cbcvebase.

Debian Chromium vulnerabilities

2,134 known vulnerabilities affecting debian/chromium.

Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8

Vulnerabilities

Page 22 of 107
CVE-2024-3837P3HIGHCVSS 8.8fixed in chromium 124.0.6367.60-1~deb12u1 (bookworm)2024
CVE-2024-3837 [HIGH] CVE-2024-3837: chromium - Use after free in QUIC in Google Chrome prior to 124.0.6367.60 allowed a remote ... Use after free in QUIC in Google Chrome prior to 124.0.6367.60 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 124.0.6367.60-1~deb12u1) bullseye: open forky: resolved (fixed in 124.0.6367.60-1) sid: resolved
debian
CVE-2023-6351P3HIGHCVSS 8.8fixed in chromium 119.0.6045.199-1~deb12u1 (bookworm)2023
CVE-2023-6351 [HIGH] CVE-2023-6351: chromium - Use after free in libavif in Google Chrome prior to 119.0.6045.199 allowed a rem... Use after free in libavif in Google Chrome prior to 119.0.6045.199 allowed a remote attacker to potentially exploit heap corruption via a crafted avif file. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 119.0.6045.199-1~deb12u1) bullseye: resolved (fixed in 119.0.6045.199-1~deb11u1) forky: resolved (fixed in 119.0.6045.199-1) sid: resol
debian
CVE-2024-1060P3HIGHCVSS 8.8fixed in chromium 121.0.6167.139-1~deb12u1 (bookworm)2024
CVE-2024-1060 [HIGH] CVE-2024-1060: chromium - Use after free in Canvas in Google Chrome prior to 121.0.6167.139 allowed a remo... Use after free in Canvas in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 121.0.6167.139-1~deb12u1) bullseye: open forky: resolved (fixed in 121.0.6167.139-1) sid: resolved (fixed in 121.0.6167.139-1) trixie: r
debian
CVE-2024-12053P3HIGHCVSS 8.8fixed in chromium 131.0.6778.108-1~deb12u1 (bookworm)2024
CVE-2024-12053 [HIGH] CVE-2024-12053: chromium - Type Confusion in V8 in Google Chrome prior to 131.0.6778.108 allowed a remote a... Type Confusion in V8 in Google Chrome prior to 131.0.6778.108 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 131.0.6778.108-1~deb12u1) bullseye: open forky: resolved (fixed in 131.0.6778.108-1) sid: resolved (fixed in 131.0.6778.108-1) trixie: r
debian
CVE-2025-2476P3HIGHCVSS 8.8fixed in chromium 134.0.6998.117-1~deb12u1 (bookworm)2025
CVE-2025-2476 [HIGH] CVE-2025-2476: chromium - Use after free in Lens in Google Chrome prior to 134.0.6998.117 allowed a remote... Use after free in Lens in Google Chrome prior to 134.0.6998.117 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical) Scope: local bookworm: resolved (fixed in 134.0.6998.117-1~deb12u1) bullseye: open forky: resolved (fixed in 134.0.6998.117-1) sid: resolved (fixed in 134.0.6998.117-1) trixie:
debian
CVE-2024-7532P3HIGHCVSS 8.8fixed in chromium 127.0.6533.99-1~deb12u1 (bookworm)2024
CVE-2024-7532 [HIGH] CVE-2024-7532: chromium - Out of bounds memory access in ANGLE in Google Chrome prior to 127.0.6533.99 all... Out of bounds memory access in ANGLE in Google Chrome prior to 127.0.6533.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical) Scope: local bookworm: resolved (fixed in 127.0.6533.99-1~deb12u1) bullseye: open forky: resolved (fixed in 127.0.6533.99-1) sid: resolved (fixed in 127.0.6533.99-
debian
CVE-2024-6101P3HIGHCVSS 8.8fixed in chromium 126.0.6478.114-1~deb12u1 (bookworm)2024
CVE-2024-6101 [HIGH] CVE-2024-6101: chromium - Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.114 allo... Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.114 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 126.0.6478.114-1~deb12u1) bullseye: open forky: resolved (fixed in 126.0.6478.114-1) sid: resolved (fixed in 126.0.6478.114-1)
debian
CVE-2024-2627P3HIGHCVSS 8.8fixed in chromium 123.0.6312.86-1~deb12u1 (bookworm)2024
CVE-2024-2627 [HIGH] CVE-2024-2627: chromium - Use after free in Canvas in Google Chrome prior to 123.0.6312.58 allowed a remot... Use after free in Canvas in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 123.0.6312.86-1~deb12u1) bullseye: open forky: resolved (fixed in 123.0.6312.58-1) sid: resolved (fixed in 123.0.6312.58-1) trixie: res
debian
CVE-2024-3158P3HIGHCVSS 8.8fixed in chromium 123.0.6312.105-1~deb12u1 (bookworm)2024
CVE-2024-3158 [HIGH] CVE-2024-3158: chromium - Use after free in Bookmarks in Google Chrome prior to 123.0.6312.105 allowed a r... Use after free in Bookmarks in Google Chrome prior to 123.0.6312.105 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 123.0.6312.105-1~deb12u1) bullseye: open forky: resolved (fixed in 123.0.6312.105-1) sid: resolved (fixed in 123.0.6312.105-1) trixie
debian
CVE-2024-9955P3HIGHCVSS 8.8fixed in chromium 130.0.6723.58-1~deb12u1 (bookworm)2024
