cbcvebase.

Debian Chromium vulnerabilities

2,134 known vulnerabilities affecting debian/chromium.

Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8

Vulnerabilities

Page 4 of 107
CVE-2021-37976P2MEDIUMCVSS 6.5KEVfixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-37976 [MEDIUM] CVE-2021-37976: chromium - Inappropriate implementation in Memory in Google Chrome prior to 94.0.4606.71 al... Inappropriate implementation in Memory in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. Scope: local bookworm: resolved (fixed in 97.0.4692.71-0.1) bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1) forky: resolved (fixed in 97.0.4692.71-0.1) sid: resolved
debian
CVE-2022-2856P2MEDIUMCVSS 6.5KEVfixed in chromium 104.0.5112.101-1 (bookworm)2022
CVE-2022-2856 [MEDIUM] CVE-2022-2856: chromium - Insufficient validation of untrusted input in Intents in Google Chrome on Androi... Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 104.0.5112.101 allowed a remote attacker to arbitrarily browse to a malicious website via a crafted HTML page. Scope: local bookworm: resolved (fixed in 104.0.5112.101-1) bullseye: resolved (fixed in 104.0.5112.101-1~deb11u1) forky: resolved (fixed in 104.0.5112.101-1) sid: r
debian
CVE-2021-38000P2MEDIUMCVSS 6.1KEVfixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-38000 [MEDIUM] CVE-2021-38000: chromium - Insufficient validation of untrusted input in Intents in Google Chrome on Androi... Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 95.0.4638.69 allowed a remote attacker to arbitrarily browser to a malicious URL via a crafted HTML page. Scope: local bookworm: resolved (fixed in 97.0.4692.71-0.1) bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1) forky: resolved (fixed in 97.0.4692.71-0.1) sid: reso
debian
CVE-2020-16040P2MEDIUMCVSS 6.5ExploitedPoCfixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-16040 [MEDIUM] CVE-2020-16040: chromium - Insufficient data validation in V8 in Google Chrome prior to 87.0.4280.88 allowe... Insufficient data validation in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 87.0.4280.88-0.1) bullseye: resolved (fixed in 87.0.4280.88-0.1) forky: resolved (fixed in 87.0.4280.88-0.1) sid: resolved (fixed in 87.0.4280.88-0.1) trixie:
debian
CVE-2025-4664P2MEDIUMCVSS 4.3ExploitedPoCfixed in chromium 136.0.7103.113-1~deb12u1 (bookworm)2025
CVE-2025-4664 [MEDIUM] CVE-2025-4664: chromium - Insufficient policy enforcement in Loader in Google Chrome prior to 136.0.7103.1... Insufficient policy enforcement in Loader in Google Chrome prior to 136.0.7103.113 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 136.0.7103.113-1~deb12u1) bullseye: open forky: resolved (fixed in 136.0.7103.113-1) sid: resolved (fixed in 136.0.7103.113-1) tri
debian
CVE-2022-2295P1HIGHCVSS 8.8ExploitedRansomwarefixed in chromium 103.0.5060.114-1 (bookworm)2022
CVE-2022-2295 [HIGH] CVE-2022-2295: chromium - Type confusion in V8 in Google Chrome prior to 103.0.5060.114 allowed a remote a... Type confusion in V8 in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 103.0.5060.114-1) bullseye: resolved (fixed in 103.0.5060.114-1~deb11u1) forky: resolved (fixed in 103.0.5060.114-1) sid: resolved (fixed in 103.0.5060.114-1) trixie: resolved
debian
CVE-2019-5782P2HIGHCVSS 8.8Exploitedfixed in chromium 72.0.3626.81-1 (bookworm)2019
