Debian Chromium vulnerabilities
2,134 known vulnerabilities affecting debian/chromium.
Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8
Vulnerabilities
Page 34 of 107
CVE-2020-6439P3HIGHCVSS 8.8fixed in chromium 81.0.4044.92-1 (bookworm)2020
CVE-2020-6439 [HIGH] CVE-2020-6439: chromium - Insufficient policy enforcement in navigations in Google Chrome prior to 81.0.40...
Insufficient policy enforcement in navigations in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass security UI via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 81.0.4044.92-1)
bullseye: resolved (fixed in 81.0.4044.92-1)
forky: resolved (fixed in 81.0.4044.92-1)
sid: resolved (fixed in 81.0.4044.92-1)
trixie: resolved (fixed i
debian
CVE-2020-6410P3HIGHCVSS 8.8fixed in chromium 80.0.3987.106-1 (bookworm)2020
CVE-2020-6410 [HIGH] CVE-2020-6410: chromium - Insufficient policy enforcement in navigation in Google Chrome prior to 80.0.398...
Insufficient policy enforcement in navigation in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to confuse the user via a crafted domain name.
Scope: local
bookworm: resolved (fixed in 80.0.3987.106-1)
bullseye: resolved (fixed in 80.0.3987.106-1)
forky: resolved (fixed in 80.0.3987.106-1)
sid: resolved (fixed in 80.0.3987.106-1)
trixie: resolved (fixe
debian
CVE-2020-6576P3HIGHCVSS 8.8fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-6576 [HIGH] CVE-2020-6576: chromium - Use after free in offscreen canvas in Google Chrome prior to 85.0.4183.102 allow...
Use after free in offscreen canvas in Google Chrome prior to 85.0.4183.102 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (fixed in 87.0.4280.88-0.1)
trixie: res
debian
CVE-2020-16002P3HIGHCVSS 8.8fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-16002 [HIGH] CVE-2020-16002: chromium - Use after free in PDFium in Google Chrome prior to 86.0.4240.111 allowed a remot...
Use after free in PDFium in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (fixed in 87.0.4280.88-0.1)
trixie: resolved (fi
debian
CVE-2021-21188P3HIGHCVSS 8.8fixed in chromium 89.0.4389.82-1 (bookworm)2021
CVE-2021-21188 [HIGH] CVE-2021-21188: chromium - Use after free in Blink in Google Chrome prior to 89.0.4389.72 allowed a remote ...
Use after free in Blink in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 89.0.4389.82-1)
bullseye: resolved (fixed in 89.0.4389.82-1)
forky: resolved (fixed in 89.0.4389.82-1)
sid: resolved (fixed in 89.0.4389.82-1)
trixie: resolved (fixed in 89
debian
CVE-2021-21180P3HIGHCVSS 8.8fixed in chromium 89.0.4389.82-1 (bookworm)2021
CVE-2021-21180 [HIGH] CVE-2021-21180: chromium - Use after free in tab search in Google Chrome prior to 89.0.4389.72 allowed a re...
Use after free in tab search in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 89.0.4389.82-1)
bullseye: resolved (fixed in 89.0.4389.82-1)
forky: resolved (fixed in 89.0.4389.82-1)
sid: resolved (fixed in 89.0.4389.82-1)
trixie: resolved (fixed
debian
CVE-2021-30574P3HIGHCVSS 8.8fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30574 [HIGH] CVE-2021-30574: chromium - Use after free in protocol handling in Google Chrome prior to 92.0.4515.107 allo...
Use after free in protocol handling in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 93.0.4577.82-1)
bullseye: resolved (fixed in 93.0.4577.82-1)
forky: resolved (fixed in 93.0.4577.82-1)
sid: resolved (fixed in 93.0.4577.82-1)
trixie: resolved
debian
CVE-2021-30572P3HIGHCVSS 8.8fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30572 [HIGH] CVE-2021-30572: chromium - Use after free in Autofill in Google Chrome prior to 92.0.4515.107 allowed a rem...
Use after free in Autofill in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 93.0.4577.82-1)
bullseye: resolved (fixed in 93.0.4577.82-1)
forky: resolved (fixed in 93.0.4577.82-1)
sid: resolved (fixed in 93.0.4577.82-1)
trixie: resolved (fixed i
debian
CVE-2021-30579P3HIGHCVSS 8.8fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30579 [HIGH] CVE-2021-30579: chromium - Use after free in UI framework in Google Chrome prior to 92.0.4515.107 allowed a...
Use after free in UI framework in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 93.0.4577.82-1)
bullseye: resolved (fixed in 93.0.4577.82-1)
forky: resolved (fixed in 93.0.4577.82-1)
sid: resolved (fixed in 93.0.4577.82-1)
trixie: resolved (fix
debian
CVE-2020-15979P3HIGHCVSS 8.8fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-15979 [HIGH] CVE-2020-15979: chromium - Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.75 allowe...
Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (fixed in 87.0.4280.88-0.1)
trixie: re
debian
CVE-2020-16000P3HIGHCVSS 8.8fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-16000 [HIGH] CVE-2020-16000: chromium - Inappropriate implementation in Blink in Google Chrome prior to 86.0.4240.111 al...
Inappropriate implementation in Blink in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (fixed in 87.0.4280.88-0.1)
trixie
debian
CVE-2020-16001P3HIGHCVSS 8.8fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-16001 [HIGH] CVE-2020-16001: chromium - Use after free in media in Google Chrome prior to 86.0.4240.111 allowed a remote...
Use after free in media in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (fixed in 87.0.4280.88-0.1)
trixie: resolved (fi
debian
CVE-2021-21204P3HIGHCVSS 8.8fixed in chromium 90.0.4430.72-1 (bookworm)2021
CVE-2021-21204 [HIGH] CVE-2021-21204: chromium - Use after free in Blink in Google Chrome on OS X prior to 90.0.4430.72 allowed a...
Use after free in Blink in Google Chrome on OS X prior to 90.0.4430.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 90.0.4430.72-1)
bullseye: resolved (fixed in 90.0.4430.72-1)
forky: resolved (fixed in 90.0.4430.72-1)
sid: resolved (fixed in 90.0.4430.72-1)
trixie: resolved (fix
debian
CVE-2021-21161P3HIGHCVSS 8.8fixed in chromium 89.0.4389.82-1 (bookworm)2021
CVE-2021-21161 [HIGH] CVE-2021-21161: chromium - Heap buffer overflow in TabStrip in Google Chrome prior to 89.0.4389.72 allowed ...
Heap buffer overflow in TabStrip in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 89.0.4389.82-1)
bullseye: resolved (fixed in 89.0.4389.82-1)
forky: resolved (fixed in 89.0.4389.82-1)
sid: resolved (fixed in 89.0.4389.82-1)
trixie: resolved (fi
debian
CVE-2020-15968P3HIGHCVSS 8.8fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-15968 [HIGH] CVE-2020-15968: chromium - Use after free in Blink in Google Chrome prior to 86.0.4240.75 allowed a remote ...
Use after free in Blink in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (fixed in 87.0.4280.88-0.1)
trixie: resolved (fix
debian
CVE-2021-21213P3HIGHCVSS 8.8fixed in chromium 90.0.4430.72-1 (bookworm)2021
CVE-2021-21213 [HIGH] CVE-2021-21213: chromium - Use after free in WebMIDI in Google Chrome prior to 90.0.4430.72 allowed a remot...
Use after free in WebMIDI in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 90.0.4430.72-1)
bullseye: resolved (fixed in 90.0.4430.72-1)
forky: resolved (fixed in 90.0.4430.72-1)
sid: resolved (fixed in 90.0.4430.72-1)
trixie: resolved (fixed in
debian
CVE-2021-30568P3HIGHCVSS 8.8fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30568 [HIGH] CVE-2021-30568: chromium - Heap buffer overflow in WebGL in Google Chrome prior to 92.0.4515.107 allowed a ...
Heap buffer overflow in WebGL in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 93.0.4577.82-1)
bullseye: resolved (fixed in 93.0.4577.82-1)
forky: resolved (fixed in 93.0.4577.82-1)
sid: resolved (fixed in 93.0.4577.82-1)
trixie: resolved (fixe
debian
CVE-2022-0115P3HIGHCVSS 8.8fixed in chromium 97.0.4692.71-0.1 (bookworm)2022
CVE-2022-0115 [HIGH] CVE-2022-0115: chromium - Uninitialized use in File API in Google Chrome prior to 97.0.4692.71 allowed a r...
Uninitialized use in File API in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 97.0.4692.71-0.1)
bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1)
forky: resolved (fixed in 97.0.4692.71-0.1)
sid: resolved (fixed in 97.0.4692.71-0.
debian
CVE-2021-21149P3HIGHCVSS 8.8fixed in chromium 88.0.4324.182-1 (bookworm)2021
CVE-2021-21149 [HIGH] CVE-2021-21149: chromium - Stack buffer overflow in Data Transfer in Google Chrome on Linux prior to 88.0.4...
Stack buffer overflow in Data Transfer in Google Chrome on Linux prior to 88.0.4324.182 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 88.0.4324.182-1)
bullseye: resolved (fixed in 88.0.4324.182-1)
forky: resolved (fixed in 88.0.4324.182-1)
sid: resolved (fixed in 88.0.4324.182-1)
debian
CVE-2022-2156P3HIGHCVSS 8.8fixed in chromium 103.0.5060.53-1 (bookworm)2022
CVE-2022-2156 [HIGH] CVE-2022-2156: chromium - Use after free in Core in Google Chrome prior to 103.0.5060.53 allowed a remote ...
Use after free in Core in Google Chrome prior to 103.0.5060.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 103.0.5060.53-1)
bullseye: resolved (fixed in 103.0.5060.53-1~deb11u1)
forky: resolved (fixed in 103.0.5060.53-1)
sid: resolved (fixed in 103.0.5060.53-1)
trixie: resolved (f
debian