CVE-2024-9955 [HIGH] CVE-2024-9955: chromium - Use after free in WebAuthentication in Google Chrome prior to 130.0.6723.58 allo... Use after free in WebAuthentication in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 130.0.6723.58-1~deb12u1) bullseye: open forky: resolved (fixed in 130.0.6723.58-1) sid: resolved (fixed in 130.0.6723.58-1)
debian
CVE-2024-5497P3HIGHCVSS 8.8fixed in chromium 125.0.6422.141-1~deb12u1 (bookworm)2024
CVE-2024-5497 [HIGH] CVE-2024-5497: chromium - Out of bounds memory access in Browser UI in Google Chrome prior to 125.0.6422.1... Out of bounds memory access in Browser UI in Google Chrome prior to 125.0.6422.141 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 125.0.6422.141-1~deb12u1) bullseye: open forky: resolved (fixed
debian
CVE-2024-2400P3HIGHCVSS 8.8fixed in chromium 122.0.6261.128-1~deb12u1 (bookworm)2024
CVE-2024-2400 [HIGH] CVE-2024-2400: chromium - Use after free in Performance Manager in Google Chrome prior to 122.0.6261.128 a... Use after free in Performance Manager in Google Chrome prior to 122.0.6261.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 122.0.6261.128-1~deb12u1) bullseye: open forky: resolved (fixed in 122.0.6261.128-1) sid: resolved (fixed in 122.0.6261.128
debian
CVE-2024-6102P3HIGHCVSS 8.8fixed in chromium 126.0.6478.114-1~deb12u1 (bookworm)2024
CVE-2024-6102 [HIGH] CVE-2024-6102: chromium - Out of bounds memory access in Dawn in Google Chrome prior to 126.0.6478.114 all... Out of bounds memory access in Dawn in Google Chrome prior to 126.0.6478.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 126.0.6478.114-1~deb12u1) bullseye: open forky: resolved (fixed in 126.0.6478.114-1) sid: resolved (fixed in 126.0.6478.114-1
debian
CVE-2024-5495P3HIGHCVSS 8.8fixed in chromium 125.0.6422.141-1~deb12u1 (bookworm)2024
CVE-2024-5495 [HIGH] CVE-2024-5495: chromium - Use after free in Dawn in Google Chrome prior to 125.0.6422.141 allowed a remote... Use after free in Dawn in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 125.0.6422.141-1~deb12u1) bullseye: open forky: resolved (fixed in 125.0.6422.141-1) sid: resolved (fixed in 125.0.6422.141-1) trixie: res
debian
CVE-2022-4918P3HIGHCVSS 8.8fixed in chromium 102.0.5005.61-1 (bookworm)2022
CVE-2022-4918 [HIGH] CVE-2022-4918: chromium - Use after free in UI in Google Chrome prior to 102.0.5005.61 allowed a remote at... Use after free in UI in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 102.0.5005.61-1) bullseye: resolved (fixed in 102.0.5005.61-1~deb11u1) forky: resolved (fixed in 102.0.5005.61-1) sid: resolved (fixed in 102.0.50
debian
CVE-2022-4919P3HIGHCVSS 8.8fixed in chromium 101.0.4951.41-1 (bookworm)2022
CVE-2022-4919 [HIGH] CVE-2022-4919: chromium - Use after free in Base Internals in Google Chrome prior to 101.0.4951.41 allowed... Use after free in Base Internals in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 101.0.4951.41-1) bullseye: resolved (fixed in 101.0.4951.41-1~deb11u1) forky: resolved (fixed in 101.0.4951.41-1) sid: resolved (fixed i
debian
CVE-2022-4916P3HIGHCVSS 8.8fixed in chromium 103.0.5060.53-1 (bookworm)2022
CVE-2022-4916 [HIGH] CVE-2022-4916: chromium - Use after free in Media in Google Chrome prior to 103.0.5060.53 allowed a remote... Use after free in Media in Google Chrome prior to 103.0.5060.53 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 103.0.5060.53-1) bullseye: resolved (fixed in 103.0.5060.53-1~deb11u1) forky: resolved (fixed in 103.0.5060.53-1) sid: resolved (fixed in 103.0.5
debian
CVE-2024-5494P3HIGHCVSS 8.8fixed in chromium 125.0.6422.141-1~deb12u1 (bookworm)2024
CVE-2024-5494 [HIGH] CVE-2024-5494: chromium - Use after free in Dawn in Google Chrome prior to 125.0.6422.141 allowed a remote... Use after free in Dawn in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 125.0.6422.141-1~deb12u1) bullseye: open forky: resolved (fixed in 125.0.6422.141-1) sid: resolved (fixed in 125.0.6422.141-1) trixie: res
debian
CVE-2022-4921P3HIGHCVSS 8.8fixed in chromium 99.0.4844.51-1 (bookworm)2022
CVE-2022-4921 [HIGH] CVE-2022-4921: chromium - Use after free in Accessibility in Google Chrome prior to 99.0.4844.51 allowed a... Use after free in Accessibility in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: Low) Scope: local bookworm: resolved (fixed in 99.0.4844.51-1) bullseye: resolved (fixed in 99.0.4844.51-1~deb11u1) forky: resolved
debian
CVE-2021-4317P3HIGHCVSS 8.8fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-4317 [HIGH] CVE-2021-4317: chromium - Use after free in ANGLE in Google Chrome prior to 96.0.4664.93 allowed a remote ... Use after free in ANGLE in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 97.0.4692.71-0.1) bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1) forky: resolved (fixed in 97.0.4692.71-0.1) sid: resolved (fixed in 97.0.
debian
Debian Chromium vulnerabilities | cvebase