Debian Chromium vulnerabilities
2,134 known vulnerabilities affecting debian/chromium.
Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8
Vulnerabilities
Page 43 of 107
CVE-2021-21197P3HIGHCVSS 8.8fixed in chromium 89.0.4389.114-1 (bookworm)2021
CVE-2021-21197 [HIGH] CVE-2021-21197: chromium - Heap buffer overflow in TabStrip in Google Chrome prior to 89.0.4389.114 allowed...
Heap buffer overflow in TabStrip in Google Chrome prior to 89.0.4389.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 89.0.4389.114-1)
bullseye: resolved (fixed in 89.0.4389.114-1)
forky: resolved (fixed in 89.0.4389.114-1)
sid: resolved (fixed in 89.0.4389.114-1)
trixie: resolve
debian
CVE-2021-30585P3HIGHCVSS 8.8fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30585 [HIGH] CVE-2021-30585: chromium - Use after free in sensor handling in Google Chrome on Windows prior to 92.0.4515...
Use after free in sensor handling in Google Chrome on Windows prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 93.0.4577.82-1)
bullseye: resolved (fixed in 93.0.4577.82-1)
forky: resolved (fixed in 93.0.4577.82-1)
sid: resolved (fixed in 93.0.4577.82-1)
trixie:
debian
CVE-2021-30569P3HIGHCVSS 8.8fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30569 [HIGH] CVE-2021-30569: chromium - Use after free in sqlite in Google Chrome prior to 92.0.4515.107 allowed a remot...
Use after free in sqlite in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 93.0.4577.82-1)
bullseye: resolved (fixed in 93.0.4577.82-1)
forky: resolved (fixed in 93.0.4577.82-1)
sid: resolved (fixed in 93.0.4577.82-1)
trixie: resolved (fixed in
debian
CVE-2021-21114P3HIGHCVSS 8.8fixed in chromium 87.0.4280.141-0.1 (bookworm)2021
CVE-2021-21114 [HIGH] CVE-2021-21114: chromium - Use after free in audio in Google Chrome prior to 87.0.4280.141 allowed a remote...
Use after free in audio in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.141-0.1)
bullseye: resolved (fixed in 87.0.4280.141-0.1)
forky: resolved (fixed in 87.0.4280.141-0.1)
sid: resolved (fixed in 87.0.4280.141-0.1)
trixie: resolved
debian
CVE-2021-21112P3HIGHCVSS 8.8fixed in chromium 87.0.4280.141-0.1 (bookworm)2021
CVE-2021-21112 [HIGH] CVE-2021-21112: chromium - Use after free in Blink in Google Chrome prior to 87.0.4280.141 allowed a remote...
Use after free in Blink in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.141-0.1)
bullseye: resolved (fixed in 87.0.4280.141-0.1)
forky: resolved (fixed in 87.0.4280.141-0.1)
sid: resolved (fixed in 87.0.4280.141-0.1)
trixie: resolved
debian
CVE-2021-37970P3HIGHCVSS 8.8fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-37970 [HIGH] CVE-2021-37970: chromium - Use after free in File System API in Google Chrome prior to 94.0.4606.54 allowed...
Use after free in File System API in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 97.0.4692.71-0.1)
bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1)
forky: resolved (fixed in 97.0.4692.71-0.1)
sid: resolved (fixed in 97.0.4692.71-0.1)
tri
debian
CVE-2022-0104P3HIGHCVSS 8.8fixed in chromium 97.0.4692.71-0.1 (bookworm)2022
CVE-2022-0104 [HIGH] CVE-2022-0104: chromium - Heap buffer overflow in ANGLE in Google Chrome prior to 97.0.4692.71 allowed a r...
Heap buffer overflow in ANGLE in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 97.0.4692.71-0.1)
bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1)
forky: resolved (fixed in 97.0.4692.71-0.1)
sid: resolved (fixed in 97.0.4692.71-0.1)
trixie: r
debian
CVE-2021-30516P3HIGHCVSS 8.8fixed in chromium 90.0.4430.212-1 (bookworm)2021
CVE-2021-30516 [HIGH] CVE-2021-30516: chromium - Heap buffer overflow in History in Google Chrome prior to 90.0.4430.212 allowed ...
Heap buffer overflow in History in Google Chrome prior to 90.0.4430.212 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 90.0.4430.212-1)
bullseye: resolved (fixed in 90.0.4430.212-1)
forky: resolved (fixed in 90.0.4430.212-1)
sid: resolved (f
debian
CVE-2021-30518P3HIGHCVSS 8.8fixed in chromium 90.0.4430.212-1 (bookworm)2021
CVE-2021-30518 [HIGH] CVE-2021-30518: chromium - Heap buffer overflow in Reader Mode in Google Chrome prior to 90.0.4430.212 allo...
Heap buffer overflow in Reader Mode in Google Chrome prior to 90.0.4430.212 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 90.0.4430.212-1)
bullseye: resolved (fixed in 90.0.4430.212-1)
forky: resolved (fixed in 90.0.4430.212-1)
sid: resolved (fixed in 90.0.4430.212-1)
trixie: reso
debian
CVE-2021-30521P3HIGHCVSS 8.8fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30521 [HIGH] CVE-2021-30521: chromium - Heap buffer overflow in Autofill in Google Chrome on Android prior to 91.0.4472....
