cbcvebase.

Debian Chromium vulnerabilities

2,134 known vulnerabilities affecting debian/chromium.

Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8

Vulnerabilities

Page 38 of 107
CVE-2021-4318P3HIGHCVSS 8.8fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-4318 [HIGH] CVE-2021-4318: chromium - Object corruption in Blink in Google Chrome prior to 94.0.4606.54 allowed a remo... Object corruption in Blink in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 97.0.4692.71-0.1) bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1) forky: resolved (fixed in 97.0.4692.71-0.1) sid: resolved (fi
debian
CVE-2023-1214P3HIGHCVSS 8.8fixed in chromium 111.0.5563.64-1 (bookworm)2023
CVE-2023-1214 [HIGH] CVE-2023-1214: chromium - Type confusion in V8 in Google Chrome prior to 111.0.5563.64 allowed a remote at... Type confusion in V8 in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 111.0.5563.64-1) bullseye: resolved (fixed in 111.0.5563.64-1~deb11u1) forky: resolved (fixed in 111.0.5563.64-1) sid: resolved (fixed in 111
debian
CVE-2022-4181P3HIGHCVSS 8.8fixed in chromium 108.0.5359.71-1 (bookworm)2022
CVE-2022-4181 [HIGH] CVE-2022-4181: chromium - Use after free in Forms in Google Chrome prior to 108.0.5359.71 allowed a remote... Use after free in Forms in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 108.0.5359.71-1) bullseye: resolved (fixed in 108.0.5359.71-2~deb11u1) forky: resolved (fixed in 108.0.5359.71-1) sid: resolved (fixed in
debian
CVE-2022-4437P3HIGHCVSS 8.8fixed in chromium 108.0.5359.124-1 (bookworm)2022
CVE-2022-4437 [HIGH] CVE-2022-4437: chromium - Use after free in Mojo IPC in Google Chrome prior to 108.0.5359.124 allowed a re... Use after free in Mojo IPC in Google Chrome prior to 108.0.5359.124 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 108.0.5359.124-1) bullseye: resolved (fixed in 108.0.5359.124-1~deb11u1) forky: resolved (fixed in 108.0.5359.124-1) sid: resolved (fi
debian
CVE-2023-6707P3HIGHCVSS 8.8fixed in chromium 120.0.6099.109-1~deb12u1 (bookworm)2023
CVE-2023-6707 [HIGH] CVE-2023-6707: chromium - Use after free in CSS in Google Chrome prior to 120.0.6099.109 allowed a remote ... Use after free in CSS in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 120.0.6099.109-1~deb12u1) bullseye: resolved (fixed in 120.0.6099.109-1~deb11u1) forky: resolved (fixed in 120.0.6099.109-1) sid: resolve
debian
CVE-2022-3307P3HIGHCVSS 8.8fixed in chromium 106.0.5249.61-1 (bookworm)2022
CVE-2022-3307 [HIGH] CVE-2022-3307: chromium - Use after free in media in Google Chrome prior to 106.0.5249.62 allowed a remote... Use after free in media in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 106.0.5249.61-1) bullseye: resolved (fixed in 106.0.5249.61-1~deb11u1) forky: resolved (fixed in 106.0.5249.61-1) sid: resolved (fixed in
debian
CVE-2024-5159P3HIGHCVSS 8.8fixed in chromium 125.0.6422.76-1~deb12u1 (bookworm)2024
CVE-2024-5159 [HIGH] CVE-2024-5159: chromium - Heap buffer overflow in ANGLE in Google Chrome prior to 125.0.6422.76 allowed a ... Heap buffer overflow in ANGLE in Google Chrome prior to 125.0.6422.76 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 125.0.6422.76-1~deb12u1) bullseye: open forky: resolved (fixed in 125.0.6422.76-1) sid: resolved (fixed in 125.0.6422.76-1) trixie:
debian
CVE-2023-6706P3HIGHCVSS 8.8fixed in chromium 120.0.6099.109-1~deb12u1 (bookworm)2023
CVE-2023-6706 [HIGH] CVE-2023-6706: chromium - Use after free in FedCM in Google Chrome prior to 120.0.6099.109 allowed a remot... Use after free in FedCM in Google Chrome prior to 120.0.6099.109 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 120.0.6099.109-1~deb12u1) bullseye: resolved (fixed in 120.0.6099.109-1~deb11u1
debian
CVE-2023-0931P3HIGHCVSS 8.8fixed in chromium 110.0.5481.177-1 (bookworm)2023
CVE-2023-0931 [HIGH] CVE-2023-0931: chromium - Use after free in Video in Google Chrome prior to 110.0.5481.177 allowed a remot... Use after free in Video in Google Chrome prior to 110.0.5481.177 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 110.0.5481.177-1) bullseye: resolved (fixed in 110.0.5481.177-1~deb11u1) forky: resolved (fixed in 110.0.5481.177-1) sid: resolved (fixed
debian
CVE-2022-3450P3HIGHCVSS 8.8fixed in chromium 106.0.5249.119-1 (bookworm)2022
CVE-2022-3450 [HIGH] CVE-2022-3450: chromium - Use after free in Peer Connection in Google Chrome prior to 106.0.5249.119 allow... Use after free in Peer Connection in Google Chrome prior to 106.0.5249.119 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 106.0.5249.119-1) bullseye: resolved (fixed in 106.0.5249.119-1~deb11u1) forky: resolved (fixed in 106.0.5249.119-1) sid: resol
debian
CVE-2022-4436P3HIGHCVSS 8.8fixed in chromium 108.0.5359.124-1 (bookworm)2022
