Debian Chromium vulnerabilities
2,134 known vulnerabilities affecting debian/chromium.
Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8
Vulnerabilities
Page 41 of 107
CVE-2020-6407P3HIGHCVSS 8.8fixed in chromium 80.0.3987.122-1 (bookworm)2020
CVE-2020-6407 [HIGH] CVE-2020-6407: chromium - Out of bounds memory access in streams in Google Chrome prior to 80.0.3987.122 a...
Out of bounds memory access in streams in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 80.0.3987.122-1)
bullseye: resolved (fixed in 80.0.3987.122-1)
forky: resolved (fixed in 80.0.3987.122-1)
sid: resolved (fixed in 80.0.3987.122-1)
trixie: res
debian
CVE-2020-6409P3HIGHCVSS 8.8fixed in chromium 80.0.3987.106-1 (bookworm)2020
CVE-2020-6409 [HIGH] CVE-2020-6409: chromium - Inappropriate implementation in Omnibox in Google Chrome prior to 80.0.3987.87 a...
Inappropriate implementation in Omnibox in Google Chrome prior to 80.0.3987.87 allowed a remote attacker who convinced the user to enter a URI to bypass navigation restrictions via a crafted domain name.
Scope: local
bookworm: resolved (fixed in 80.0.3987.106-1)
bullseye: resolved (fixed in 80.0.3987.106-1)
forky: resolved (fixed in 80.0.3987.106-1)
sid: resolved (fi
debian
CVE-2020-6389P3HIGHCVSS 8.8fixed in chromium 80.0.3987.106-1 (bookworm)2020
CVE-2020-6389 [HIGH] CVE-2020-6389: chromium - Out of bounds write in WebRTC in Google Chrome prior to 80.0.3987.87 allowed a r...
Out of bounds write in WebRTC in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted video stream.
Scope: local
bookworm: resolved (fixed in 80.0.3987.106-1)
bullseye: resolved (fixed in 80.0.3987.106-1)
forky: resolved (fixed in 80.0.3987.106-1)
sid: resolved (fixed in 80.0.3987.106-1)
trixie: resolved (
debian
CVE-2020-6474P3HIGHCVSS 8.8fixed in chromium 83.0.4103.83-1 (bookworm)2020
CVE-2020-6474 [HIGH] CVE-2020-6474: chromium - Use after free in Blink in Google Chrome prior to 83.0.4103.61 allowed a remote ...
Use after free in Blink in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 83.0.4103.83-1)
bullseye: resolved (fixed in 83.0.4103.83-1)
forky: resolved (fixed in 83.0.4103.83-1)
sid: resolved (fixed in 83.0.4103.83-1)
trixie: resolved (fixed in 83.0
debian
CVE-2020-6448P3HIGHCVSS 8.8fixed in chromium 81.0.4044.92-1 (bookworm)2020
CVE-2020-6448 [HIGH] CVE-2020-6448: chromium - Use after free in V8 in Google Chrome prior to 81.0.4044.92 allowed a remote att...
Use after free in V8 in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 81.0.4044.92-1)
bullseye: resolved (fixed in 81.0.4044.92-1)
forky: resolved (fixed in 81.0.4044.92-1)
sid: resolved (fixed in 81.0.4044.92-1)
trixie: resolved (fixed in 81.0.40
debian
CVE-2020-6386P3HIGHCVSS 8.8fixed in chromium 80.0.3987.116-1 (bookworm)2020
CVE-2020-6386 [HIGH] CVE-2020-6386: chromium - Use after free in speech in Google Chrome prior to 80.0.3987.116 allowed a remot...
Use after free in speech in Google Chrome prior to 80.0.3987.116 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 80.0.3987.116-1)
bullseye: resolved (fixed in 80.0.3987.116-1)
forky: resolved (fixed in 80.0.3987.116-1)
sid: resolved (fixed in 80.0.3987.116-1)
trixie: resolved (fixed i
debian
CVE-2020-6423P3HIGHCVSS 8.8fixed in chromium 81.0.4044.92-1 (bookworm)2020
CVE-2020-6423 [HIGH] CVE-2020-6423: chromium - Use after free in audio in Google Chrome prior to 81.0.4044.92 allowed a remote ...
Use after free in audio in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 81.0.4044.92-1)
bullseye: resolved (fixed in 81.0.4044.92-1)
forky: resolved (fixed in 81.0.4044.92-1)
sid: resolved (fixed in 81.0.4044.92-1)
trixie: resolved (fixed in 81.0
debian
CVE-2020-6384P3HIGHCVSS 8.8fixed in chromium 80.0.3987.116-1 (bookworm)2020
CVE-2020-6384 [HIGH] CVE-2020-6384: chromium - Use after free in WebAudio in Google Chrome prior to 80.0.3987.116 allowed a rem...
Use after free in WebAudio in Google Chrome prior to 80.0.3987.116 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 80.0.3987.116-1)
bullseye: resolved (fixed in 80.0.3987.116-1)
forky: resolved (fixed in 80.0.3987.116-1)
sid: resolved (fixed in 80.0.3987.116-1)
trixie: resolved (fixed
debian
CVE-2018-18337P3HIGHCVSS 8.8fixed in chromium 71.0.3578.80-1 (bookworm)2018
CVE-2018-18337 [HIGH] CVE-2018-18337: chromium - Incorrect handling of stylesheets leading to a use after free in Blink in Google...
