cbcvebase.

Debian Chromium vulnerabilities

2,134 known vulnerabilities affecting debian/chromium.

Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8

Vulnerabilities

Page 21 of 107
CVE-2021-30575P3HIGHCVSS 8.8fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30575 [HIGH] CVE-2021-30575: chromium - Out of bounds write in Autofill in Google Chrome prior to 92.0.4515.107 allowed ... Out of bounds write in Autofill in Google Chrome prior to 92.0.4515.107 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 93.0.4577.82-1) bullseye: resolved (fixed in 93.0.4577.82-1) forky: resolved (fixed in 93.0.4577.82-1) sid: resolved (fixe
debian
CVE-2020-6537P3HIGHCVSS 8.8fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-6537 [HIGH] CVE-2020-6537: chromium - Type confusion in V8 in Google Chrome prior to 84.0.4147.105 allowed a remote at... Type confusion in V8 in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. Scope: local bookworm: resolved (fixed in 87.0.4280.88-0.1) bullseye: resolved (fixed in 87.0.4280.88-0.1) forky: resolved (fixed in 87.0.4280.88-0.1) sid: resolved (fixed in 87.0.4280.88-0.1) trixie: resolved (fix
debian
CVE-2023-2934P3HIGHCVSS 8.8fixed in chromium 114.0.5735.90-2~deb12u1 (bookworm)2023
CVE-2023-2934 [HIGH] CVE-2023-2934: chromium - Out of bounds memory access in Mojo in Google Chrome prior to 114.0.5735.90 allo... Out of bounds memory access in Mojo in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 114.0.5735.90-2~deb12u1) bullseye: resolved (fixed in 114.0.5735.90-2~deb11u1) forky: resolved (fixed in 114.0.5735.90-1) sid:
debian
CVE-2023-4071P3HIGHCVSS 8.8fixed in chromium 115.0.5790.170-1~deb12u1 (bookworm)2023
CVE-2023-4071 [HIGH] CVE-2023-4071: chromium - Heap buffer overflow in Visuals in Google Chrome prior to 115.0.5790.170 allowed... Heap buffer overflow in Visuals in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 115.0.5790.170-1~deb12u1) bullseye: resolved (fixed in 115.0.5790.170-1~deb11u1) forky: resolved (fixed in 115.0.5790.170-1) sid:
debian
CVE-2023-5218P3HIGHCVSS 8.8fixed in chromium 118.0.5993.70-1~deb12u1 (bookworm)2023
CVE-2023-5218 [HIGH] CVE-2023-5218: chromium - Use after free in Site Isolation in Google Chrome prior to 118.0.5993.70 allowed... Use after free in Site Isolation in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical) Scope: local bookworm: resolved (fixed in 118.0.5993.70-1~deb12u1) bullseye: resolved (fixed in 118.0.5993.70-1~deb11u1) forky: resolved (fixed in 118.0.5993.70-1) sid
debian
CVE-2023-4073P3HIGHCVSS 8.8fixed in chromium 115.0.5790.170-1~deb12u1 (bookworm)2023
CVE-2023-4073 [HIGH] CVE-2023-4073: chromium - Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 115.0.5790... Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 115.0.5790.170 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 115.0.5790.170-1~deb12u1) bullseye: resolved (fixed in 115.0.5790.170-1~deb11u1) forky: resolved (fixed in 115.0.5790
debian
CVE-2024-3832P3HIGHCVSS 8.8fixed in chromium 124.0.6367.60-1~deb12u1 (bookworm)2024
CVE-2024-3832 [HIGH] CVE-2024-3832: chromium - Object corruption in V8 in Google Chrome prior to 124.0.6367.60 allowed a remote... Object corruption in V8 in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 124.0.6367.60-1~deb12u1) bullseye: open forky: resolved (fixed in 124.0.6367.60-1) sid: resolved (fixed in 124.0.6367.60-1) trixie: reso
debian
CVE-2023-4075P3HIGHCVSS 8.8fixed in chromium 115.0.5790.170-1~deb12u1 (bookworm)2023
CVE-2023-4075 [HIGH] CVE-2023-4075: chromium - Use after free in Cast in Google Chrome prior to 115.0.5790.170 allowed a remote... Use after free in Cast in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 115.0.5790.170-1~deb12u1) bullseye: resolved (fixed in 115.0.5790.170-1~deb11u1) forky: resolved (fixed in 115.0.5790.170-1) sid: resolved
debian
CVE-2023-4763P3HIGHCVSS 8.8fixed in chromium 116.0.5845.180-1~deb12u1 (bookworm)2023
CVE-2023-4763 [HIGH] CVE-2023-4763: chromium - Use after free in Networks in Google Chrome prior to 116.0.5845.179 allowed a re... Use after free in Networks in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 116.0.5845.180-1~deb12u1) bullseye: resolved (fixed in 116.0.5845.180-1~deb11u1) forky: resolved (fixed in 116.0.5845.180-1) sid: reso
debian
CVE-2023-3421P3HIGHCVSS 8.8fixed in chromium 114.0.5735.198-1~deb12u1 (bookworm)2023
CVE-2023-3421 [HIGH] CVE-2023-3421: chromium - Use after free in Media in Google Chrome prior to 114.0.5735.198 allowed a remot... Use after free in Media in Google Chrome prior to 114.0.5735.198 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 114.0.5735.198-1~deb12u1) bullseye: resolved (fixed in 114.0.5735.198-1~deb11u1) forky: resolved (fixed in 114.0.5735.198-1) sid: resolve
