Debian Chromium vulnerabilities
2,134 known vulnerabilities affecting debian/chromium.
Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8
Vulnerabilities
Page 42 of 107
CVE-2020-16004P3HIGHCVSS 8.8fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-16004 [HIGH] CVE-2020-16004: chromium - Use after free in user interface in Google Chrome prior to 86.0.4240.183 allowed...
Use after free in user interface in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (fixed in 87.0.4280.88-0.1)
trixie: res
debian
CVE-2021-21135P3MEDIUMCVSS 6.5fixed in chromium 88.0.4324.96-0.1 (bookworm)2021
CVE-2021-21135 [MEDIUM] CVE-2021-21135: chromium - Inappropriate implementation in Performance API in Google Chrome prior to 88.0.4...
Inappropriate implementation in Performance API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 88.0.4324.96-0.1)
bullseye: resolved (fixed in 88.0.4324.96-0.1)
forky: resolved (fixed in 88.0.4324.96-0.1)
sid: resolved (fixed in 88.0.4324.96-0.1)
trixie:
debian
CVE-2021-21192P3HIGHCVSS 8.8fixed in chromium 89.0.4389.90-1 (bookworm)2021
CVE-2021-21192 [HIGH] CVE-2021-21192: chromium - Heap buffer overflow in tab groups in Google Chrome prior to 89.0.4389.90 allowe...
Heap buffer overflow in tab groups in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 89.0.4389.90-1)
bullseye: resolved (fixed in 89.0.4389.90-1)
forky: resolved (fixed in 89.0.4389.90-1)
sid: resolved (fixed in 89.0.4389.90-1)
trixie: resolved (
debian
CVE-2021-21113P3HIGHCVSS 8.8fixed in chromium 87.0.4280.141-0.1 (bookworm)2021
CVE-2021-21113 [HIGH] CVE-2021-21113: chromium - Heap buffer overflow in Skia in Google Chrome prior to 87.0.4280.141 allowed a r...
Heap buffer overflow in Skia in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.141-0.1)
bullseye: resolved (fixed in 87.0.4280.141-0.1)
forky: resolved (fixed in 87.0.4280.141-0.1)
sid: resolved (fixed in 87.0.4280.141-0.1)
trixie: res
debian
CVE-2020-16003P3HIGHCVSS 8.8fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-16003 [HIGH] CVE-2020-16003: chromium - Use after free in printing in Google Chrome prior to 86.0.4240.111 allowed a rem...
Use after free in printing in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (fixed in 87.0.4280.88-0.1)
trixie: resolved
debian
CVE-2021-21195P3HIGHCVSS 8.8fixed in chromium 89.0.4389.114-1 (bookworm)2021
CVE-2021-21195 [HIGH] CVE-2021-21195: chromium - Use after free in V8 in Google Chrome prior to 89.0.4389.114 allowed a remote at...
Use after free in V8 in Google Chrome prior to 89.0.4389.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 89.0.4389.114-1)
bullseye: resolved (fixed in 89.0.4389.114-1)
forky: resolved (fixed in 89.0.4389.114-1)
sid: resolved (fixed in 89.0.4389.114-1)
trixie: resolved (fixed in
debian
CVE-2021-21116P3HIGHCVSS 8.8fixed in chromium 87.0.4280.141-0.1 (bookworm)2021
CVE-2021-21116 [HIGH] CVE-2021-21116: chromium - Heap buffer overflow in audio in Google Chrome prior to 87.0.4280.141 allowed a ...
Heap buffer overflow in audio in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.141-0.1)
bullseye: resolved (fixed in 87.0.4280.141-0.1)
forky: resolved (fixed in 87.0.4280.141-0.1)
sid: resolved (fixed in 87.0.4280.141-0.1)
trixie: re
debian
CVE-2021-30522P3HIGHCVSS 8.8fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30522 [HIGH] CVE-2021-30522: chromium - Use after free in WebAudio in Google Chrome prior to 91.0.4472.77 allowed a remo...
Use after free in WebAudio in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 93.0.4577.82-1)
bullseye: resolved (fixed in 93.0.4577.82-1)
forky: resolved (fixed in 93.0.4577.82-1)
sid: resolved (fixed in 93.0.4577.82-1)
trixie: resolved (fixed in
debian
CVE-2021-4062P3HIGHCVSS 8.8fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-4062 [HIGH] CVE-2021-4062: chromium - Heap buffer overflow in BFCache in Google Chrome prior to 96.0.4664.93 allowed a...
Heap buffer overflow in BFCache in Google Chrome prior to 96.0.4664.93 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 97.0.4692.71-0.1)
bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1)
forky: resolved (fixed in 97.0.4692.71-0.1)
sid: res
debian
CVE-2021-30564P3HIGHCVSS 8.8fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30564 [HIGH] CVE-2021-30564: chromium - Heap buffer overflow in WebXR in Google Chrome prior to 91.0.4472.164 allowed a ...
