cbcvebase.

Debian Chromium vulnerabilities

2,134 known vulnerabilities affecting debian/chromium.

Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8

Vulnerabilities

Page 35 of 107
CVE-2021-4056P3HIGHCVSS 8.8fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-4056 [HIGH] CVE-2021-4056: chromium - Type confusion in loader in Google Chrome prior to 96.0.4664.93 allowed a remote... Type confusion in loader in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 97.0.4692.71-0.1) bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1) forky: resolved (fixed in 97.0.4692.71-0.1) sid: resolved (fixed in 97.0.4692.71-0.1) trixie: resolv
debian
CVE-2021-4061P3HIGHCVSS 8.8fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-4061 [HIGH] CVE-2021-4061: chromium - Type confusion in V8 in Google Chrome prior to 96.0.4664.93 allowed a remote att... Type confusion in V8 in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 97.0.4692.71-0.1) bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1) forky: resolved (fixed in 97.0.4692.71-0.1) sid: resolved (fixed in 97.0.4692.71-0.1) trixie: resolved (
debian
CVE-2020-15967P3HIGHCVSS 8.8fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-15967 [HIGH] CVE-2020-15967: chromium - Use after free in payments in Google Chrome prior to 86.0.4240.75 allowed a remo... Use after free in payments in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. Scope: local bookworm: resolved (fixed in 87.0.4280.88-0.1) bullseye: resolved (fixed in 87.0.4280.88-0.1) forky: resolved (fixed in 87.0.4280.88-0.1) sid: resolved (fixed in 87.0.4280.88-0.1) trixie: resolved
debian
CVE-2022-0096P3HIGHCVSS 8.8fixed in chromium 97.0.4692.71-0.1 (bookworm)2022
CVE-2022-0096 [HIGH] CVE-2022-0096: chromium - Use after free in Storage in Google Chrome prior to 97.0.4692.71 allowed a remot... Use after free in Storage in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 97.0.4692.71-0.1) bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1) forky: resolved (fixed in 97.0.4692.71-0.1) sid: resolved (fixed in 97.0.4692.71-0.1) trixie: resol
debian
CVE-2021-30528P3HIGHCVSS 8.8fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30528 [HIGH] CVE-2021-30528: chromium - Use after free in WebAuthentication in Google Chrome on Android prior to 91.0.44... Use after free in WebAuthentication in Google Chrome on Android prior to 91.0.4472.77 allowed a remote attacker who had compromised the renderer process of a user who had saved a credit card in their Google account to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 93.0.4577.82-1) bullseye: resolved (fixed in 9
debian
CVE-2023-1534P3HIGHCVSS 8.8fixed in chromium 111.0.5563.110-1 (bookworm)2023
CVE-2023-1534 [HIGH] CVE-2023-1534: chromium - Out of bounds read in ANGLE in Google Chrome prior to 111.0.5563.110 allowed a r... Out of bounds read in ANGLE in Google Chrome prior to 111.0.5563.110 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 111.0.5563.110-1) bullseye: resolved (fixed in 111.0.5563.110-1~deb11u1) forky: resolved (fi
debian
CVE-2022-0102P3HIGHCVSS 8.8fixed in chromium 97.0.4692.71-0.1 (bookworm)2022
CVE-2022-0102 [HIGH] CVE-2022-0102: chromium - Type confusion in V8 in Google Chrome prior to 97.0.4692.71 allowed a remote att... Type confusion in V8 in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 97.0.4692.71-0.1) bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1) forky: resolved (fixed in 97.0.4692.71-0.1) sid: resolved (fixed in 97.0.4692.71-0.1) trixie: resolved (
debian
CVE-2021-30559P3HIGHCVSS 8.8fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30559 [HIGH] CVE-2021-30559: chromium - Out of bounds write in ANGLE in Google Chrome prior to 91.0.4472.164 allowed a r... Out of bounds write in ANGLE in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 93.0.4577.82-1) bullseye: resolved (fixed in 93.0.4577.82-1) forky: resolved (fixed in 93.0.4577.82-1) sid: resolved (fixed in 93.0.4577.82-1) trixie: resolved (fixed
debian
CVE-2021-37974P3HIGHCVSS 8.8fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-37974 [HIGH] CVE-2021-37974: chromium - Use after free in Safebrowsing in Google Chrome prior to 94.0.4606.71 allowed a ... Use after free in Safebrowsing in Google Chrome prior to 94.0.4606.71 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 97.0.4692.71-0.1) bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1) forky: resolved (fixed in 97.0.4692.71-0.1) sid: re
debian
CVE-2021-21153P3HIGHCVSS 8.8fixed in chromium 88.0.4324.182-1 (bookworm)2021
CVE-2021-21153 [HIGH] CVE-2021-21153: chromium - Stack buffer overflow in GPU Process in Google Chrome on Linux prior to 88.0.432... Stack buffer overflow in GPU Process in Google Chrome on Linux prior to 88.0.4324.182 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. Scope: local bookworm: resolved (fixed in 88.0.4324.182-1) bullseye: resolved (fixed in 88.0.4324.182-1) forky: resolved (fixed in 88.0.4324.182-1) sid: resolved (fixed in 88.0.43