debian
CVE-2023-6350P3HIGHCVSS 8.8fixed in chromium 119.0.6045.199-1~deb12u1 (bookworm)2023
CVE-2023-6350 [HIGH] CVE-2023-6350: chromium - Use after free in libavif in Google Chrome prior to 119.0.6045.199 allowed a rem... Use after free in libavif in Google Chrome prior to 119.0.6045.199 allowed a remote attacker to potentially exploit heap corruption via a crafted avif file. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 119.0.6045.199-1~deb12u1) bullseye: resolved (fixed in 119.0.6045.199-1~deb11u1) forky: resolved (fixed in 119.0.6045.199-1) sid: resol
debian
CVE-2024-4368P3HIGHCVSS 8.8fixed in chromium 124.0.6367.118-1~deb12u1 (bookworm)2024
CVE-2024-4368 [HIGH] CVE-2024-4368: chromium - Use after free in Dawn in Google Chrome prior to 124.0.6367.118 allowed a remote... Use after free in Dawn in Google Chrome prior to 124.0.6367.118 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 124.0.6367.118-1~deb12u1) bullseye: open forky: resolved (fixed in 124.0.6367.118-1) sid: resolved (fixed in 124.0.6367.118-1) trixie: res
debian
CVE-2024-3834P3HIGHCVSS 8.8fixed in chromium 124.0.6367.60-1~deb12u1 (bookworm)2024
CVE-2024-3834 [HIGH] CVE-2024-3834: chromium - Use after free in Downloads in Google Chrome prior to 124.0.6367.60 allowed a re... Use after free in Downloads in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 124.0.6367.60-1~deb12u1) bullseye: open forky: resolved (fixed in 124.0.6367.60-1) sid: resolved (fixed in 124.0.6367.60-1) trixie: re
debian
CVE-2022-4907P3HIGHCVSS 8.8fixed in chromium 108.0.5359.71-1 (bookworm)2022
CVE-2022-4907 [HIGH] CVE-2022-4907: chromium - Uninitialized Use in FFmpeg in Google Chrome prior to 108.0.5359.71 allowed a re... Uninitialized Use in FFmpeg in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 108.0.5359.71-1) bullseye: resolved (fixed in 108.0.5359.71-2~deb11u1) forky: resolved (fixed in 108.0.5359.71-1) sid: resolved
debian
CVE-2024-0225P3HIGHCVSS 8.8fixed in chromium 120.0.6099.199-1~deb12u1 (bookworm)2024
CVE-2024-0225 [HIGH] CVE-2024-0225: chromium - Use after free in WebGPU in Google Chrome prior to 120.0.6099.199 allowed a remo... Use after free in WebGPU in Google Chrome prior to 120.0.6099.199 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 120.0.6099.199-1~deb12u1) bullseye: resolved (fixed in 120.0.6099.199-1~deb11u1) forky: resolved (fixed in 120.0.6099.199-1) sid: resolv
debian
CVE-2024-0224P3HIGHCVSS 8.8fixed in chromium 120.0.6099.199-1~deb12u1 (bookworm)2024
CVE-2024-0224 [HIGH] CVE-2024-0224: chromium - Use after free in WebAudio in Google Chrome prior to 120.0.6099.199 allowed a re... Use after free in WebAudio in Google Chrome prior to 120.0.6099.199 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 120.0.6099.199-1~deb12u1) bullseye: resolved (fixed in 120.0.6099.199-1~deb11u1) forky: resolved (fixed in 120.0.6099.199-1) sid: reso
debian
CVE-2023-5997P3HIGHCVSS 8.8fixed in chromium 119.0.6045.159-1~deb12u1 (bookworm)2023
CVE-2023-5997 [HIGH] CVE-2023-5997: chromium - Use after free in Garbage Collection in Google Chrome prior to 119.0.6045.159 al... Use after free in Garbage Collection in Google Chrome prior to 119.0.6045.159 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 119.0.6045.159-1~deb12u1) bullseye: resolved (fixed in 119.0.6045.159-1~deb11u1) forky: resolved (fixed in 119.0.6045.159-1)
debian
CVE-2023-6346P3HIGHCVSS 8.8fixed in chromium 119.0.6045.199-1~deb12u1 (bookworm)2023
CVE-2023-6346 [HIGH] CVE-2023-6346: chromium - Use after free in WebAudio in Google Chrome prior to 119.0.6045.199 allowed a re... Use after free in WebAudio in Google Chrome prior to 119.0.6045.199 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 119.0.6045.199-1~deb12u1) bullseye: resolved (fixed in 119.0.6045.199-1~deb11u1) forky: resolved (fixed in 119.0.6045.199-1) sid: reso
debian
CVE-2024-1669P3HIGHCVSS 8.8fixed in chromium 122.0.6261.57-1~deb12u1 (bookworm)2024
CVE-2024-1669 [HIGH] CVE-2024-1669: chromium - Out of bounds memory access in Blink in Google Chrome prior to 122.0.6261.57 all... Out of bounds memory access in Blink in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 122.0.6261.57-1~deb12u1) bullseye: open forky: resolved (fixed in 122.0.6261.57-1) sid: resolved (fixed in 122.0.6261.57-1) t
debian
CVE-2024-0518P3HIGHCVSS 8.8fixed in chromium 120.0.6099.224-1~deb12u1 (bookworm)2024
CVE-2024-0518 [HIGH] CVE-2024-0518: chromium - Type confusion in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote a... Type confusion in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 120.0.6099.224-1~deb12u1) bullseye: resolved (fixed in 120.0.6099.224-1~deb11u1) forky: resolved (fixed in 120.0.6099.224-1) sid: resolved (
debian
Debian Chromium vulnerabilities | cvebase