cbcvebase.

Debian Chromium vulnerabilities

2,134 known vulnerabilities affecting debian/chromium.

Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8

Vulnerabilities

Page 37 of 107
CVE-2023-2722P3HIGHCVSS 8.8fixed in chromium 113.0.5672.126-1 (bookworm)2023
CVE-2023-2722 [HIGH] CVE-2023-2722: chromium - Use after free in Autofill UI in Google Chrome on Android prior to 113.0.5672.12... Use after free in Autofill UI in Google Chrome on Android prior to 113.0.5672.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 113.0.5672.126-1) bullseye: resolved (fixed in 113.0.5672.126-1~deb11u1) forky: resolved (fixed in 113.0.5672.126-1) sid
debian
CVE-2022-3370P3HIGHCVSS 8.8fixed in chromium 106.0.5249.91-1 (bookworm)2022
CVE-2022-3370 [HIGH] CVE-2022-3370: chromium - Use after free in Custom Elements in Google Chrome prior to 106.0.5249.91 allowe... Use after free in Custom Elements in Google Chrome prior to 106.0.5249.91 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 106.0.5249.91-1) bullseye: resolved (fixed in 106.0.5249.91-1~deb11u1) forky: resolved (fixed in 106.0.5249.91-1) sid: resolved
debian
CVE-2023-2312P3HIGHCVSS 8.8fixed in chromium 116.0.5845.96-1~deb12u1 (bookworm)2023
CVE-2023-2312 [HIGH] CVE-2023-2312: chromium - Use after free in Offline in Google Chrome on Android prior to 116.0.5845.96 all... Use after free in Offline in Google Chrome on Android prior to 116.0.5845.96 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 116.0.5845.96-1~deb12u1) bullseye: resolved (fixed in 116.0.5845.96-1~deb11u1) forky
debian
CVE-2023-1530P3HIGHCVSS 8.8fixed in chromium 111.0.5563.110-1 (bookworm)2023
CVE-2023-1530 [HIGH] CVE-2023-1530: chromium - Use after free in PDF in Google Chrome prior to 111.0.5563.110 allowed a remote ... Use after free in PDF in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 111.0.5563.110-1) bullseye: resolved (fixed in 111.0.5563.110-1~deb11u1) forky: resolved (fixed in 111.0.5563.110-1) sid: resolved (fixed i
debian
CVE-2024-1674P3HIGHCVSS 8.8fixed in chromium 122.0.6261.57-1~deb12u1 (bookworm)2024
CVE-2024-1674 [HIGH] CVE-2024-1674: chromium - Inappropriate implementation in Navigation in Google Chrome prior to 122.0.6261.... Inappropriate implementation in Navigation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 122.0.6261.57-1~deb12u1) bullseye: open forky: resolved (fixed in 122.0.6261.57-1) sid: resolved (fixed in 122.0.6261.57-1
debian
CVE-2022-3885P3HIGHCVSS 8.8fixed in chromium 107.0.5304.110-1 (bookworm)2022
CVE-2022-3885 [HIGH] CVE-2022-3885: chromium - Use after free in V8 in Google Chrome prior to 107.0.5304.106 allowed a remote a... Use after free in V8 in Google Chrome prior to 107.0.5304.106 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 107.0.5304.110-1) bullseye: resolved (fixed in 107.0.5304.110-1~deb11u1) forky: resolved (fixed in 107.0.5304.110-1) sid: resolved (fixed in
debian
CVE-2023-1528P3HIGHCVSS 8.8fixed in chromium 111.0.5563.110-1 (bookworm)2023
CVE-2023-1528 [HIGH] CVE-2023-1528: chromium - Use after free in Passwords in Google Chrome prior to 111.0.5563.110 allowed a r... Use after free in Passwords in Google Chrome prior to 111.0.5563.110 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 111.0.5563.110-1) bullseye: resolved (fixed in 111.0.5563.110-1~deb11u1) forky: resolved (fi
debian
CVE-2023-2461P3HIGHCVSS 8.8fixed in chromium 113.0.5672.63-1 (bookworm)2023
CVE-2023-2461 [HIGH] CVE-2023-2461: chromium - Use after free in OS Inputs in Google Chrome on ChromeOS prior to 113.0.5672.63 ... Use after free in OS Inputs in Google Chrome on ChromeOS prior to 113.0.5672.63 allowed a remote attacker who convinced a user to enage in specific UI interaction to potentially exploit heap corruption via crafted UI interaction. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 113.0.5672.63-1) bullseye: resolved (fixed in 113.0.5672.63-
debian
CVE-2024-7255P3HIGHCVSS 8.8fixed in chromium 127.0.6533.88-1~deb12u1 (bookworm)2024
CVE-2024-7255 [HIGH] CVE-2024-7255: chromium - Out of bounds read in WebTransport in Google Chrome prior to 127.0.6533.88 allow... Out of bounds read in WebTransport in Google Chrome prior to 127.0.6533.88 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 127.0.6533.88-1~deb12u1) bullseye: open forky: resolved (fixed in 127.0.6533.88-1) sid: resolved (fixed in 127.0.65
debian
CVE-2023-0471P3HIGHCVSS 8.8fixed in chromium 109.0.5414.119-1 (bookworm)2023
CVE-2023-0471 [HIGH] CVE-2023-0471: chromium - Use after free in WebTransport in Google Chrome prior to 109.0.5414.119 allowed ... Use after free in WebTransport in Google Chrome prior to 109.0.5414.119 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 109.0.5414.119-1) bullseye: resolved (fixed in 109.0.5414.119-1~deb11u1) forky: resolved (fixed in 109.0.5414.119-1) sid: resolved
