Debian Chromium vulnerabilities
2,134 known vulnerabilities affecting debian/chromium.
Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8
Vulnerabilities
Page 33 of 107
CVE-2020-6518P3HIGHCVSS 8.8fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-6518 [HIGH] CVE-2020-6518: chromium - Use after free in developer tools in Google Chrome prior to 84.0.4147.89 allowed...
Use after free in developer tools in Google Chrome prior to 84.0.4147.89 allowed a remote attacker who had convinced the user to use developer tools to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid:
debian
CVE-2020-6427P3HIGHCVSS 8.8fixed in chromium 80.0.3987.149-1 (bookworm)2020
CVE-2020-6427 [HIGH] CVE-2020-6427: chromium - Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote...
Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 80.0.3987.149-1)
bullseye: resolved (fixed in 80.0.3987.149-1)
forky: resolved (fixed in 80.0.3987.149-1)
sid: resolved (fixed in 80.0.3987.149-1)
trixie: resolved (fixed in
debian
CVE-2020-6422P3HIGHCVSS 8.8fixed in chromium 80.0.3987.149-1 (bookworm)2020
CVE-2020-6422 [HIGH] CVE-2020-6422: chromium - Use after free in WebGL in Google Chrome prior to 80.0.3987.149 allowed a remote...
Use after free in WebGL in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 80.0.3987.149-1)
bullseye: resolved (fixed in 80.0.3987.149-1)
forky: resolved (fixed in 80.0.3987.149-1)
sid: resolved (fixed in 80.0.3987.149-1)
trixie: resolved (fixed in
debian
CVE-2020-6428P3HIGHCVSS 8.8fixed in chromium 80.0.3987.149-1 (bookworm)2020
CVE-2020-6428 [HIGH] CVE-2020-6428: chromium - Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote...
Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 80.0.3987.149-1)
bullseye: resolved (fixed in 80.0.3987.149-1)
forky: resolved (fixed in 80.0.3987.149-1)
sid: resolved (fixed in 80.0.3987.149-1)
trixie: resolved (fixed in
debian
CVE-2020-6429P3HIGHCVSS 8.8fixed in chromium 80.0.3987.149-1 (bookworm)2020
CVE-2020-6429 [HIGH] CVE-2020-6429: chromium - Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote...
Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 80.0.3987.149-1)
bullseye: resolved (fixed in 80.0.3987.149-1)
forky: resolved (fixed in 80.0.3987.149-1)
sid: resolved (fixed in 80.0.3987.149-1)
trixie: resolved (fixed in
debian
CVE-2020-6382P3HIGHCVSS 8.8fixed in chromium 80.0.3987.106-1 (bookworm)2020
CVE-2020-6382 [HIGH] CVE-2020-6382: chromium - Type confusion in JavaScript in Google Chrome prior to 80.0.3987.87 allowed a re...
Type confusion in JavaScript in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 80.0.3987.106-1)
bullseye: resolved (fixed in 80.0.3987.106-1)
forky: resolved (fixed in 80.0.3987.106-1)
sid: resolved (fixed in 80.0.3987.106-1)
trixie: resolved (fixe
debian
CVE-2021-30602P3HIGHCVSS 8.8fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30602 [HIGH] CVE-2021-30602: chromium - Use after free in WebRTC in Google Chrome prior to 92.0.4515.159 allowed an atta...
Use after free in WebRTC in Google Chrome prior to 92.0.4515.159 allowed an attacker who convinced a user to visit a malicious website to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 93.0.4577.82-1)
bullseye: resolved (fixed in 93.0.4577.82-1)
forky: resolved (fixed in 93.0.4577.82-1)
sid: resolved (fixed in
debian
CVE-2020-6388P3HIGHCVSS 8.8fixed in chromium 80.0.3987.106-1 (bookworm)2020
CVE-2020-6388 [HIGH] CVE-2020-6388: chromium - Out of bounds access in WebAudio in Google Chrome prior to 80.0.3987.87 allowed ...
Out of bounds access in WebAudio in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 80.0.3987.106-1)
bullseye: resolved (fixed in 80.0.3987.106-1)
forky: resolved (fixed in 80.0.3987.106-1)
sid: resolved (fixed in 80.0.3987.106-1)
trixie: resolved (
debian
CVE-2021-30592P3HIGHCVSS 8.8fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30592 [HIGH] CVE-2021-30592: chromium - Out of bounds write in Tab Groups in Google Chrome prior to 92.0.4515.131 allowe...
Out of bounds write in Tab Groups in Google Chrome prior to 92.0.4515.131 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory write via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 93.0.4577.82-1)
bullseye: resolved (fixed in 93.0.4577.82-1)
forky: resolved (fixed in 93.0.4577.82-1)
sid: res
debian
CVE-2020-6416P3HIGHCVSS 8.8fixed in chromium 80.0.3987.106-1 (bookworm)2020
CVE-2020-6416 [HIGH] CVE-2020-6416: chromium - Insufficient data validation in streams in Google Chrome prior to 80.0.3987.87 a...
