Debian Chromium vulnerabilities
2,134 known vulnerabilities affecting debian/chromium.
Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8
Vulnerabilities
Page 36 of 107
CVE-2022-2296P3HIGHCVSS 8.8fixed in chromium 103.0.5060.114-1 (bookworm)2022
CVE-2022-2296 [HIGH] CVE-2022-2296: chromium - Use after free in Chrome OS Shell in Google Chrome on Chrome OS prior to 103.0.5...
Use after free in Chrome OS Shell in Google Chrome on Chrome OS prior to 103.0.5060.114 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via direct UI interactions.
Scope: local
bookworm: resolved (fixed in 103.0.5060.114-1)
bullseye: resolved (fixed in 103.0.5060.114-1~deb11u1)
forky: resol
debian
CVE-2023-1810P3HIGHCVSS 8.8fixed in chromium 112.0.5615.49-1 (bookworm)2023
CVE-2023-1810 [HIGH] CVE-2023-1810: chromium - Heap buffer overflow in Visuals in Google Chrome prior to 112.0.5615.49 allowed ...
Heap buffer overflow in Visuals in Google Chrome prior to 112.0.5615.49 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 112.0.5615.49-1)
bullseye: resolved (fixed in 112.0.5615.49-2~deb11u2)
forky: resolved (f
debian
CVE-2023-2133P3HIGHCVSS 8.8fixed in chromium 112.0.5615.138-1 (bookworm)2023
CVE-2023-2133 [HIGH] CVE-2023-2133: chromium - Out of bounds memory access in Service Worker API in Google Chrome prior to 112....
Out of bounds memory access in Service Worker API in Google Chrome prior to 112.0.5615.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 112.0.5615.138-1)
bullseye: resolved (fixed in 112.0.5615.138-1~deb11u1)
forky: resolved (fixed in 112.0.5615.1
debian
CVE-2023-2134P3HIGHCVSS 8.8fixed in chromium 112.0.5615.138-1 (bookworm)2023
CVE-2023-2134 [HIGH] CVE-2023-2134: chromium - Out of bounds memory access in Service Worker API in Google Chrome prior to 112....
Out of bounds memory access in Service Worker API in Google Chrome prior to 112.0.5615.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 112.0.5615.138-1)
bullseye: resolved (fixed in 112.0.5615.138-1~deb11u1)
forky: resolved (fixed in 112.0.5615.1
debian
CVE-2023-5852P3HIGHCVSS 8.8fixed in chromium 119.0.6045.105-1~deb12u1 (bookworm)2023
CVE-2023-5852 [HIGH] CVE-2023-5852: chromium - Use after free in Printing in Google Chrome prior to 119.0.6045.105 allowed a re...
Use after free in Printing in Google Chrome prior to 119.0.6045.105 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via specific UI gestures. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 119.0.6045.105-1~deb12u1)
bullseye: resolved (fixed in 119.0.6045.105-1~deb1
debian
CVE-2023-5855P3HIGHCVSS 8.8fixed in chromium 119.0.6045.105-1~deb12u1 (bookworm)2023
CVE-2023-5855 [HIGH] CVE-2023-5855: chromium - Use after free in Reading Mode in Google Chrome prior to 119.0.6045.105 allowed ...
Use after free in Reading Mode in Google Chrome prior to 119.0.6045.105 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via specific UI gestures. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 119.0.6045.105-1~deb12u1)
bullseye: resolved (fixed in 119.0.6045.105-1~
debian
CVE-2023-6509P3HIGHCVSS 8.8fixed in chromium 120.0.6099.71-1~deb12u1 (bookworm)2023
CVE-2023-6509 [HIGH] CVE-2023-6509: chromium - Use after free in Side Panel Search in Google Chrome prior to 120.0.6099.62 allo...
Use after free in Side Panel Search in Google Chrome prior to 120.0.6099.62 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via specific UI interaction. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 120.0.6099.71-1~deb12u1)
bullseye: resolved (fixed in 120.0.6099
debian
CVE-2023-2932P3HIGHCVSS 8.8fixed in chromium 114.0.5735.90-2~deb12u1 (bookworm)2023
CVE-2023-2932 [HIGH] CVE-2023-2932: chromium - Use after free in PDF in Google Chrome prior to 114.0.5735.90 allowed a remote a...
Use after free in PDF in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 114.0.5735.90-2~deb12u1)
bullseye: resolved (fixed in 114.0.5735.90-2~deb11u1)
forky: resolved (fixed in 114.0.5735.90-1)
sid: resolved (fixe
debian
CVE-2023-4076P3HIGHCVSS 8.8fixed in chromium 115.0.5790.170-1~deb12u1 (bookworm)2023
CVE-2023-4076 [HIGH] CVE-2023-4076: chromium - Use after free in WebRTC in Google Chrome prior to 115.0.5790.170 allowed a remo...
Use after free in WebRTC in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to potentially exploit heap corruption via a crafted WebRTC session. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 115.0.5790.170-1~deb12u1)
bullseye: resolved (fixed in 115.0.5790.170-1~deb11u1)
forky: resolved (fixed in 115.0.5790.170-1)
sid: r
debian
CVE-2023-3214P3HIGHCVSS 8.8fixed in chromium 114.0.5735.133-1~deb12u1 (bookworm)2023
CVE-2023-3214 [HIGH] CVE-2023-3214: chromium - Use after free in Autofill payments in Google Chrome prior to 114.0.5735.133 all...