Heap buffer overflow in WebXR in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 93.0.4577.82-1)
bullseye: resolved (fixed in 93.0.4577.82-1)
forky: resolved (fixed in 93.0.4577.82-1)
sid: resolved (fixed in 93.0.4577.82-1)
trixie: resolved (fixe
debian
CVE-2021-21169P3HIGHCVSS 8.8fixed in chromium 89.0.4389.82-1 (bookworm)2021
CVE-2021-21169 [HIGH] CVE-2021-21169: chromium - Out of bounds memory access in V8 in Google Chrome prior to 89.0.4389.72 allowed...
Out of bounds memory access in V8 in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 89.0.4389.82-1)
bullseye: resolved (fixed in 89.0.4389.82-1)
forky: resolved (fixed in 89.0.4389.82-1)
sid: resolved (fixed in 89.0.4389.82-1)
trixie:
debian
CVE-2021-21179P3HIGHCVSS 8.8fixed in chromium 89.0.4389.82-1 (bookworm)2021
CVE-2021-21179 [HIGH] CVE-2021-21179: chromium - Use after free in Network Internals in Google Chrome on Linux prior to 89.0.4389...
Use after free in Network Internals in Google Chrome on Linux prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 89.0.4389.82-1)
bullseye: resolved (fixed in 89.0.4389.82-1)
forky: resolved (fixed in 89.0.4389.82-1)
sid: resolved (fixed in 89.0.4389.82-1)
trixie:
debian
CVE-2020-15990P3HIGHCVSS 8.8fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-15990 [HIGH] CVE-2020-15990: chromium - Use after free in autofill in Google Chrome prior to 86.0.4240.75 allowed a remo...
Use after free in autofill in Google Chrome prior to 86.0.4240.75 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (fix
debian
CVE-2021-4058P3HIGHCVSS 8.8fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-4058 [HIGH] CVE-2021-4058: chromium - Heap buffer overflow in ANGLE in Google Chrome prior to 96.0.4664.93 allowed a r...
Heap buffer overflow in ANGLE in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 97.0.4692.71-0.1)
bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1)
forky: resolved (fixed in 97.0.4692.71-0.1)
sid: resolved (fixed in 97.0.4692.71-0.1)
trixie: r
debian
CVE-2021-21167P3HIGHCVSS 8.8fixed in chromium 89.0.4389.82-1 (bookworm)2021
CVE-2021-21167 [HIGH] CVE-2021-21167: chromium - Use after free in bookmarks in Google Chrome prior to 89.0.4389.72 allowed a rem...
Use after free in bookmarks in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 89.0.4389.82-1)
bullseye: resolved (fixed in 89.0.4389.82-1)
forky: resolved (fixed in 89.0.4389.82-1)
sid: resolved (fixed in 89.0.4389.82-1)
trixie: resolved (fixed i
debian
CVE-2021-21162P3HIGHCVSS 8.8fixed in chromium 89.0.4389.82-1 (bookworm)2021
CVE-2021-21162 [HIGH] CVE-2021-21162: chromium - Use after free in WebRTC in Google Chrome prior to 89.0.4389.72 allowed a remote...
Use after free in WebRTC in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 89.0.4389.82-1)
bullseye: resolved (fixed in 89.0.4389.82-1)
forky: resolved (fixed in 89.0.4389.82-1)
sid: resolved (fixed in 89.0.4389.82-1)
trixie: resolved (fixed in 8
debian
CVE-2021-21191P3HIGHCVSS 8.8fixed in chromium 89.0.4389.90-1 (bookworm)2021
CVE-2021-21191 [HIGH] CVE-2021-21191: chromium - Use after free in WebRTC in Google Chrome prior to 89.0.4389.90 allowed a remote...
Use after free in WebRTC in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 89.0.4389.90-1)
bullseye: resolved (fixed in 89.0.4389.90-1)
forky: resolved (fixed in 89.0.4389.90-1)
sid: resolved (fixed in 89.0.4389.90-1)
trixie: resolved (fixed in 8
debian
CVE-2020-15970P3HIGHCVSS 8.8fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-15970 [HIGH] CVE-2020-15970: chromium - Use after free in NFC in Google Chrome prior to 86.0.4240.75 allowed a remote at...
Use after free in NFC in Google Chrome prior to 86.0.4240.75 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (fixed in
debian
CVE-2020-15971P3HIGHCVSS 8.8fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-15971 [HIGH] CVE-2020-15971: chromium - Use after free in printing in Google Chrome prior to 86.0.4240.75 allowed a remo...
Use after free in printing in Google Chrome prior to 86.0.4240.75 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (fix
debian
CVE-2021-38008P3HIGHCVSS 8.8fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-38008 [HIGH] CVE-2021-38008: chromium - Use after free in media in Google Chrome prior to 96.0.4664.45 allowed a remote ...
Use after free in media in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 97.0.4692.71-0.1)
bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1)
forky: resolved (fixed in 97.0.4692.71-0.1)
sid: resolved (fixed in 97.0.4692.71-0.1)
trixie: resol
debian