cbcvebase.

Debian Chromium vulnerabilities

2,134 known vulnerabilities affecting debian/chromium.

Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8

Vulnerabilities

Page 28 of 107
CVE-2024-0222P3HIGHCVSS 8.8fixed in chromium 120.0.6099.199-1~deb12u1 (bookworm)2024
CVE-2024-0222 [HIGH] CVE-2024-0222: chromium - Use after free in ANGLE in Google Chrome prior to 120.0.6099.199 allowed a remot... Use after free in ANGLE in Google Chrome prior to 120.0.6099.199 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 120.0.6099.199-1~deb12u1) bullseye: resolved (fixed in 120.0.6099.199-1~deb11u1) forky: resolved
debian
CVE-2023-3732P3HIGHCVSS 8.8fixed in chromium 115.0.5790.98-1~deb12u1 (bookworm)2023
CVE-2023-3732 [HIGH] CVE-2023-3732: chromium - Out of bounds memory access in Mojo in Google Chrome prior to 115.0.5790.98 allo... Out of bounds memory access in Mojo in Google Chrome prior to 115.0.5790.98 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 115.0.5790.98-1~deb12u1) bullseye: resolved (fixed in 115.0.5790.98-1~deb11u1) forky:
debian
CVE-2023-6508P3HIGHCVSS 8.8fixed in chromium 120.0.6099.71-1~deb12u1 (bookworm)2023
CVE-2023-6508 [HIGH] CVE-2023-6508: chromium - Use after free in Media Stream in Google Chrome prior to 120.0.6099.62 allowed a... Use after free in Media Stream in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 120.0.6099.71-1~deb12u1) bullseye: resolved (fixed in 120.0.6099.71-1~deb11u1) forky: resolved (fixed in 120.0.6099.71-1) sid: reso
debian
CVE-2023-6348P3HIGHCVSS 8.8fixed in chromium 119.0.6045.199-1~deb12u1 (bookworm)2023
CVE-2023-6348 [HIGH] CVE-2023-6348: chromium - Type Confusion in Spellcheck in Google Chrome prior to 119.0.6045.199 allowed a ... Type Confusion in Spellcheck in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 119.0.6045.199-1~deb12u1) bullseye: resolved (fixed in 119.0.6045.199-1~deb11u1) forky: res
debian
CVE-2023-5186P3HIGHCVSS 8.8fixed in chromium 117.0.5938.132-1~deb12u1 (bookworm)2023
CVE-2023-5186 [HIGH] CVE-2023-5186: chromium - Use after free in Passwords in Google Chrome prior to 117.0.5938.132 allowed a r... Use after free in Passwords in Google Chrome prior to 117.0.5938.132 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via crafted UI interaction. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 117.0.5938.132-1~deb12u1) bullseye: resolved (fixed in 117.0.5938.132-1~
debian
CVE-2023-4429P3HIGHCVSS 8.8fixed in chromium 116.0.5845.110-1~deb12u1 (bookworm)2023
CVE-2023-4429 [HIGH] CVE-2023-4429: chromium - Use after free in Loader in Google Chrome prior to 116.0.5845.110 allowed a remo... Use after free in Loader in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 116.0.5845.110-1~deb12u1) bullseye: resolved (fixed in 116.0.5845.110-1~deb11u1) forky: resolved (fixed in 116.0.5845.110-1) sid: resolv
debian
CVE-2023-3216P3HIGHCVSS 8.8fixed in chromium 114.0.5735.133-1~deb12u1 (bookworm)2023
CVE-2023-3216 [HIGH] CVE-2023-3216: chromium - Type confusion in V8 in Google Chrome prior to 114.0.5735.133 allowed a remote a... Type confusion in V8 in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 114.0.5735.133-1~deb12u1) bullseye: resolved (fixed in 114.0.5735.133-1~deb11u1) forky: resolved (fixed in 114.0.5735.133-1) sid: resolved (
debian
CVE-2024-1059P3HIGHCVSS 8.8fixed in chromium 121.0.6167.139-1~deb12u1 (bookworm)2024
CVE-2024-1059 [HIGH] CVE-2024-1059: chromium - Use after free in Peer Connection in Google Chrome prior to 121.0.6167.139 allow... Use after free in Peer Connection in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially exploit stack corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 121.0.6167.139-1~deb12u1) bullseye: open forky: resolved (fixed in 121.0.6167.139-1) sid: resolved (fixed in 121.0.6167.139-1)
debian
CVE-2024-1077P3HIGHCVSS 8.8fixed in chromium 121.0.6167.139-1~deb12u1 (bookworm)2024
CVE-2024-1077 [HIGH] CVE-2024-1077: chromium - Use after free in Network in Google Chrome prior to 121.0.6167.139 allowed a rem... Use after free in Network in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially exploit heap corruption via a malicious file. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 121.0.6167.139-1~deb12u1) bullseye: open forky: resolved (fixed in 121.0.6167.139-1) sid: resolved (fixed in 121.0.6167.139-1) trixie: res
debian
CVE-2024-5830P3HIGHCVSS 8.8fixed in chromium 126.0.6478.56-1~deb12u1 (bookworm)2024
CVE-2024-5830 [HIGH] CVE-2024-5830: chromium - Type Confusion in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote at... Type Confusion in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 126.0.6478.56-1~deb12u1) bullseye: open forky: resolved (fixed in 126.0.6478.56-1) sid: resolved (fixed in 126.0.6478.56-1) trixie: resolve