Incorrect handling of stylesheets leading to a use after free in Blink in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 71.0.3578.80-1)
bullseye: resolved (fixed in 71.0.3578.80-1)
forky: resolved (fixed in 71.0.3578.80-1)
sid: resolved (fixed i
debian
CVE-2020-6467P3HIGHCVSS 8.8fixed in chromium 83.0.4103.83-1 (bookworm)2020
CVE-2020-6467 [HIGH] CVE-2020-6467: chromium - Use after free in WebRTC in Google Chrome prior to 83.0.4103.61 allowed a remote...
Use after free in WebRTC in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 83.0.4103.83-1)
bullseye: resolved (fixed in 83.0.4103.83-1)
forky: resolved (fixed in 83.0.4103.83-1)
sid: resolved (fixed in 83.0.4103.83-1)
trixie: resolved (fixed in 83.
debian
CVE-2019-5758P3HIGHCVSS 8.8fixed in chromium 72.0.3626.81-1 (bookworm)2019
CVE-2019-5758 [HIGH] CVE-2019-5758: chromium - Incorrect object lifecycle management in Blink in Google Chrome prior to 72.0.36...
Incorrect object lifecycle management in Blink in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 72.0.3626.81-1)
bullseye: resolved (fixed in 72.0.3626.81-1)
forky: resolved (fixed in 72.0.3626.81-1)
sid: resolved (fixed in 72.0.3626.81-1)
trixie:
debian
CVE-2021-37972P3HIGHCVSS 8.8fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-37972 [HIGH] CVE-2021-37972: chromium - Out of bounds read in libjpeg-turbo in Google Chrome prior to 94.0.4606.54 allow...
Out of bounds read in libjpeg-turbo in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 97.0.4692.71-0.1)
bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1)
forky: resolved (fixed in 97.0.4692.71-0.1)
sid: resolved (fixed in 97.0.4692.71-0.1)
t
debian
CVE-2020-6434P3HIGHCVSS 8.8fixed in chromium 81.0.4044.92-1 (bookworm)2020
CVE-2020-6434 [HIGH] CVE-2020-6434: chromium - Use after free in devtools in Google Chrome prior to 81.0.4044.92 allowed a remo...
Use after free in devtools in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 81.0.4044.92-1)
bullseye: resolved (fixed in 81.0.4044.92-1)
forky: resolved (fixed in 81.0.4044.92-1)
sid: resolved (fixed in 81.0.4044.92-1)
trixie: resolved (fixed in 8
debian
CVE-2020-6436P3HIGHCVSS 8.8fixed in chromium 81.0.4044.92-1 (bookworm)2020
CVE-2020-6436 [HIGH] CVE-2020-6436: chromium - Use after free in window management in Google Chrome prior to 81.0.4044.92 allow...
Use after free in window management in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 81.0.4044.92-1)
bullseye: resolved (fixed in 81.0.4044.92-1)
forky: resolved (fixed in 81.0.4044.92-1)
sid: resolved (fixed in 81.0.4044.92-1)
trixie: resolved (f
debian
CVE-2019-13728P3HIGHCVSS 8.8fixed in chromium 79.0.3945.79-1 (bookworm)2019
CVE-2019-13728 [HIGH] CVE-2019-13728: chromium - Out of bounds write in JavaScript in Google Chrome prior to 79.0.3945.79 allowed...
Out of bounds write in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 79.0.3945.79-1)
bullseye: resolved (fixed in 79.0.3945.79-1)
forky: resolved (fixed in 79.0.3945.79-1)
sid: resolved (fixed in 79.0.3945.79-1)
trixie: resolved (f
debian
CVE-2019-5809P3HIGHCVSS 8.8fixed in chromium 74.0.3729.108-1 (bookworm)2019
CVE-2019-5809 [HIGH] CVE-2019-5809: chromium - Use after free in file chooser in Google Chrome prior to 74.0.3729.108 allowed a...
Use after free in file chooser in Google Chrome prior to 74.0.3729.108 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 74.0.3729.108-1)
bullseye: resolved (fixed in 74.0.3729.108-1)
forky: resolved (fixed in 74.0.3729.108-1)
sid: resolved (fixed in 74
debian
CVE-2020-6553P3HIGHCVSS 8.8fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-6553 [HIGH] CVE-2020-6553: chromium - Use after free in offline mode in Google Chrome on iOS prior to 84.0.4147.125 al...
Use after free in offline mode in Google Chrome on iOS prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (fixed in 87.0.4280.88-0.1)
trixie:
debian
CVE-2020-6552P3HIGHCVSS 8.8fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-6552 [HIGH] CVE-2020-6552: chromium - Use after free in Blink in Google Chrome prior to 84.0.4147.125 allowed a remote...
Use after free in Blink in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (fixed in 87.0.4280.88-0.1)
trixie: resolved (fixe
debian
CVE-2019-5774P3HIGHCVSS 8.8fixed in chromium 72.0.3626.81-1 (bookworm)2019
CVE-2019-5774 [HIGH] CVE-2019-5774: chromium - Omission of the .desktop filetype from the Safe Browsing checklist in SafeBrowsi...
Omission of the .desktop filetype from the Safe Browsing checklist in SafeBrowsing in Google Chrome on Linux prior to 72.0.3626.81 allowed an attacker who convinced a user to download a .desktop file to execute arbitrary code via a downloaded .desktop file.
Scope: local
bookworm: resolved (fixed in 72.0.3626.81-1)
bullseye: resolved (fixed in 72.0.3626.81-1)
forky: r
debian
CVE-2020-6540P3HIGHCVSS 8.8fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-6540 [HIGH] CVE-2020-6540: chromium - Buffer overflow in Skia in Google Chrome prior to 84.0.4147.105 allowed a remote...
Buffer overflow in Skia in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (fixed in 87.0.4280.88-0.1)
trixie: resolved (fixe
debian