Debian Chromium vulnerabilities
2,134 known vulnerabilities affecting debian/chromium.
Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8
Vulnerabilities
Page 44 of 107
CVE-2021-4067P3HIGHCVSS 8.8fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-4067 [HIGH] CVE-2021-4067: chromium - Use after free in window manager in Google Chrome on ChromeOS prior to 96.0.4664...
Use after free in window manager in Google Chrome on ChromeOS prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 97.0.4692.71-0.1)
bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1)
forky: resolved (fixed in 97.0.4692.71-0.1)
sid: resolved (fixed in 97.0.4692.71
debian
CVE-2021-4065P3HIGHCVSS 8.8fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-4065 [HIGH] CVE-2021-4065: chromium - Use after free in autofill in Google Chrome prior to 96.0.4664.93 allowed a remo...
Use after free in autofill in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 97.0.4692.71-0.1)
bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1)
forky: resolved (fixed in 97.0.4692.71-0.1)
sid: resolved (fixed in 97.0.4692.71-0.1)
trixie: reso
debian
CVE-2021-4053P3HIGHCVSS 8.8fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-4053 [HIGH] CVE-2021-4053: chromium - Use after free in UI in Google Chrome on Linux prior to 96.0.4664.93 allowed a r...
Use after free in UI in Google Chrome on Linux prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 97.0.4692.71-0.1)
bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1)
forky: resolved (fixed in 97.0.4692.71-0.1)
sid: resolved (fixed in 97.0.4692.71-0.1)
trixie: r
debian
CVE-2021-30544P3HIGHCVSS 8.8fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30544 [HIGH] CVE-2021-30544: chromium - Use after free in BFCache in Google Chrome prior to 91.0.4472.101 allowed a remo...
Use after free in BFCache in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 93.0.4577.82-1)
bullseye: resolved (fixed in 93.0.4577.82-1)
forky: resolved (fixed in 93.0.4577.82-1)
sid: resolved (fixed in 93.0.4577.82-1)
trixie: resolved (fixed in
debian
CVE-2021-37961P3HIGHCVSS 8.8fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-37961 [HIGH] CVE-2021-37961: chromium - Use after free in Tab Strip in Google Chrome prior to 94.0.4606.54 allowed a rem...
Use after free in Tab Strip in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 97.0.4692.71-0.1)
bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1)
forky: resolved (fixed in 97.0.4692.71-0.1)
sid: resolved (fixed in 97.0.4692.71-0.1)
trixie: r
debian
CVE-2021-30510P3HIGHCVSS 8.8fixed in chromium 90.0.4430.212-1 (bookworm)2021
CVE-2021-30510 [HIGH] CVE-2021-30510: chromium - Use after free in Aura in Google Chrome prior to 90.0.4430.212 allowed a remote ...
Use after free in Aura in Google Chrome prior to 90.0.4430.212 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 90.0.4430.212-1)
bullseye: resolved (fixed in 90.0.4430.212-1)
forky: resolved (fixed in 90.0.4430.212-1)
sid: resolved (fixed in 90.0.4430.212-1)
trixie: resolved (fixed i
debian
CVE-2021-21194P3HIGHCVSS 8.8fixed in chromium 89.0.4389.114-1 (bookworm)2021
CVE-2021-21194 [HIGH] CVE-2021-21194: chromium - Use after free in screen sharing in Google Chrome prior to 89.0.4389.114 allowed...
Use after free in screen sharing in Google Chrome prior to 89.0.4389.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 89.0.4389.114-1)
bullseye: resolved (fixed in 89.0.4389.114-1)
forky: resolved (fixed in 89.0.4389.114-1)
sid: resolved (fixed in 89.0.4389.114-1)
trixie: resolve
debian
CVE-2022-0103P3HIGHCVSS 8.8fixed in chromium 97.0.4692.71-0.1 (bookworm)2022
CVE-2022-0103 [HIGH] CVE-2022-0103: chromium - Use after free in SwiftShader in Google Chrome prior to 97.0.4692.71 allowed a r...
Use after free in SwiftShader in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 97.0.4692.71-0.1)
bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1)
forky: resolved (fixed in 97.0.4692.71-0.1)
sid: resolved (fixed in 97.0.4692.71-0.1)
trixie: r
debian
CVE-2021-30515P3HIGHCVSS 8.8fixed in chromium 90.0.4430.212-1 (bookworm)2021
CVE-2021-30515 [HIGH] CVE-2021-30515: chromium - Use after free in File API in Google Chrome prior to 90.0.4430.212 allowed a rem...
Use after free in File API in Google Chrome prior to 90.0.4430.212 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 90.0.4430.212-1)
bullseye: resolved (fixed in 90.0.4430.212-1)
forky: resolved (fixed in 90.0.4430.212-1)
sid: resolved (fixed in 90.0.4430.212-1)
trixie: resolved (fix
debian
CVE-2022-0971P3HIGHCVSS 8.8fixed in chromium 99.0.4844.74-1 (bookworm)2022
CVE-2022-0971 [HIGH] CVE-2022-0971: chromium - Use after free in Blink Layout in Google Chrome on Android prior to 99.0.4844.74...
Use after free in Blink Layout in Google Chrome on Android prior to 99.0.4844.74 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 99.0.4844.74-1)
bullseye: resolved (fixed in 99.0.4844.74-1~deb11u1)
forky: resolved (fixed in 99.0.4844.74-1)
sid:
debian
CVE-2021-21227P3HIGHCVSS 8.8fixed in chromium 90.0.4430.93-1 (bookworm)2021
CVE-2021-21227 [HIGH] CVE-2021-21227: chromium - Insufficient data validation in V8 in Google Chrome prior to 90.0.4430.93 allowe...