debian
CVE-2019-13693P3HIGHCVSS 8.8fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-13693 [HIGH] CVE-2019-13693: chromium - Use after free in IndexedDB in Google Chrome prior to 77.0.3865.120 allowed a re... Use after free in IndexedDB in Google Chrome prior to 77.0.3865.120 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. Scope: local bookworm: resolved (fixed in 78.0.3904.87-1) bullseye: resolved (fixed in 78.0.3904.87-1) forky: resolved (fixed in 78.0.3904.87-1) sid: resolved (fixed in 78.0.3904.87
debian
CVE-2022-2162P3HIGHCVSS 8.8fixed in chromium 103.0.5060.53-1 (bookworm)2022
CVE-2022-2162 [HIGH] CVE-2022-2162: chromium - Insufficient policy enforcement in File System API in Google Chrome on Windows p... Insufficient policy enforcement in File System API in Google Chrome on Windows prior to 103.0.5060.53 allowed a remote attacker to bypass file system access via a crafted HTML page. Scope: local bookworm: resolved (fixed in 103.0.5060.53-1) bullseye: resolved (fixed in 103.0.5060.53-1~deb11u1) forky: resolved (fixed in 103.0.5060.53-1) sid: resolved (fixed in 103.0.5
debian
CVE-2021-30512P3HIGHCVSS 8.8fixed in chromium 90.0.4430.212-1 (bookworm)2021
CVE-2021-30512 [HIGH] CVE-2021-30512: chromium - Use after free in Notifications in Google Chrome prior to 90.0.4430.212 allowed ... Use after free in Notifications in Google Chrome prior to 90.0.4430.212 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 90.0.4430.212-1) bullseye: resolved (fixed in 90.0.4430.212-1) forky: resolved (fixed in 90.0.4430.212-1) sid: resolved (f
debian
CVE-2021-37962P3HIGHCVSS 8.8fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-37962 [HIGH] CVE-2021-37962: chromium - Use after free in Performance Manager in Google Chrome prior to 94.0.4606.54 all... Use after free in Performance Manager in Google Chrome prior to 94.0.4606.54 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 97.0.4692.71-0.1) bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1) forky: resolved (fixed in 97.0.4692.71-0.1)
debian
CVE-2021-30530P3HIGHCVSS 8.8fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30530 [HIGH] CVE-2021-30530: chromium - Out of bounds memory access in WebAudio in Google Chrome prior to 91.0.4472.77 a... Out of bounds memory access in WebAudio in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. Scope: local bookworm: resolved (fixed in 93.0.4577.82-1) bullseye: resolved (fixed in 93.0.4577.82-1) forky: resolved (fixed in 93.0.4577.82-1) sid: resolved (fixed in 93.0.4577.82-1) trixie: resol
debian
CVE-2023-5854P3HIGHCVSS 8.8fixed in chromium 119.0.6045.105-1~deb12u1 (bookworm)2023
CVE-2023-5854 [HIGH] CVE-2023-5854: chromium - Use after free in Profiles in Google Chrome prior to 119.0.6045.105 allowed a re... Use after free in Profiles in Google Chrome prior to 119.0.6045.105 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via specific UI gestures. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 119.0.6045.105-1~deb12u1) bullseye: resolved (fixed in 119.0.6045.105-1~deb1
debian
CVE-2023-2137P3HIGHCVSS 8.8fixed in chromium 112.0.5615.138-1 (bookworm)2023
CVE-2023-2137 [HIGH] CVE-2023-2137: chromium - Heap buffer overflow in sqlite in Google Chrome prior to 112.0.5615.137 allowed ... Heap buffer overflow in sqlite in Google Chrome prior to 112.0.5615.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 112.0.5615.138-1) bullseye: resolved (fixed in 112.0.5615.138-1~deb11u1) forky: resolved (fixed in 112.0.5615.138-1) sid: resolv
debian
CVE-2023-1220P3HIGHCVSS 8.8fixed in chromium 111.0.5563.64-1 (bookworm)2023
CVE-2023-1220 [HIGH] CVE-2023-1220: chromium - Heap buffer overflow in UMA in Google Chrome prior to 111.0.5563.64 allowed a re... Heap buffer overflow in UMA in Google Chrome prior to 111.0.5563.64 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 111.0.5563.64-1) bullseye: resolved (fixed in 111.0.5563.64-1~deb11u1) forky: resolved (fixed
debian
CVE-2023-1219P3HIGHCVSS 8.8fixed in chromium 111.0.5563.64-1 (bookworm)2023
CVE-2023-1219 [HIGH] CVE-2023-1219: chromium - Heap buffer overflow in Metrics in Google Chrome prior to 111.0.5563.64 allowed ... Heap buffer overflow in Metrics in Google Chrome prior to 111.0.5563.64 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 111.0.5563.64-1) bullseye: resolved (fixed in 111.0.5563.64-1~deb11u1) forky: resolved (f
debian
CVE-2023-2929P3HIGHCVSS 8.8fixed in chromium 114.0.5735.90-2~deb12u1 (bookworm)2023
CVE-2023-2929 [HIGH] CVE-2023-2929: chromium - Out of bounds write in Swiftshader in Google Chrome prior to 114.0.5735.90 allow... Out of bounds write in Swiftshader in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 114.0.5735.90-2~deb12u1) bullseye: resolved (fixed in 114.0.5735.90-2~deb11u1) forky: resolved (fixed in 114.0.5735.90-1) sid:
debian
Debian Chromium vulnerabilities | cvebase