cbcvebase.

Debian Chromium vulnerabilities

2,134 known vulnerabilities affecting debian/chromium.

Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8

Vulnerabilities

Page 29 of 107
CVE-2024-5493P3HIGHCVSS 8.8fixed in chromium 125.0.6422.141-1~deb12u1 (bookworm)2024
CVE-2024-5493 [HIGH] CVE-2024-5493: chromium - Heap buffer overflow in WebRTC in Google Chrome prior to 125.0.6422.141 allowed ... Heap buffer overflow in WebRTC in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 125.0.6422.141-1~deb12u1) bullseye: open forky: resolved (fixed in 125.0.6422.141-1) sid: resolved (fixed in 125.0.6422.141-1) tri
debian
CVE-2023-3728P3HIGHCVSS 8.8fixed in chromium 115.0.5790.98-1~deb12u1 (bookworm)2023
CVE-2023-3728 [HIGH] CVE-2023-3728: chromium - Use after free in WebRTC in Google Chrome prior to 115.0.5790.98 allowed a remot... Use after free in WebRTC in Google Chrome prior to 115.0.5790.98 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 115.0.5790.98-1~deb12u1) bullseye: resolved (fixed in 115.0.5790.98-1~deb11u1) forky: resolved (fixed in 115.0.5790.98-1) sid: resolved (
debian
CVE-2023-3727P3HIGHCVSS 8.8fixed in chromium 115.0.5790.98-1~deb12u1 (bookworm)2023
CVE-2023-3727 [HIGH] CVE-2023-3727: chromium - Use after free in WebRTC in Google Chrome prior to 115.0.5790.98 allowed a remot... Use after free in WebRTC in Google Chrome prior to 115.0.5790.98 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 115.0.5790.98-1~deb12u1) bullseye: resolved (fixed in 115.0.5790.98-1~deb11u1) forky: resolved (fixed in 115.0.5790.98-1) sid: resolved (
debian
CVE-2022-4912P3HIGHCVSS 8.8fixed in chromium 105.0.5195.52-1 (bookworm)2022
CVE-2022-4912 [HIGH] CVE-2022-4912: chromium - Type Confusion in MathML in Google Chrome prior to 105.0.5195.52 allowed a remot... Type Confusion in MathML in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 105.0.5195.52-1) bullseye: resolved (fixed in 105.0.5195.52-1~deb11u1) forky: resolved (fixed in 105.0.5195.52-1) sid: resolved (fixed in
debian
CVE-2024-7534P3HIGHCVSS 8.8fixed in chromium 127.0.6533.99-1~deb12u1 (bookworm)2024
CVE-2024-7534 [HIGH] CVE-2024-7534: chromium - Heap buffer overflow in Layout in Google Chrome prior to 127.0.6533.99 allowed a... Heap buffer overflow in Layout in Google Chrome prior to 127.0.6533.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 127.0.6533.99-1~deb12u1) bullseye: open forky: resolved (fixed in 127.0.6533.99-1) sid: resolved (fixed in 127.0.6533.99-1) trixie:
debian
CVE-2023-6705P3HIGHCVSS 8.8fixed in chromium 120.0.6099.109-1~deb12u1 (bookworm)2023
CVE-2023-6705 [HIGH] CVE-2023-6705: chromium - Use after free in WebRTC in Google Chrome prior to 120.0.6099.109 allowed a remo... Use after free in WebRTC in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 120.0.6099.109-1~deb12u1) bullseye: resolved (fixed in 120.0.6099.109-1~deb11u1) forky: resolved (fixed in 120.0.6099.109-1) sid: resolv
debian
CVE-2024-10487P3HIGHCVSS 8.8fixed in chromium 130.0.6723.91-1~deb12u1 (bookworm)2024
CVE-2024-10487 [HIGH] CVE-2024-10487: chromium - Out of bounds write in Dawn in Google Chrome prior to 130.0.6723.92 allowed a re... Out of bounds write in Dawn in Google Chrome prior to 130.0.6723.92 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Critical) Scope: local bookworm: resolved (fixed in 130.0.6723.91-1~deb12u1) bullseye: open forky: resolved (fixed in 130.0.6723.91-1) sid: resolved (fixed in 130.0.6723.91-1) trix
debian
CVE-2024-7535P3HIGHCVSS 8.8fixed in chromium 127.0.6533.99-1~deb12u1 (bookworm)2024
CVE-2024-7535 [HIGH] CVE-2024-7535: chromium - Inappropriate implementation in V8 in Google Chrome prior to 127.0.6533.99 allow... Inappropriate implementation in V8 in Google Chrome prior to 127.0.6533.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 127.0.6533.99-1~deb12u1) bullseye: open forky: resolved (fixed in 127.0.6533.99-1) sid: resolved (fixed in 127.0.6533.99-1) tri
debian
CVE-2023-6703P3HIGHCVSS 8.8fixed in chromium 120.0.6099.109-1~deb12u1 (bookworm)2023
CVE-2023-6703 [HIGH] CVE-2023-6703: chromium - Use after free in Blink in Google Chrome prior to 120.0.6099.109 allowed a remot... Use after free in Blink in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 120.0.6099.109-1~deb12u1) bullseye: resolved (fixed in 120.0.6099.109-1~deb11u1) forky: resolved (fixed in 120.0.6099.109-1) sid: resolve
debian
CVE-2024-7533P3HIGHCVSS 8.8fixed in chromium 127.0.6533.99-1~deb12u1 (bookworm)2024
CVE-2024-7533 [HIGH] CVE-2024-7533: chromium - Use after free in Sharing in Google Chrome on iOS prior to 127.0.6533.99 allowed... Use after free in Sharing in Google Chrome on iOS prior to 127.0.6533.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 127.0.6533.99-1~deb12u1) bullseye: open forky: resolved (fixed in 127.0.6533.99-1) sid: resolved (fixed in 127.0.6533.99-1) trixi