CVE-2019-5782 [HIGH] CVE-2019-5782: chromium - Incorrect optimization assumptions in V8 in Google Chrome prior to 72.0.3626.81 ... Incorrect optimization assumptions in V8 in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. Scope: local bookworm: resolved (fixed in 72.0.3626.81-1) bullseye: resolved (fixed in 72.0.3626.81-1) forky: resolved (fixed in 72.0.3626.81-1) sid: resolved (fixed in 72.0.3626.81-1) trixie: re
debian
CVE-2020-6453P2HIGHCVSS 8.8Exploitedfixed in chromium 80.0.3987.162-1 (bookworm)2020
CVE-2020-6453 [HIGH] CVE-2020-6453: chromium - Inappropriate implementation in V8 in Google Chrome prior to 80.0.3987.162 allow... Inappropriate implementation in V8 in Google Chrome prior to 80.0.3987.162 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 80.0.3987.162-1) bullseye: resolved (fixed in 80.0.3987.162-1) forky: resolved (fixed in 80.0.3987.162-1) sid: resolved (fixed in 80.0.3987.162-1) trixie: resolve
debian
CVE-2022-0456P2HIGHCVSS 8.8Exploitedfixed in chromium 98.0.4758.80-1 (bookworm)2022
CVE-2022-0456 [HIGH] CVE-2022-0456: chromium - Use after free in Web Search in Google Chrome prior to 98.0.4758.80 allowed a re... Use after free in Web Search in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to potentially exploit heap corruption via profile destruction. Scope: local bookworm: resolved (fixed in 98.0.4758.80-1) bullseye: resolved (fixed in 98.0.4758.80-1~deb11u1) forky: resolved (fixed in 98.0.4758.80-1) sid: resolved (fixed in 98.0.4758.80-1) trixie: resolved (
debian
CVE-2021-30538P2MEDIUMCVSS 4.3Exploitedfixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30538 [MEDIUM] CVE-2021-30538: chromium - Insufficient policy enforcement in content security policy in Google Chrome prio... Insufficient policy enforcement in content security policy in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass content security policy via a crafted HTML page. Scope: local bookworm: resolved (fixed in 93.0.4577.82-1) bullseye: resolved (fixed in 93.0.4577.82-1) forky: resolved (fixed in 93.0.4577.82-1) sid: resolved (fixed in 93.0.4577.82-
debian
CVE-2019-5840P2MEDIUMCVSS 4.3Exploitedfixed in chromium 75.0.3770.80-1 (bookworm)2019
CVE-2019-5840 [MEDIUM] CVE-2019-5840: chromium - Incorrect security UI in popup blocker in Google Chrome on iOS prior to 75.0.377... Incorrect security UI in popup blocker in Google Chrome on iOS prior to 75.0.3770.80 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. Scope: local bookworm: resolved (fixed in 75.0.3770.80-1) bullseye: resolved (fixed in 75.0.3770.80-1) forky: resolved (fixed in 75.0.3770.80-1) sid: resolved (fixed in 75.0.3770.80-1) trixie: reso
debian
CVE-2020-6507P2HIGHCVSS 8.8PoCfixed in chromium 83.0.4103.106-1 (bookworm)2020
CVE-2020-6507 [HIGH] CVE-2020-6507: chromium - Out of bounds write in V8 in Google Chrome prior to 83.0.4103.106 allowed a remo... Out of bounds write in V8 in Google Chrome prior to 83.0.4103.106 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 83.0.4103.106-1) bullseye: resolved (fixed in 83.0.4103.106-1) forky: resolved (fixed in 83.0.4103.106-1) sid: resolved (fixed in 83.0.4103.106-1) trixie: resolved (fixed
debian
CVE-2019-5789P2HIGHCVSS 8.8PoCfixed in chromium 73.0.3683.75-1 (bookworm)2019
CVE-2019-5789 [HIGH] CVE-2019-5789: chromium - An integer overflow that leads to a use-after-free in WebMIDI in Google Chrome o... An integer overflow that leads to a use-after-free in WebMIDI in Google Chrome on Windows prior to 73.0.3683.75 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. Scope: local bookworm: resolved (fixed in 73.0.3683.75-1) bullseye: resolved (fixed in 73.0.3683.75-1) forky: resolved (fixed in 73.0.3683.