CVE-2022-4436 [HIGH] CVE-2022-4436: chromium - Use after free in Blink Media in Google Chrome prior to 108.0.5359.124 allowed a... Use after free in Blink Media in Google Chrome prior to 108.0.5359.124 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 108.0.5359.124-1) bullseye: resolved (fixed in 108.0.5359.124-1~deb11u1) forky: resolved (fixed in 108.0.5359.124-1) sid: resolved
debian
CVE-2021-30603P3HIGHCVSS 7.5fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30603 [HIGH] CVE-2021-30603: chromium - Data race in WebAudio in Google Chrome prior to 92.0.4515.159 allowed a remote a... Data race in WebAudio in Google Chrome prior to 92.0.4515.159 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 93.0.4577.82-1) bullseye: resolved (fixed in 93.0.4577.82-1) forky: resolved (fixed in 93.0.4577.82-1) sid: resolved (fixed in 93.0.4577.82-1) trixie: resolved (fixed in 93.
debian
CVE-2022-3315P3HIGHCVSS 8.8fixed in chromium 106.0.5249.61-1 (bookworm)2022
CVE-2022-3315 [HIGH] CVE-2022-3315: chromium - Type confusion in Blink in Google Chrome prior to 106.0.5249.62 allowed a remote... Type confusion in Blink in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low) Scope: local bookworm: resolved (fixed in 106.0.5249.61-1) bullseye: resolved (fixed in 106.0.5249.61-1~deb11u1) forky: resolved (fixed in 106.0.5249.61-1) sid: resolved (fixed in 1
debian
CVE-2022-3306P3HIGHCVSS 8.8fixed in chromium 106.0.5249.61-1 (bookworm)2022
CVE-2022-3306 [HIGH] CVE-2022-3306: chromium - Use after free in survey in Google Chrome on ChromeOS prior to 106.0.5249.62 all... Use after free in survey in Google Chrome on ChromeOS prior to 106.0.5249.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 106.0.5249.61-1) bullseye: resolved (fixed in 106.0.5249.61-1~deb11u1) forky: resolved (fixed in 106.0.5249.61-1) sid: resolv
debian
CVE-2023-0128P3HIGHCVSS 8.8fixed in chromium 109.0.5414.74-1 (bookworm)2023
CVE-2023-0128 [HIGH] CVE-2023-0128: chromium - Use after free in Overview Mode in Google Chrome on Chrome OS prior to 109.0.541... Use after free in Overview Mode in Google Chrome on Chrome OS prior to 109.0.5414.74 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 109.0.5414.74-1) bullseye: resolved (fixed in 109.0.5414.7
debian
CVE-2023-0928P3HIGHCVSS 8.8fixed in chromium 110.0.5481.177-1 (bookworm)2023
CVE-2023-0928 [HIGH] CVE-2023-0928: chromium - Use after free in SwiftShader in Google Chrome prior to 110.0.5481.177 allowed a... Use after free in SwiftShader in Google Chrome prior to 110.0.5481.177 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 110.0.5481.177-1) bullseye: resolved (fixed in 110.0.5481.177-1~deb11u1) forky: resolved (fixed in 110.0.5481.177-1) sid: resolved
debian
CVE-2022-4439P3HIGHCVSS 8.8fixed in chromium 108.0.5359.124-1 (bookworm)2022
CVE-2022-4439 [HIGH] CVE-2022-4439: chromium - Use after free in Aura in Google Chrome on Windows prior to 108.0.5359.124 allow... Use after free in Aura in Google Chrome on Windows prior to 108.0.5359.124 allowed a remote attacker who convinced the user to engage in specific UI interactions to potentially exploit heap corruption via specific UI interactions. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 108.0.5359.124-1) bullseye: resolved (fixed in 108.0.5359.124
debian
CVE-2022-3305P3HIGHCVSS 8.8fixed in chromium 106.0.5249.61-1 (bookworm)2022
CVE-2022-3305 [HIGH] CVE-2022-3305: chromium - Use after free in survey in Google Chrome on ChromeOS prior to 106.0.5249.62 all... Use after free in survey in Google Chrome on ChromeOS prior to 106.0.5249.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 106.0.5249.61-1) bullseye: resolved (fixed in 106.0.5249.61-1~deb11u1) forky: resolved (fixed in 106.0.5249.61-1) sid: resolv
debian
CVE-2023-0929P3HIGHCVSS 8.8fixed in chromium 110.0.5481.177-1 (bookworm)2023
CVE-2023-0929 [HIGH] CVE-2023-0929: chromium - Use after free in Vulkan in Google Chrome prior to 110.0.5481.177 allowed a remo... Use after free in Vulkan in Google Chrome prior to 110.0.5481.177 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 110.0.5481.177-1) bullseye: resolved (fixed in 110.0.5481.177-1~deb11u1) forky: resolved (fixed in 110.0.5481.177-1) sid: resolved (fixe
debian
CVE-2023-0696P3HIGHCVSS 8.8fixed in chromium 110.0.5481.77-1 (bookworm)2023
CVE-2023-0696 [HIGH] CVE-2023-0696: chromium - Type confusion in V8 in Google Chrome prior to 110.0.5481.77 allowed a remote at... Type confusion in V8 in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 110.0.5481.77-1) bullseye: resolved (fixed in 110.0.5481.77-1~deb11u1) forky: resolved (fixed in 110.0.5481.77-1) sid: resolved (fixed in 110
debian
Debian Chromium vulnerabilities | cvebase