debian
CVE-2022-3889P3HIGHCVSS 8.8fixed in chromium 107.0.5304.110-1 (bookworm)2022
CVE-2022-3889 [HIGH] CVE-2022-3889: chromium - Type confusion in V8 in Google Chrome prior to 107.0.5304.106 allowed a remote a... Type confusion in V8 in Google Chrome prior to 107.0.5304.106 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 107.0.5304.110-1) bullseye: resolved (fixed in 107.0.5304.110-1~deb11u1) forky: resolved (fixed in 107.0.5304.110-1) sid: resolved (fixed in
debian
CVE-2022-3445P3HIGHCVSS 8.8fixed in chromium 106.0.5249.119-1 (bookworm)2022
CVE-2022-3445 [HIGH] CVE-2022-3445: chromium - Use after free in Skia in Google Chrome prior to 106.0.5249.119 allowed a remote... Use after free in Skia in Google Chrome prior to 106.0.5249.119 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 106.0.5249.119-1) bullseye: resolved (fixed in 106.0.5249.119-1~deb11u1) forky: resolved (fixed in 106.0.5249.119-1) sid: resolved (fixed
debian
CVE-2023-3730P3HIGHCVSS 8.8fixed in chromium 115.0.5790.98-1~deb12u1 (bookworm)2023
CVE-2023-3730 [HIGH] CVE-2023-3730: chromium - Use after free in Tab Groups in Google Chrome prior to 115.0.5790.98 allowed a r... Use after free in Tab Groups in Google Chrome prior to 115.0.5790.98 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 115.0.5790.98-1~deb12u1) bullseye: resolved (fixed in 115.0.5790.98-1~deb1
debian
CVE-2022-3886P3HIGHCVSS 8.8fixed in chromium 107.0.5304.110-1 (bookworm)2022
CVE-2022-3886 [HIGH] CVE-2022-3886: chromium - Use after free in Speech Recognition in Google Chrome prior to 107.0.5304.106 al... Use after free in Speech Recognition in Google Chrome prior to 107.0.5304.106 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 107.0.5304.110-1) bullseye: resolved (fixed in 107.0.5304.110-1~deb11u1) forky: resolved (fixed in 107.0.5304.110-1) sid: re
debian
CVE-2022-4175P3HIGHCVSS 8.8fixed in chromium 108.0.5359.71-1 (bookworm)2022
CVE-2022-4175 [HIGH] CVE-2022-4175: chromium - Use after free in Camera Capture in Google Chrome prior to 108.0.5359.71 allowed... Use after free in Camera Capture in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 108.0.5359.71-1) bullseye: resolved (fixed in 108.0.5359.71-2~deb11u1) forky: resolved (fixed in 108.0.5359.71-1) sid: resolved (
debian
CVE-2022-3652P3HIGHCVSS 8.8fixed in chromium 107.0.5304.68-1 (bookworm)2022
CVE-2022-3652 [HIGH] CVE-2022-3652: chromium - Type confusion in V8 in Google Chrome prior to 107.0.5304.62 allowed a remote at... Type confusion in V8 in Google Chrome prior to 107.0.5304.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 107.0.5304.68-1) bullseye: resolved (fixed in 107.0.5304.68-1~deb11u1) forky: resolved (fixed in 107.0.5304.68-1) sid: resolved (fixed in 107
debian
CVE-2022-3888P3HIGHCVSS 8.8fixed in chromium 107.0.5304.110-1 (bookworm)2022
CVE-2022-3888 [HIGH] CVE-2022-3888: chromium - Use after free in WebCodecs in Google Chrome prior to 107.0.5304.106 allowed a r... Use after free in WebCodecs in Google Chrome prior to 107.0.5304.106 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 107.0.5304.110-1) bullseye: resolved (fixed in 107.0.5304.110-1~deb11u1) forky: resolved (fixed in 107.0.5304.110-1) sid: resolved (f
debian
CVE-2023-0472P3HIGHCVSS 8.8fixed in chromium 109.0.5414.119-1 (bookworm)2023
CVE-2023-0472 [HIGH] CVE-2023-0472: chromium - Use after free in WebRTC in Google Chrome prior to 109.0.5414.119 allowed a remo... Use after free in WebRTC in Google Chrome prior to 109.0.5414.119 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 109.0.5414.119-1) bullseye: resolved (fixed in 109.0.5414.119-1~deb11u1) forky: resolved (fixed in 109.0.5414.119-1) sid: resolved (fixe
debian
CVE-2022-3304P3HIGHCVSS 8.8fixed in chromium 106.0.5249.61-1 (bookworm)2022
CVE-2022-3304 [HIGH] CVE-2022-3304: chromium - Use after free in CSS in Google Chrome prior to 106.0.5249.62 allowed a remote a... Use after free in CSS in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 106.0.5249.61-1) bullseye: resolved (fixed in 106.0.5249.61-1~deb11u1) forky: resolved (fixed in 106.0.5249.61-1) sid: resolved (fixed in 10
debian
CVE-2023-0473P3HIGHCVSS 8.8fixed in chromium 109.0.5414.119-1 (bookworm)2023
CVE-2023-0473 [HIGH] CVE-2023-0473: chromium - Type Confusion in ServiceWorker API in Google Chrome prior to 109.0.5414.119 all... Type Confusion in ServiceWorker API in Google Chrome prior to 109.0.5414.119 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 109.0.5414.119-1) bullseye: resolved (fixed in 109.0.5414.119-1~deb11u1) forky: resolved (fixed in 109.0.5414.119-1) sid: r
debian
Debian Chromium vulnerabilities | cvebase