - Inappropriate memory management when caching in PDFium in Google Chrome prior to... Inappropriate memory management when caching in PDFium in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. Scope: local bookworm: resolved (fixed in 72.0.3626.81-1) bullseye: resolved (fixed in 72.0.3626.81-1) forky: resolved (fixed in 72.0.3626.81-1) sid: resolved (fixed in 72.0.3626.81-
debian
CVE-2019-5762P3HIGHCVSS 8.8fixed in chromium 72.0.3626.81-1 (bookworm)2019
CVE-2019-5762 [HIGH] CVE-2019-5762: chromium - Inappropriate memory management when caching in PDFium in Google Chrome prior to... Inappropriate memory management when caching in PDFium in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. Scope: local bookworm: resolved (fixed in 72.0.3626.81-1) bullseye: resolved (fixed in 72.0.3626.81-1) forky: resolved (fixed in 72.0.3626.81-1) sid: resolved (fixed in 72.0.3626.81-
debian
CVE-2020-15972P3HIGHCVSS 8.8fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-15972 [HIGH] CVE-2020-15972: chromium - Use after free in audio in Google Chrome prior to 86.0.4240.75 allowed a remote ... Use after free in audio in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 87.0.4280.88-0.1) bullseye: resolved (fixed in 87.0.4280.88-0.1) forky: resolved (fixed in 87.0.4280.88-0.1) sid: resolved (fixed in 87.0.4280.88-0.1) trixie: resolved (fix
debian
CVE-2021-30591P3HIGHCVSS 8.8fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30591 [HIGH] CVE-2021-30591: chromium - Use after free in File System API in Google Chrome prior to 92.0.4515.131 allowe... Use after free in File System API in Google Chrome prior to 92.0.4515.131 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 93.0.4577.82-1) bullseye: resolved (fixed in 93.0.4577.82-1) forky: resolved (fixed in 93.0.4577.82-1) sid: resolved (fixed in 93.0.4577.82-1) trixie: resolved (
debian
CVE-2021-30604P3HIGHCVSS 8.8fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30604 [HIGH] CVE-2021-30604: chromium - Use after free in ANGLE in Google Chrome prior to 92.0.4515.159 allowed a remote... Use after free in ANGLE in Google Chrome prior to 92.0.4515.159 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 93.0.4577.82-1) bullseye: resolved (fixed in 93.0.4577.82-1) forky: resolved (fixed in 93.0.4577.82-1) sid: resolved (fixed in 93.0.4577.82-1) trixie: resolved (fixed in 9
debian
CVE-2024-7024P3CRITICALCVSS 9.6fixed in chromium 126.0.6478.56-1~deb12u1 (bookworm)2024
CVE-2024-7024 [CRITICAL] CVE-2024-7024: chromium - Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.54 allow... Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low) Scope: local bookworm: resolved (fixed in 126.0.6478.56-1~deb12u1) bullseye: open forky: resolved (fixed in 126.0.6478.56-1) sid: resolved (fixed in 126.0.6478.56-1)
debian
CVE-2019-25154P3CRITICALCVSS 9.6fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-25154 [CRITICAL] CVE-2019-25154: chromium - Inappropriate implementation in iframe in Google Chrome prior to 77.0.3865.75 al... Inappropriate implementation in iframe in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 78.0.3904.87-1) bullseye: resolved (fixed in 78.0.3904.87-1) forky: resolved (fixed in 78.0.3904.87-1) sid: resolve
debian
CVE-2021-4057P3HIGHCVSS 8.8fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-4057 [HIGH] CVE-2021-4057: chromium - Use after free in file API in Google Chrome prior to 96.0.4664.93 allowed a remo... Use after free in file API in Google Chrome prior to 96.0.4664.93 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 97.0.4692.71-0.1) bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1) forky: resolved (fixed in 97.0.4692.71-0.1) sid: resolved
debian
CVE-2021-30513P3HIGHCVSS 8.8fixed in chromium 90.0.4430.212-1 (bookworm)2021
CVE-2021-30513 [HIGH] CVE-2021-30513: chromium - Type confusion in V8 in Google Chrome prior to 90.0.4430.212 allowed a remote at... Type confusion in V8 in Google Chrome prior to 90.0.4430.212 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 90.0.4430.212-1) bullseye: resolved (fixed in 90.0.4430.212-1) forky: resolved (fixed in 90.0.4430.212-1) sid: resolved (fixed in 90.0.4430.212-1) trixie: resolved (fixed in
