cbcvebase.

Debian Chromium vulnerabilities

2,134 known vulnerabilities affecting debian/chromium.

Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8

Vulnerabilities

Page 45 of 107
CVE-2020-16043P3HIGHCVSS 8.8fixed in chromium 87.0.4280.141-0.1 (bookworm)2020
CVE-2020-16043 [HIGH] CVE-2020-16043: chromium - Insufficient data validation in networking in Google Chrome prior to 87.0.4280.1... Insufficient data validation in networking in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to bypass discretionary access control via malicious network traffic. Scope: local bookworm: resolved (fixed in 87.0.4280.141-0.1) bullseye: resolved (fixed in 87.0.4280.141-0.1) forky: resolved (fixed in 87.0.4280.141-0.1) sid: resolved (fixed in 87.0.4280.
debian
CVE-2022-3195P3HIGHCVSS 8.8fixed in chromium 105.0.5195.125-1 (bookworm)2022
CVE-2022-3195 [HIGH] CVE-2022-3195: chromium - Out of bounds write in Storage in Google Chrome prior to 105.0.5195.125 allowed ... Out of bounds write in Storage in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 105.0.5195.125-1) bullseye: resolved (fixed in 105.0.5195.125-1~deb11u1) forky: resolved (fixed in 105.0.5195.125-1) sid: resolv
debian
CVE-2023-6510P3HIGHCVSS 8.8fixed in chromium 120.0.6099.71-1~deb12u1 (bookworm)2023
CVE-2023-6510 [HIGH] CVE-2023-6510: chromium - Use after free in Media Capture in Google Chrome prior to 120.0.6099.62 allowed ... Use after free in Media Capture in Google Chrome prior to 120.0.6099.62 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via specific UI interaction. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 120.0.6099.71-1~deb12u1) bullseye: resolved (fixed in 120.0.6099.7
debian
CVE-2022-2158P3HIGHCVSS 8.8fixed in chromium 103.0.5060.53-1 (bookworm)2022
CVE-2022-2158 [HIGH] CVE-2022-2158: chromium - Type confusion in V8 in Google Chrome prior to 103.0.5060.53 allowed a remote at... Type confusion in V8 in Google Chrome prior to 103.0.5060.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 103.0.5060.53-1) bullseye: resolved (fixed in 103.0.5060.53-1~deb11u1) forky: resolved (fixed in 103.0.5060.53-1) sid: resolved (fixed in 103.0.5060.53-1) trixie: resolved (fix
debian
CVE-2022-1489P3HIGHCVSS 8.8fixed in chromium 101.0.4951.41-1 (bookworm)2022
CVE-2022-1489 [HIGH] CVE-2022-1489: chromium - Out of bounds memory access in UI Shelf in Google Chrome on Chrome OS, Lacros pr... Out of bounds memory access in UI Shelf in Google Chrome on Chrome OS, Lacros prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via specific user interactions. Scope: local bookworm: resolved (fixed in 101.0.4951.41-1) bullseye: resolved (fixed in 101.0.4951.41-1~deb11u1) forky: resolved (fixed in 101.0.4951.41-1) sid: resolved (
debian
CVE-2022-0795P3HIGHCVSS 8.8fixed in chromium 99.0.4844.51-1 (bookworm)2022
CVE-2022-0795 [HIGH] CVE-2022-0795: chromium - Type confusion in Blink Layout in Google Chrome prior to 99.0.4844.51 allowed a ... Type confusion in Blink Layout in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 99.0.4844.51-1) bullseye: resolved (fixed in 99.0.4844.51-1~deb11u1) forky: resolved (fixed in 99.0.4844.51-1) sid: resolved (fixed in 99.0.4844.51-1) trixie: resolved
debian
CVE-2023-1820P3HIGHCVSS 8.8fixed in chromium 112.0.5615.49-1 (bookworm)2023
CVE-2023-1820 [HIGH] CVE-2023-1820: chromium - Heap buffer overflow in Browser History in Google Chrome prior to 112.0.5615.49 ... Heap buffer overflow in Browser History in Google Chrome prior to 112.0.5615.49 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 112.0.5615.49-1) bullseye: resolved (fixed in 112.0.5615.49-2~
debian
CVE-2022-2008P3HIGHCVSS 8.8fixed in chromium 102.0.5005.115-1 (bookworm)2022
CVE-2022-2008 [HIGH] CVE-2022-2008: chromium - Double free in WebGL in Google Chrome prior to 102.0.5005.115 allowed a remote a... Double free in WebGL in Google Chrome prior to 102.0.5005.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 102.0.5005.115-1) bullseye: resolved (fixed in 102.0.5005.115-1~deb11u1) forky: resolved (fixed in 102.0.5005.115-1) sid: resolved (fixed in 102.0.5005.115-1) trixie: resolved
debian
CVE-2022-2157P3HIGHCVSS 8.8fixed in chromium 103.0.5060.53-1 (bookworm)2022
CVE-2022-2157 [HIGH] CVE-2022-2157: chromium - Use after free in Interest groups in Google Chrome prior to 103.0.5060.53 allowe... Use after free in Interest groups in Google Chrome prior to 103.0.5060.53 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 103.0.5060.53-1) bullseye: resolved (fixed in 103.0.5060.53-1~deb11u1) forky: resolved (fixed in 103.0.5060.53-1) sid: res
debian
CVE-2023-1811P3HIGHCVSS 8.8fixed in chromium 112.0.5615.49-1 (bookworm)2023
CVE-2023-1811 [HIGH] CVE-2023-1811: chromium - Use after free in Frames in Google Chrome prior to 112.0.5615.49 allowed a remot... Use after free in Frames in Google Chrome prior to 112.0.5615.49 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 112.0.5615.49-1) bullseye: resolved (fixed in 112.0.5615.49-2~deb11u2) forky: r
debian