debian
CVE-2019-5788P2HIGHCVSS 8.8PoCfixed in chromium 73.0.3683.75-1 (bookworm)2019
CVE-2019-5788 [HIGH] CVE-2019-5788: chromium - An integer overflow that leads to a use-after-free in Blink Storage in Google Ch... An integer overflow that leads to a use-after-free in Blink Storage in Google Chrome on Linux prior to 73.0.3683.75 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. Scope: local bookworm: resolved (fixed in 73.0.3683.75-1) bullseye: resolved (fixed in 73.0.3683.75-1) forky: resolved (fixed in 73.0.3
debian
CVE-2022-0306P2HIGHCVSS 8.8fixed in chromium 97.0.4692.99-1 (bookworm)2022
CVE-2022-0306 [HIGH] CVE-2022-0306: chromium - Heap buffer overflow in PDFium in Google Chrome prior to 97.0.4692.99 allowed a ... Heap buffer overflow in PDFium in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 97.0.4692.99-1) bullseye: resolved (fixed in 97.0.4692.99-1~deb11u2) forky: resolved (fixed in 97.0.4692.99-1) sid: resolved (fixed in 97.0.4692.99-1) trixie: resolved
debian
CVE-2023-3420P2HIGHCVSS 8.8fixed in chromium 114.0.5735.198-1~deb12u1 (bookworm)2023
CVE-2023-3420 [HIGH] CVE-2023-3420: chromium - Type Confusion in V8 in Google Chrome prior to 114.0.5735.198 allowed a remote a... Type Confusion in V8 in Google Chrome prior to 114.0.5735.198 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 114.0.5735.198-1~deb12u1) bullseye: resolved (fixed in 114.0.5735.198-1~deb11u1) forky: resolved (fixed in 114.0.5735.198-1) sid: resolved (
debian
CVE-2020-6404P3HIGHCVSS 8.8PoCfixed in chromium 80.0.3987.106-1 (bookworm)2020
CVE-2020-6404 [HIGH] CVE-2020-6404: chromium - Inappropriate implementation in Blink in Google Chrome prior to 80.0.3987.87 all... Inappropriate implementation in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 80.0.3987.106-1) bullseye: resolved (fixed in 80.0.3987.106-1) forky: resolved (fixed in 80.0.3987.106-1) sid: resolved (fixed in 80.0.3987.106-1) trixie: resol
debian
CVE-2023-6702P2HIGHCVSS 8.8fixed in chromium 120.0.6099.109-1~deb12u1 (bookworm)2023
CVE-2023-6702 [HIGH] CVE-2023-6702: chromium - Type confusion in V8 in Google Chrome prior to 120.0.6099.109 allowed a remote a... Type confusion in V8 in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 120.0.6099.109-1~deb12u1) bullseye: resolved (fixed in 120.0.6099.109-1~deb11u1) forky: resolved (fixed in 120.0.6099.109-1) sid: resolved (
debian
CVE-2019-5796P3HIGHCVSS 7.5PoCfixed in chromium 73.0.3683.75-1 (bookworm)2019
CVE-2019-5796 [HIGH] CVE-2019-5796: chromium - Data race in extensions guest view in Google Chrome prior to 73.0.3683.75 allowe... Data race in extensions guest view in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 73.0.3683.75-1) bullseye: resolved (fixed in 73.0.3683.75-1) forky: resolved (fixed in 73.0.3683.75-1) sid: resolved (fixed in 73.0.3683.75-1) trixie: resolved (fi
debian
CVE-2023-4357P2HIGHCVSS 8.8fixed in chromium 116.0.5845.96-1~deb12u1 (bookworm)2023
CVE-2023-4357 [HIGH] CVE-2023-4357: chromium - Insufficient validation of untrusted input in XML in Google Chrome prior to 116.... Insufficient validation of untrusted input in XML in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to bypass file access restrictions via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 116.0.5845.96-1~deb12u1) bullseye: resolved (fixed in 116.0.5845.96-1~deb11u1) forky: resolved (fixed in 116.0.584
debian
Debian Chromium vulnerabilities | cvebase