debian
CVE-2021-30601P3HIGHCVSS 8.8fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30601 [HIGH] CVE-2021-30601: chromium - Use after free in Extensions API in Google Chrome prior to 92.0.4515.159 allowed... Use after free in Extensions API in Google Chrome prior to 92.0.4515.159 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 93.0.4577.82-1) bullseye: resolved (fixed in 93.0.4577.82-1) forky: resolved (fixed in 93.0.4577.82-1) sid: resolv
debian
CVE-2022-3656P3HIGHCVSS 8.8fixed in chromium 107.0.5304.68-1 (bookworm)2022
CVE-2022-3656 [HIGH] CVE-2022-3656: chromium - Insufficient data validation in File System in Google Chrome prior to 107.0.5304... Insufficient data validation in File System in Google Chrome prior to 107.0.5304.62 allowed a remote attacker to bypass file system restrictions via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 107.0.5304.68-1) bullseye: resolved (fixed in 107.0.5304.68-1~deb11u1) forky: resolved (fixed in 107.0.5304.68-1) sid: r
debian
CVE-2020-15962P3HIGHCVSS 8.8fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-15962 [HIGH] CVE-2020-15962: chromium - Insufficient policy validation in serial in Google Chrome prior to 85.0.4183.121... Insufficient policy validation in serial in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. Scope: local bookworm: resolved (fixed in 87.0.4280.88-0.1) bullseye: resolved (fixed in 87.0.4280.88-0.1) forky: resolved (fixed in 87.0.4280.88-0.1) sid: resolved (fixed in 87.0.4280
debian
CVE-2022-2415P3HIGHCVSS 8.8fixed in chromium 103.0.5060.53-1 (bookworm)2022
CVE-2022-2415 [HIGH] CVE-2022-2415: chromium - Heap buffer overflow in WebGL in Google Chrome prior to 103.0.5060.53 allowed a ... Heap buffer overflow in WebGL in Google Chrome prior to 103.0.5060.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 103.0.5060.53-1) bullseye: resolved (fixed in 103.0.5060.53-1~deb11u1) forky: resolved (fixed in 103.0.5060.53-1) sid: resolved (fixed in 103.0.5060.53-1) trixie: reso
debian
CVE-2022-1134P3HIGHCVSS 8.8fixed in chromium 100.0.4896.60-1 (bookworm)2022
CVE-2022-1134 [HIGH] CVE-2022-1134: chromium - Type confusion in V8 in Google Chrome prior to 100.0.4896.60 allowed a remote at... Type confusion in V8 in Google Chrome prior to 100.0.4896.60 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 100.0.4896.60-1) bullseye: resolved (fixed in 100.0.4896.60-1~deb11u1) forky: resolved (fixed in 100.0.4896.60-1) sid: resolved (fixed in 100.0.4896.60-1) trixie: resolved (fix
debian
CVE-2021-30578P3HIGHCVSS 8.8fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30578 [HIGH] CVE-2021-30578: chromium - Uninitialized use in Media in Google Chrome prior to 92.0.4515.107 allowed a rem... Uninitialized use in Media in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. Scope: local bookworm: resolved (fixed in 93.0.4577.82-1) bullseye: resolved (fixed in 93.0.4577.82-1) forky: resolved (fixed in 93.0.4577.82-1) sid: resolved (fixed in 93.0.4577.82-1) trixie: resolved (fixed i
debian
CVE-2021-30566P3HIGHCVSS 8.8fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30566 [HIGH] CVE-2021-30566: chromium - Stack buffer overflow in Printing in Google Chrome prior to 92.0.4515.107 allowe... Stack buffer overflow in Printing in Google Chrome prior to 92.0.4515.107 allowed a remote attacker who had compromised the renderer process to potentially exploit stack corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 93.0.4577.82-1) bullseye: resolved (fixed in 93.0.4577.82-1) forky: resolved (fixed in 93.0.4577.82-1) sid: resolved (f
debian
CVE-2022-0797P3HIGHCVSS 8.8fixed in chromium 99.0.4844.51-1 (bookworm)2022
CVE-2022-0797 [HIGH] CVE-2022-0797: chromium - Out of bounds memory access in Mojo in Google Chrome prior to 99.0.4844.51 allow... Out of bounds memory access in Mojo in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. Scope: local bookworm: resolved (fixed in 99.0.4844.51-1) bullseye: resolved (fixed in 99.0.4844.51-1~deb11u1) forky: resolved (fixed in 99.0.4844.51-1) sid: resolved (fixed in 99.0.4844.51-1) trixie: r
debian
Debian Chromium vulnerabilities | cvebase