CVE-2022-0799P3HIGHCVSS 8.8fixed in chromium 99.0.4844.51-1 (bookworm)2022
CVE-2022-0799 [HIGH] CVE-2022-0799: chromium - Insufficient policy enforcement in Installer in Google Chrome on Windows prior t... Insufficient policy enforcement in Installer in Google Chrome on Windows prior to 99.0.4844.51 allowed a remote attacker to perform local privilege escalation via a crafted offline installer file. Scope: local bookworm: resolved (fixed in 99.0.4844.51-1) bullseye: resolved (fixed in 99.0.4844.51-1~deb11u1) forky: resolved (fixed in 99.0.4844.51-1) sid: resolved (fixe
debian
CVE-2021-4078P3HIGHCVSS 8.8fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-4078 [HIGH] CVE-2021-4078: chromium - Type confusion in V8 in Google Chrome prior to 96.0.4664.93 allowed a remote att... Type confusion in V8 in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 97.0.4692.71-0.1) bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1) forky: resolved (fixed in 97.0.4692.71-0.1) sid: resolved (fixed in 97.0.4692.71-0.1) trixie: resolved (
debian
CVE-2022-3045P3HIGHCVSS 8.8fixed in chromium 105.0.5195.52-1 (bookworm)2022
CVE-2022-3045 [HIGH] CVE-2022-3045: chromium - Insufficient validation of untrusted input in V8 in Google Chrome prior to 105.0... Insufficient validation of untrusted input in V8 in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 105.0.5195.52-1) bullseye: resolved (fixed in 105.0.5195.52-1~deb11u1) forky: resolved (fixed in 105.0.5195.52-1) sid: resolved (fixed in 105.0.5195
debian
CVE-2023-4078P3HIGHCVSS 8.8fixed in chromium 115.0.5790.170-1~deb12u1 (bookworm)2023
CVE-2023-4078 [HIGH] CVE-2023-4078: chromium - Inappropriate implementation in Extensions in Google Chrome prior to 115.0.5790.... Inappropriate implementation in Extensions in Google Chrome prior to 115.0.5790.170 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via a crafted Chrome Extension. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 115.0.5790.170-1~deb12u1) bullseye: resolved (fixed
debian
CVE-2023-4077P3HIGHCVSS 8.8fixed in chromium 115.0.5790.170-1~deb12u1 (bookworm)2023
CVE-2023-4077 [HIGH] CVE-2023-4077: chromium - Insufficient data validation in Extensions in Google Chrome prior to 115.0.5790.... Insufficient data validation in Extensions in Google Chrome prior to 115.0.5790.170 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via a crafted Chrome Extension. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 115.0.5790.170-1~deb12u1) bullseye: resolved (fixed
debian
CVE-2022-1314P3HIGHCVSS 8.8fixed in chromium 100.0.4896.88-1 (bookworm)2022
CVE-2022-1314 [HIGH] CVE-2022-1314: chromium - Type confusion in V8 in Google Chrome prior to 100.0.4896.88 allowed a remote at... Type confusion in V8 in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 100.0.4896.88-1) bullseye: resolved (fixed in 100.0.4896.88-1~deb11u1) forky: resolved (fixed in 100.0.4896.88-1) sid: resolved (fixed in 100.0.4896.88-1) trixie: resolved (fix
debian
CVE-2022-0808P3HIGHCVSS 8.8fixed in chromium 99.0.4844.51-1 (bookworm)2022
CVE-2022-0808 [HIGH] CVE-2022-0808: chromium - Use after free in Chrome OS Shell in Google Chrome on Chrome OS prior to 99.0.48... Use after free in Chrome OS Shell in Google Chrome on Chrome OS prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in a series of user interaction to potentially exploit heap corruption via user interactions. Scope: local bookworm: resolved (fixed in 99.0.4844.51-1) bullseye: resolved (fixed in 99.0.4844.51-1~deb11u1) forky: resolved (fixe
debian
CVE-2021-30627P3HIGHCVSS 8.8fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30627 [HIGH] CVE-2021-30627: chromium - Type confusion in Blink layout in Google Chrome prior to 93.0.4577.82 allowed a ... Type confusion in Blink layout in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 93.0.4577.82-1) bullseye: resolved (fixed in 93.0.4577.82-1) forky: resolved (fixed in 93.0.4577.82-1) sid: resolved (fixed in 93.0.4577.82-1) trixie: resolved (fixe
debian
CVE-2022-1496P3HIGHCVSS 8.8fixed in chromium 101.0.4951.41-1 (bookworm)2022
CVE-2022-1496 [HIGH] CVE-2022-1496: chromium - Use after free in File Manager in Google Chrome prior to 101.0.4951.41 allowed a... Use after free in File Manager in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via specific and direct user interaction. Scope: local bookworm: resolved (fixed in 101.0.4951.41-1) bullseye: resolved (fixed in 101.0.4951.41-1~deb11u1) forky: resolved (fixed in 101.0.4951.41-1) sid: resolved (fixed in 101.0.4951.
debian
CVE-2023-5187P3HIGHCVSS 8.8fixed in chromium 117.0.5938.132-1~deb12u1 (bookworm)2023
CVE-2023-5187 [HIGH] CVE-2023-5187: chromium - Use after free in Extensions in Google Chrome prior to 117.0.5938.132 allowed an... Use after free in Extensions in Google Chrome prior to 117.0.5938.132 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 117.0.5938.132-1~deb12u1) bullseye: resolved (fixed in 117.0.5938.132-1~deb11u1) for
debian
Debian Chromium vulnerabilities | cvebase