Use after free in Autofill payments in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
Scope: local
bookworm: resolved (fixed in 114.0.5735.133-1~deb12u1)
bullseye: resolved (fixed in 114.0.5735.133-1~deb11u1)
forky: resolved (fixed in 114.0.5735.133
debian
CVE-2023-1812P3HIGHCVSS 8.8fixed in chromium 112.0.5615.49-1 (bookworm)2023
CVE-2023-1812 [HIGH] CVE-2023-1812: chromium - Out of bounds memory access in DOM Bindings in Google Chrome prior to 112.0.5615...
Out of bounds memory access in DOM Bindings in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 112.0.5615.49-1)
bullseye: resolved (fixed in 112.0.5615.49-2~deb11u2)
forky: resolved (fixed in 112.0.5615.49-1)
si
debian
CVE-2023-4353P3HIGHCVSS 8.8fixed in chromium 116.0.5845.96-1~deb12u1 (bookworm)2023
CVE-2023-4353 [HIGH] CVE-2023-4353: chromium - Heap buffer overflow in ANGLE in Google Chrome prior to 116.0.5845.96 allowed a ...
Heap buffer overflow in ANGLE in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 116.0.5845.96-1~deb12u1)
bullseye: resolved (fixed in 116.0.5845.96-1~deb11u1)
forky: resolved (fixed in 116.0.5845.96-1)
sid: resol
debian
CVE-2023-2931P3HIGHCVSS 8.8fixed in chromium 114.0.5735.90-2~deb12u1 (bookworm)2023
CVE-2023-2931 [HIGH] CVE-2023-2931: chromium - Use after free in PDF in Google Chrome prior to 114.0.5735.90 allowed a remote a...
Use after free in PDF in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 114.0.5735.90-2~deb12u1)
bullseye: resolved (fixed in 114.0.5735.90-2~deb11u1)
forky: resolved (fixed in 114.0.5735.90-1)
sid: resolved (fixe
debian
CVE-2023-2933P3HIGHCVSS 8.8fixed in chromium 114.0.5735.90-2~deb12u1 (bookworm)2023
CVE-2023-2933 [HIGH] CVE-2023-2933: chromium - Use after free in PDF in Google Chrome prior to 114.0.5735.90 allowed a remote a...
Use after free in PDF in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 114.0.5735.90-2~deb12u1)
bullseye: resolved (fixed in 114.0.5735.90-2~deb11u1)
forky: resolved (fixed in 114.0.5735.90-1)
sid: resolved (fixe
debian
CVE-2022-4174P3HIGHCVSS 8.8fixed in chromium 108.0.5359.71-1 (bookworm)2022
CVE-2022-4174 [HIGH] CVE-2022-4174: chromium - Type confusion in V8 in Google Chrome prior to 108.0.5359.71 allowed a remote at...
Type confusion in V8 in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 108.0.5359.71-1)
bullseye: resolved (fixed in 108.0.5359.71-2~deb11u1)
forky: resolved (fixed in 108.0.5359.71-1)
sid: resolved (fixed in 108
debian
CVE-2023-1818P3HIGHCVSS 8.8fixed in chromium 112.0.5615.49-1 (bookworm)2023
CVE-2023-1818 [HIGH] CVE-2023-1818: chromium - Use after free in Vulkan in Google Chrome prior to 112.0.5615.49 allowed a remot...
Use after free in Vulkan in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 112.0.5615.49-1)
bullseye: resolved (fixed in 112.0.5615.49-2~deb11u2)
forky: resolved (fixed in 112.0.5615.49-1)
sid: resolved (fixed
debian
CVE-2023-2721P3HIGHCVSS 8.8fixed in chromium 113.0.5672.126-1 (bookworm)2023
CVE-2023-2721 [HIGH] CVE-2023-2721: chromium - Use after free in Navigation in Google Chrome prior to 113.0.5672.126 allowed a ...
Use after free in Navigation in Google Chrome prior to 113.0.5672.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
Scope: local
bookworm: resolved (fixed in 113.0.5672.126-1)
bullseye: resolved (fixed in 113.0.5672.126-1~deb11u1)
forky: resolved (fixed in 113.0.5672.126-1)
sid: resolv
debian
CVE-2022-3196P3HIGHCVSS 8.8fixed in chromium 105.0.5195.125-1 (bookworm)2022
CVE-2022-3196 [HIGH] CVE-2022-3196: chromium - Use after free in PDF in Google Chrome prior to 105.0.5195.125 allowed a remote ...
Use after free in PDF in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 105.0.5195.125-1)
bullseye: resolved (fixed in 105.0.5195.125-1~deb11u1)
forky: resolved (fixed in 105.0.5195.125-1)
sid: resolved (fixed in
debian
CVE-2022-3197P3HIGHCVSS 8.8fixed in chromium 105.0.5195.125-1 (bookworm)2022
CVE-2022-3197 [HIGH] CVE-2022-3197: chromium - Use after free in PDF in Google Chrome prior to 105.0.5195.125 allowed a remote ...
Use after free in PDF in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 105.0.5195.125-1)
bullseye: resolved (fixed in 105.0.5195.125-1~deb11u1)
forky: resolved (fixed in 105.0.5195.125-1)
sid: resolved (fixed in
debian
CVE-2023-1533P3HIGHCVSS 8.8fixed in chromium 111.0.5563.110-1 (bookworm)2023
CVE-2023-1533 [HIGH] CVE-2023-1533: chromium - Use after free in WebProtect in Google Chrome prior to 111.0.5563.110 allowed a ...
Use after free in WebProtect in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 111.0.5563.110-1)
bullseye: resolved (fixed in 111.0.5563.110-1~deb11u1)
forky: resolved (fixed in 111.0.5563.110-1)
sid: resolved (
debian