Heap buffer overflow in Autofill in Google Chrome on Android prior to 91.0.4472.77 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 93.0.4577.82-1)
bullseye: resolved (fixed in 93.0.4577.82-1)
forky: resolved (fixed in 93.0.4577.82-1)
sid: resolved (fixed in 93.0.4577.82-1)
trixie: r
debian
CVE-2021-4063P3HIGHCVSS 8.8fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-4063 [HIGH] CVE-2021-4063: chromium - Use after free in developer tools in Google Chrome prior to 96.0.4664.93 allowed...
Use after free in developer tools in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 97.0.4692.71-0.1)
bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1)
forky: resolved (fixed in 97.0.4692.71-0.1)
sid: resolved (fixed in 97.0.4692.71-0.1)
trixi
debian
CVE-2021-30562P3HIGHCVSS 8.8fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30562 [HIGH] CVE-2021-30562: chromium - Use after free in WebSerial in Google Chrome prior to 91.0.4472.164 allowed a re...
Use after free in WebSerial in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 93.0.4577.82-1)
bullseye: resolved (fixed in 93.0.4577.82-1)
forky: resolved (fixed in 93.0.4577.82-1)
sid: resolved (fixed in 93.0.4577.82-1)
trixie: resolved (fixed
debian
CVE-2022-0106P3HIGHCVSS 8.8fixed in chromium 97.0.4692.71-0.1 (bookworm)2022
CVE-2022-0106 [HIGH] CVE-2022-0106: chromium - Use after free in Autofill in Google Chrome prior to 97.0.4692.71 allowed a remo...
Use after free in Autofill in Google Chrome prior to 97.0.4692.71 allowed a remote attacker who convinced a user to perform specific user gesture to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 97.0.4692.71-0.1)
bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1)
forky: resolved (fixed in 97.0.4692.71-0.1)
debian
CVE-2023-1532P3HIGHCVSS 8.8fixed in chromium 111.0.5563.110-1 (bookworm)2023
CVE-2023-1532 [HIGH] CVE-2023-1532: chromium - Out of bounds read in GPU Video in Google Chrome prior to 111.0.5563.110 allowed...
Out of bounds read in GPU Video in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 111.0.5563.110-1)
bullseye: resolved (fixed in 111.0.5563.110-1~deb11u1)
forky: resolved (fixed in 111.0.5563.110-1)
sid: resolve
debian
CVE-2022-0105P3HIGHCVSS 8.8fixed in chromium 97.0.4692.71-0.1 (bookworm)2022
CVE-2022-0105 [HIGH] CVE-2022-0105: chromium - Use after free in PDF Accessibility in Google Chrome prior to 97.0.4692.71 allow...
Use after free in PDF Accessibility in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 97.0.4692.71-0.1)
bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1)
forky: resolved (fixed in 97.0.4692.71-0.1)
sid: resolved (fixed in 97.0.4692.71-0.1)
tri
debian
CVE-2021-4064P3HIGHCVSS 8.8fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-4064 [HIGH] CVE-2021-4064: chromium - Use after free in screen capture in Google Chrome on ChromeOS prior to 96.0.4664...
Use after free in screen capture in Google Chrome on ChromeOS prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 97.0.4692.71-0.1)
bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1)
forky: resolved (fixed in 97.0.4692.71-0.1)
sid: resolved (fixed in 97.0.4692.71
debian
CVE-2021-4066P3HIGHCVSS 8.8fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-4066 [HIGH] CVE-2021-4066: chromium - Integer underflow in ANGLE in Google Chrome prior to 96.0.4664.93 allowed a remo...
Integer underflow in ANGLE in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 97.0.4692.71-0.1)
bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1)
forky: resolved (fixed in 97.0.4692.71-0.1)
sid: resolved (fixed in 97.0.4692.71-0.1)
trixie: reso
debian
CVE-2020-15995P3HIGHCVSS 8.8fixed in chromium 87.0.4280.141-0.1 (bookworm)2020
CVE-2020-15995 [HIGH] CVE-2020-15995: chromium - Out of bounds write in V8 in Google Chrome prior to 86.0.4240.99 allowed a remot...
Out of bounds write in V8 in Google Chrome prior to 86.0.4240.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.141-0.1)
bullseye: resolved (fixed in 87.0.4280.141-0.1)
forky: resolved (fixed in 87.0.4280.141-0.1)
sid: resolved (fixed in 87.0.4280.141-0.1)
trixie: resolve
debian
CVE-2020-16039P3HIGHCVSS 8.8fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-16039 [HIGH] CVE-2020-16039: chromium - Use after free in extensions in Google Chrome prior to 87.0.4280.88 allowed a re...
Use after free in extensions in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (fixed in 87.0.4280.88-0.1)
trixie: resolved
debian
CVE-2020-16037P3HIGHCVSS 8.8fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-16037 [HIGH] CVE-2020-16037: chromium - Use after free in clipboard in Google Chrome prior to 87.0.4280.88 allowed a rem...
Use after free in clipboard in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (fixed in 87.0.4280.88-0.1)
trixie: resolved
debian