debian
CVE-2024-5160P3HIGHCVSS 8.8fixed in chromium 125.0.6422.76-1~deb12u1 (bookworm)2024
CVE-2024-5160 [HIGH] CVE-2024-5160: chromium - Heap buffer overflow in Dawn in Google Chrome prior to 125.0.6422.76 allowed a r... Heap buffer overflow in Dawn in Google Chrome prior to 125.0.6422.76 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 125.0.6422.76-1~deb12u1) bullseye: open forky: resolved (fixed in 125.0.6422.76-1) sid: resolved (fixed in 125.0.6422.76-1) trixie:
debian
CVE-2024-7025P3HIGHCVSS 8.8fixed in chromium 129.0.6668.89-1~deb12u1 (bookworm)2024
CVE-2024-7025 [HIGH] CVE-2024-7025: chromium - Integer overflow in Layout in Google Chrome prior to 129.0.6668.89 allowed a rem... Integer overflow in Layout in Google Chrome prior to 129.0.6668.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 129.0.6668.89-1~deb12u1) bullseye: open forky: resolved (fixed in 129.0.6668.89-1) sid: resolved (fixed in 129.0.6668.89-1) trixie: res
debian
CVE-2025-1426P3HIGHCVSS 8.8fixed in chromium 133.0.6943.126-1~deb12u1 (bookworm)2025
CVE-2025-1426 [HIGH] CVE-2025-1426: chromium - Heap buffer overflow in GPU in Google Chrome on Android prior to 133.0.6943.126 ... Heap buffer overflow in GPU in Google Chrome on Android prior to 133.0.6943.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 133.0.6943.126-1~deb12u1) bullseye: open forky: resolved (fixed in 133.0.6943.126-1) sid: resolved (fixed in 133.0.6943.12
debian
CVE-2024-6988P3HIGHCVSS 8.8fixed in chromium 127.0.6533.88-1~deb12u1 (bookworm)2024
CVE-2024-6988 [HIGH] CVE-2024-6988: chromium - Use after free in Downloads in Google Chrome on iOS prior to 127.0.6533.72 allow... Use after free in Downloads in Google Chrome on iOS prior to 127.0.6533.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 127.0.6533.88-1~deb12u1) bullseye: open forky: resolved (fixed in 127.0.6533.88-1) sid: resolved (fixed in 127.0.6533.88-1) tri
debian
CVE-2024-7967P3HIGHCVSS 8.8fixed in chromium 128.0.6613.84-1~deb12u1 (bookworm)2024
CVE-2024-7967 [HIGH] CVE-2024-7967: chromium - Heap buffer overflow in Fonts in Google Chrome prior to 128.0.6613.84 allowed a ... Heap buffer overflow in Fonts in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 128.0.6613.84-1~deb12u1) bullseye: open forky: resolved (fixed in 128.0.6613.84-1) sid: resolved (fixed in 128.0.6613.84-1) trixie:
debian
CVE-2024-6994P3HIGHCVSS 8.8fixed in chromium 127.0.6533.88-1~deb12u1 (bookworm)2024
CVE-2024-6994 [HIGH] CVE-2024-6994: chromium - Heap buffer overflow in Layout in Google Chrome prior to 127.0.6533.72 allowed a... Heap buffer overflow in Layout in Google Chrome prior to 127.0.6533.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 127.0.6533.88-1~deb12u1) bullseye: open forky: resolved (fixed in 127.0.6533.88-1) sid: resolved (fixed in 127.0.6533.88-1) trixi
debian
CVE-2024-10826P3HIGHCVSS 8.8fixed in chromium 130.0.6723.116-1~deb12u1 (bookworm)2024
CVE-2024-10826 [HIGH] CVE-2024-10826: chromium - Use after free in Family Experiences in Google Chrome on Android prior to 130.0.... Use after free in Family Experiences in Google Chrome on Android prior to 130.0.6723.116 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 130.0.6723.116-1~deb12u1) bullseye: open forky: resolved (fixed in 130.0.6723.116-1) sid: resolved (fixed in 13
debian
CVE-2024-7964P3HIGHCVSS 8.8fixed in chromium 128.0.6613.84-1~deb12u1 (bookworm)2024
CVE-2024-7964 [HIGH] CVE-2024-7964: chromium - Use after free in Passwords in Google Chrome on Android prior to 128.0.6613.84 a... Use after free in Passwords in Google Chrome on Android prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 128.0.6613.84-1~deb12u1) bullseye: open forky: resolved (fixed in 128.0.6613.84-1) sid: resolved (fixed in 128.0.6613.84-1)
debian
CVE-2024-6997P3HIGHCVSS 8.8fixed in chromium 127.0.6533.88-1~deb12u1 (bookworm)2024
CVE-2024-6997 [HIGH] CVE-2024-6997: chromium - Use after free in Tabs in Google Chrome prior to 127.0.6533.72 allowed a remote ... Use after free in Tabs in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 127.0.6533.88-1~deb12u1) bullseye: open forky: resolved (fixed in 127.0.6533.88-1)
debian
CVE-2024-7972P3HIGHCVSS 8.8fixed in chromium 128.0.6613.84-1~deb12u1 (bookworm)2024
CVE-2024-7972 [HIGH] CVE-2024-7972: chromium - Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allow... Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 128.0.6613.84-1~deb12u1) bullseye: open forky: resolved (fixed in 128.0.6613.84-1) sid: resolved (fixed in 128.0.
debian
Debian Chromium vulnerabilities | cvebase