Insufficient data validation in streams in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 80.0.3987.106-1)
bullseye: resolved (fixed in 80.0.3987.106-1)
forky: resolved (fixed in 80.0.3987.106-1)
sid: resolved (fixed in 80.0.3987.106-1)
trixie: res
debian
CVE-2019-5787P3HIGHCVSS 8.8fixed in chromium 73.0.3683.75-1 (bookworm)2019
CVE-2019-5787 [HIGH] CVE-2019-5787: chromium - Use-after-garbage-collection in Blink in Google Chrome prior to 73.0.3683.75 all...
Use-after-garbage-collection in Blink in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 73.0.3683.75-1)
bullseye: resolved (fixed in 73.0.3683.75-1)
forky: resolved (fixed in 73.0.3683.75-1)
sid: resolved (fixed in 73.0.3683.75-1)
trixie: resolved
debian
CVE-2019-5831P3HIGHCVSS 8.8fixed in chromium 75.0.3770.80-1 (bookworm)2019
CVE-2019-5831 [HIGH] CVE-2019-5831: chromium - Object lifecycle issue in V8 in Google Chrome prior to 75.0.3770.80 allowed a re...
Object lifecycle issue in V8 in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 75.0.3770.80-1)
bullseye: resolved (fixed in 75.0.3770.80-1)
forky: resolved (fixed in 75.0.3770.80-1)
sid: resolved (fixed in 75.0.3770.80-1)
trixie: resolved (fixed in
debian
CVE-2019-13730P3HIGHCVSS 8.8fixed in chromium 79.0.3945.79-1 (bookworm)2019
CVE-2019-13730 [HIGH] CVE-2019-13730: chromium - Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a re...
Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 79.0.3945.79-1)
bullseye: resolved (fixed in 79.0.3945.79-1)
forky: resolved (fixed in 79.0.3945.79-1)
sid: resolved (fixed in 79.0.3945.79-1)
trixie: resolved (fixed
debian
CVE-2020-6534P3HIGHCVSS 8.8fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-6534 [HIGH] CVE-2020-6534: chromium - Heap buffer overflow in WebRTC in Google Chrome prior to 84.0.4147.89 allowed a ...
Heap buffer overflow in WebRTC in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (fixed in 87.0.4280.88-0.1)
trixie: resolved
debian
CVE-2021-30565P3HIGHCVSS 8.8fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30565 [HIGH] CVE-2021-30565: chromium - Out of bounds write in Tab Groups in Google Chrome on Linux and ChromeOS prior t...
Out of bounds write in Tab Groups in Google Chrome on Linux and ChromeOS prior to 92.0.4515.107 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory write via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 93.0.4577.82-1)
bullseye: resolved (fixed in 93.0.4577.82-1)
forky: resolved (fixed in 93
debian
CVE-2020-6525P3HIGHCVSS 8.8fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-6525 [HIGH] CVE-2020-6525: chromium - Heap buffer overflow in Skia in Google Chrome prior to 84.0.4147.89 allowed a re...
Heap buffer overflow in Skia in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (fixed in 87.0.4280.88-0.1)
trixie: resolved (
debian
CVE-2020-6406P3HIGHCVSS 8.8fixed in chromium 80.0.3987.106-1 (bookworm)2020
CVE-2020-6406 [HIGH] CVE-2020-6406: chromium - Use after free in audio in Google Chrome prior to 80.0.3987.87 allowed a remote ...
Use after free in audio in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 80.0.3987.106-1)
bullseye: resolved (fixed in 80.0.3987.106-1)
forky: resolved (fixed in 80.0.3987.106-1)
sid: resolved (fixed in 80.0.3987.106-1)
trixie: resolved (fixed in
debian
CVE-2020-6447P3HIGHCVSS 8.8fixed in chromium 81.0.4044.92-1 (bookworm)2020
CVE-2020-6447 [HIGH] CVE-2020-6447: chromium - Inappropriate implementation in developer tools in Google Chrome prior to 81.0.4...
Inappropriate implementation in developer tools in Google Chrome prior to 81.0.4044.92 allowed a remote attacker who had convinced the user to use devtools to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 81.0.4044.92-1)
bullseye: resolved (fixed in 81.0.4044.92-1)
forky: resolved (fixed in 81.0.4044.92-1)
sid:
debian
CVE-2019-5790P3HIGHCVSS 8.8fixed in chromium 73.0.3683.75-1 (bookworm)2019
CVE-2019-5790 [HIGH] CVE-2019-5790: chromium - An integer overflow leading to an incorrect capacity of a buffer in JavaScript i...
An integer overflow leading to an incorrect capacity of a buffer in JavaScript in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 73.0.3683.75-1)
bullseye: resolved (fixed in 73.0.3683.75-1)
forky: resolved (fixed in 73.0.3683.75-1)
sid: resolve
debian
CVE-2020-6452P3HIGHCVSS 8.8fixed in chromium 80.0.3987.162-1 (bookworm)2020
CVE-2020-6452 [HIGH] CVE-2020-6452: chromium - Heap buffer overflow in media in Google Chrome prior to 80.0.3987.162 allowed a ...
Heap buffer overflow in media in Google Chrome prior to 80.0.3987.162 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 80.0.3987.162-1)
bullseye: resolved (fixed in 80.0.3987.162-1)
forky: resolved (fixed in 80.0.3987.162-1)
sid: resolved (fixed in 80.0.3987.162-1)
trixie: resolved (fi
debian