debian
CVE-2024-6990P3HIGHCVSS 8.8fixed in chromium 127.0.6533.88-1~deb12u1 (bookworm)2024
CVE-2024-6990 [HIGH] CVE-2024-6990: chromium - Uninitialized Use in Dawn in Google Chrome on Android prior to 127.0.6533.88 all... Uninitialized Use in Dawn in Google Chrome on Android prior to 127.0.6533.88 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Critical) Scope: local bookworm: resolved (fixed in 127.0.6533.88-1~deb12u1) bullseye: open forky: resolved (fixed in 127.0.6533.88-1) sid: resolved (fixed in 12
debian
CVE-2023-4572P3HIGHCVSS 8.8fixed in chromium 116.0.5845.140-1~deb12u1 (bookworm)2023
CVE-2023-4572 [HIGH] CVE-2023-4572: chromium - Use after free in MediaStream in Google Chrome prior to 116.0.5845.140 allowed a... Use after free in MediaStream in Google Chrome prior to 116.0.5845.140 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 116.0.5845.140-1~deb12u1) bullseye: resolved (fixed in 116.0.5845.140-1~deb11u1) forky: resolved (fixed in 116.0.5845.140-1) sid: r
debian
CVE-2023-5476P3HIGHCVSS 8.8fixed in chromium 118.0.5993.70-1~deb12u1 (bookworm)2023
CVE-2023-5476 [HIGH] CVE-2023-5476: chromium - Use after free in Blink History in Google Chrome prior to 118.0.5993.70 allowed ... Use after free in Blink History in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 118.0.5993.70-1~deb12u1) bullseye: resolved (fixed in 118.0.5993.70-1~deb11u1) forky: resolved (fixed in 118.0.5993.70-1) sid: r
debian
CVE-2023-5474P3HIGHCVSS 8.8fixed in chromium 118.0.5993.70-1~deb12u1 (bookworm)2023
CVE-2023-5474 [HIGH] CVE-2023-5474: chromium - Heap buffer overflow in PDF in Google Chrome prior to 118.0.5993.70 allowed a re... Heap buffer overflow in PDF in Google Chrome prior to 118.0.5993.70 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 118.0.5993.70-1~deb12u1) bullseye: resolved (fixed in 118.0.5993.70-1~de
debian
CVE-2024-1938P3HIGHCVSS 8.8fixed in chromium 122.0.6261.94-1~deb12u1 (bookworm)2024
CVE-2024-1938 [HIGH] CVE-2024-1938: chromium - Type Confusion in V8 in Google Chrome prior to 122.0.6261.94 allowed a remote at... Type Confusion in V8 in Google Chrome prior to 122.0.6261.94 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 122.0.6261.94-1~deb12u1) bullseye: open forky: resolved (fixed in 122.0.6261.94-1) sid: resolved (fixed in 122.0.6261.94-1) trixie: resolve
debian
CVE-2023-4349P3HIGHCVSS 8.8fixed in chromium 116.0.5845.96-1~deb12u1 (bookworm)2023
CVE-2023-4349 [HIGH] CVE-2023-4349: chromium - Use after free in Device Trust Connectors in Google Chrome prior to 116.0.5845.9... Use after free in Device Trust Connectors in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 116.0.5845.96-1~deb12u1) bullseye: resolved (fixed in 116.0.5845.96-1~deb11u1) forky: resolved (fixed in 116.0.5845.96-1
debian
CVE-2023-4351P3HIGHCVSS 8.8fixed in chromium 116.0.5845.96-1~deb12u1 (bookworm)2023
CVE-2023-4351 [HIGH] CVE-2023-4351: chromium - Use after free in Network in Google Chrome prior to 116.0.5845.96 allowed a remo... Use after free in Network in Google Chrome prior to 116.0.5845.96 allowed a remote attacker who has elicited a browser shutdown to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 116.0.5845.96-1~deb12u1) bullseye: resolved (fixed in 116.0.5845.96-1~deb11u1) forky: resolved (fixe
debian
CVE-2023-4358P3HIGHCVSS 8.8fixed in chromium 116.0.5845.96-1~deb12u1 (bookworm)2023
CVE-2023-4358 [HIGH] CVE-2023-4358: chromium - Use after free in DNS in Google Chrome prior to 116.0.5845.96 allowed a remote a... Use after free in DNS in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 116.0.5845.96-1~deb12u1) bullseye: resolved (fixed in 116.0.5845.96-1~deb11u1) forky: resolved (fixed in 116.0.5845.96-1) sid: resolved (f
debian
CVE-2024-1673P3HIGHCVSS 8.8fixed in chromium 122.0.6261.57-1~deb12u1 (bookworm)2024
CVE-2024-1673 [HIGH] CVE-2024-1673: chromium - Use after free in Accessibility in Google Chrome prior to 122.0.6261.57 allowed ... Use after free in Accessibility in Google Chrome prior to 122.0.6261.57 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via specific UI gestures. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 122.0.6261.57-1~deb12u1) bullseye: open forky: resolved (fixed in 122.0.6261.57-1) sid
debian
CVE-2024-9602P3HIGHCVSS 8.8fixed in chromium 129.0.6668.100-1~deb12u1 (bookworm)2024
CVE-2024-9602 [HIGH] CVE-2024-9602: chromium - Type Confusion in V8 in Google Chrome prior to 129.0.6668.100 allowed a remote a... Type Confusion in V8 in Google Chrome prior to 129.0.6668.100 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 129.0.6668.100-1~deb12u1) bullseye: open forky: resolved (fixed in 129.0.6668.100-1) sid: resolved (fixed in 129.0.6668.100-1) trixie: res
debian
Debian Chromium vulnerabilities | cvebase