Insufficient data validation in V8 in Google Chrome prior to 90.0.4430.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 90.0.4430.93-1)
bullseye: resolved (fixed in 90.0.4430.93-1)
forky: resolved (fixed in 90.0.4430.93-1)
sid: resolved (fixed in 90.0.4430.93-1)
trixie: resolved (
debian
CVE-2022-0099P3HIGHCVSS 8.8fixed in chromium 97.0.4692.71-0.1 (bookworm)2022
CVE-2022-0099 [HIGH] CVE-2022-0099: chromium - Use after free in Sign-in in Google Chrome prior to 97.0.4692.71 allowed a remot...
Use after free in Sign-in in Google Chrome prior to 97.0.4692.71 allowed a remote attacker who convinced a user to perform specific user gestures to potentially exploit heap corruption via specific user gesture.
Scope: local
bookworm: resolved (fixed in 97.0.4692.71-0.1)
bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1)
forky: resolved (fixed in 97.0.4692.71-0.1
debian
CVE-2022-2481P3HIGHCVSS 8.8fixed in chromium 103.0.5060.134-1 (bookworm)2022
CVE-2022-2481 [HIGH] CVE-2022-2481: chromium - Use after free in Views in Google Chrome prior to 103.0.5060.134 allowed a remot...
Use after free in Views in Google Chrome prior to 103.0.5060.134 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via UI interaction.
Scope: local
bookworm: resolved (fixed in 103.0.5060.134-1)
bullseye: resolved (fixed in 103.0.5060.134-1~deb11u1)
forky: resolved (fixed in 103.0.5060.134-1)
debian
CVE-2021-30553P3HIGHCVSS 8.8fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30553 [HIGH] CVE-2021-30553: chromium - Use after free in Network service in Google Chrome prior to 91.0.4472.101 allowe...
Use after free in Network service in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 93.0.4577.82-1)
bullseye: resolved (fixed in 93.0.4577.82-1)
forky: resolved (fixed in 93.0.4577.82-1)
sid: resolved (fixed in 93.0.4577.82-1)
trixie: resolved (
debian
CVE-2021-30548P3HIGHCVSS 8.8fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30548 [HIGH] CVE-2021-30548: chromium - Use after free in Loader in Google Chrome prior to 91.0.4472.101 allowed a remot...
Use after free in Loader in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 93.0.4577.82-1)
bullseye: resolved (fixed in 93.0.4577.82-1)
forky: resolved (fixed in 93.0.4577.82-1)
sid: resolved (fixed in 93.0.4577.82-1)
trixie: resolved (fixed in
debian
CVE-2021-37957P3HIGHCVSS 8.8fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-37957 [HIGH] CVE-2021-37957: chromium - Use after free in WebGPU in Google Chrome prior to 94.0.4606.54 allowed a remote...
Use after free in WebGPU in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 97.0.4692.71-0.1)
bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1)
forky: resolved (fixed in 97.0.4692.71-0.1)
sid: resolved (fixed in 97.0.4692.71-0.1)
trixie: reso
debian
CVE-2022-0789P3HIGHCVSS 8.8fixed in chromium 99.0.4844.51-1 (bookworm)2022
CVE-2022-0789 [HIGH] CVE-2022-0789: chromium - Heap buffer overflow in ANGLE in Google Chrome prior to 99.0.4844.51 allowed a r...
Heap buffer overflow in ANGLE in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 99.0.4844.51-1)
bullseye: resolved (fixed in 99.0.4844.51-1~deb11u1)
forky: resolved (fixed in 99.0.4844.51-1)
sid: resolved (fixed in 99.0.4844.51-1)
trixie: resolved
debian
CVE-2022-1483P3HIGHCVSS 8.8fixed in chromium 101.0.4951.41-1 (bookworm)2022
CVE-2022-1483 [HIGH] CVE-2022-1483: chromium - Heap buffer overflow in WebGPU in Google Chrome prior to 101.0.4951.41 allowed a...
Heap buffer overflow in WebGPU in Google Chrome prior to 101.0.4951.41 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 101.0.4951.41-1)
bullseye: resolved (fixed in 101.0.4951.41-1~deb11u1)
forky: resolved (fixed in 101.0.4951.41-1)
sid: resolv
debian
CVE-2021-21199P3HIGHCVSS 8.8fixed in chromium 89.0.4389.114-1 (bookworm)2021
CVE-2021-21199 [HIGH] CVE-2021-21199: chromium - Use after free in Aura in Google Chrome on Linux prior to 89.0.4389.114 allowed ...
Use after free in Aura in Google Chrome on Linux prior to 89.0.4389.114 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 89.0.4389.114-1)
bullseye: resolved (fixed in 89.0.4389.114-1)
forky: resolved (fixed in 89.0.4389.114-1)
sid: resolved (f
debian
CVE-2021-21231P3HIGHCVSS 8.8fixed in chromium 90.0.4430.93-1 (bookworm)2021
CVE-2021-21231 [HIGH] CVE-2021-21231: chromium - Insufficient data validation in V8 in Google Chrome prior to 90.0.4430.93 allowe...
Insufficient data validation in V8 in Google Chrome prior to 90.0.4430.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 90.0.4430.93-1)
bullseye: resolved (fixed in 90.0.4430.93-1)
forky: resolved (fixed in 90.0.4430.93-1)
sid: resolved (fixed in 90.0.4430.93-1)
trixie: resolved (
debian