cbcvebase.

Debian Chromium vulnerabilities

2,134 known vulnerabilities affecting debian/chromium.

Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8

Vulnerabilities

Page 46 of 107
CVE-2022-3373P3HIGHCVSS 8.8fixed in chromium 106.0.5249.91-1 (bookworm)2022
CVE-2022-3373 [HIGH] CVE-2022-3373: chromium - Out of bounds write in V8 in Google Chrome prior to 106.0.5249.91 allowed a remo... Out of bounds write in V8 in Google Chrome prior to 106.0.5249.91 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 106.0.5249.91-1) bullseye: resolved (fixed in 106.0.5249.91-1~deb11u1) forky: resolved (fixed in 106.0.5249.91-1) sid: resolved (fixed
debian
CVE-2023-4356P3HIGHCVSS 8.8fixed in chromium 116.0.5845.96-1~deb12u1 (bookworm)2023
CVE-2023-4356 [HIGH] CVE-2023-4356: chromium - Use after free in Audio in Google Chrome prior to 116.0.5845.96 allowed a remote... Use after free in Audio in Google Chrome prior to 116.0.5845.96 allowed a remote attacker who has convinced a user to engage in specific UI interaction to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 116.0.5845.96-1~deb12u1) bullseye: resolved (fixed in 116.0.5845.96-1~deb1
debian
CVE-2022-1141P3HIGHCVSS 8.8fixed in chromium 100.0.4896.60-1 (bookworm)2022
CVE-2022-1141 [HIGH] CVE-2022-1141: chromium - Use after free in File Manager in Google Chrome prior to 100.0.4896.60 allowed a... Use after free in File Manager in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via specific user gesture. Scope: local bookworm: resolved (fixed in 100.0.4896.60-1) bullseye: resolved (fixed in 100.0.4896.60-1~deb11u1) forky: resolved (fixed in 100.0.4
debian
CVE-2022-2859P3HIGHCVSS 8.8fixed in chromium 104.0.5112.101-1 (bookworm)2022
CVE-2022-2859 [HIGH] CVE-2022-2859: chromium - Use after free in Chrome OS Shell in Google Chrome prior to 104.0.5112.101 allow... Use after free in Chrome OS Shell in Google Chrome prior to 104.0.5112.101 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via specific UI interactions. Scope: local bookworm: resolved (fixed in 104.0.5112.101-1) bullseye: resolved (fixed in 104.0.5112.101-1~deb11u1) forky: resolved (fixed in
debian
CVE-2022-3446P3HIGHCVSS 8.8fixed in chromium 106.0.5249.119-1 (bookworm)2022
CVE-2022-3446 [HIGH] CVE-2022-3446: chromium - Heap buffer overflow in WebSQL in Google Chrome prior to 106.0.5249.119 allowed ... Heap buffer overflow in WebSQL in Google Chrome prior to 106.0.5249.119 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 106.0.5249.119-1) bullseye: resolved (fixed in 106.0.5249.119-1~deb11u1) forky: resolved (fixed in 106.0.5249.119-1) sid: resolved
debian
CVE-2023-2930P3HIGHCVSS 8.8fixed in chromium 114.0.5735.90-2~deb12u1 (bookworm)2023
CVE-2023-2930 [HIGH] CVE-2023-2930: chromium - Use after free in Extensions in Google Chrome prior to 114.0.5735.90 allowed an ... Use after free in Extensions in Google Chrome prior to 114.0.5735.90 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 114.0.5735.90-2~deb12u1) bullseye: resolved (fixed in 114.0.5735.90-2~deb11u1) forky:
debian
CVE-2022-1633P3HIGHCVSS 8.8fixed in chromium 101.0.4951.64-1 (bookworm)2022
CVE-2022-1633 [HIGH] CVE-2022-1633: chromium - Use after free in Sharesheet in Google Chrome on Chrome OS prior to 101.0.4951.6... Use after free in Sharesheet in Google Chrome on Chrome OS prior to 101.0.4951.64 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via specific user interactions. Scope: local bookworm: resolved (fixed in 101.0.4951.64-1) bullseye: resolved (fixed in 101.0.4951.64-1~deb11u1) forky: resolved (f
debian
CVE-2022-0610P3HIGHCVSS 8.8fixed in chromium 98.0.4758.102-1 (bookworm)2022
CVE-2022-0610 [HIGH] CVE-2022-0610: chromium - Inappropriate implementation in Gamepad API in Google Chrome prior to 98.0.4758.... Inappropriate implementation in Gamepad API in Google Chrome prior to 98.0.4758.102 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 98.0.4758.102-1) bullseye: resolved (fixed in 98.0.4758.102-1~deb11u1) forky: resolved (fixed in 98.0.4758.102-1) sid: resolved (fixed in 98.0.4758.102-1
debian
CVE-2023-0699P3HIGHCVSS 8.8fixed in chromium 110.0.5481.77-1 (bookworm)2023
CVE-2023-0699 [HIGH] CVE-2023-0699: chromium - Use after free in GPU in Google Chrome prior to 110.0.5481.77 allowed a remote a... Use after free in GPU in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page and browser shutdown. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 110.0.5481.77-1) bullseye: resolved (fixed in 110.0.5481.77-1~deb11u1) forky: resolved (fixed in 110.0.5481.77-1) sid
debian
CVE-2022-2613P3HIGHCVSS 8.8fixed in chromium 104.0.5112.79-1 (bookworm)2022
CVE-2022-2613 [HIGH] CVE-2022-2613: chromium - Use after free in Input in Google Chrome on Chrome OS prior to 104.0.5112.79 all... Use after free in Input in Google Chrome on Chrome OS prior to 104.0.5112.79 allowed a remote attacker who convinced a user to enage in specific user interactions to potentially exploit heap corruption via specific UI interactions. Scope: local bookworm: resolved (fixed in 104.0.5112.79-1) bullseye: resolved (fixed in 104.0.5112.79-1~deb11u1) forky: resolved (fixed i
debian
CVE-2021-4100P3HIGHCVSS 8.8fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-4100 [HIGH] CVE-2021-4100: chromium - Object lifecycle issue in ANGLE in Google Chrome prior to 96.0.4664.110 allowed ... Object lifecycle issue in ANGLE in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 97.0.4692.71-0.1) bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1) forky: resolved (fixed in 97.0.4692.71-0.1) sid: resolved (fixed in 97.0.4692.71-0.1) trixie
debian
CVE-2022-3887P3HIGHCVSS 8.8fixed in chromium 107.0.5304.110-1 (bookworm)2022
CVE-2022-3887 [HIGH] CVE-2022-3887: chromium - Use after free in Web Workers in Google Chrome prior to 107.0.5304.106 allowed a... Use after free in Web Workers in Google Chrome prior to 107.0.5304.106 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 107.0.5304.110-1) bullseye: resolved (fixed in 107.0.5304.110-1~deb11u1) forky: resolved (fixed in 107.0.5304.110-1) sid: resolved
debian
CVE-2023-0701P3HIGHCVSS 8.8fixed in chromium 110.0.5481.77-1 (bookworm)2023
CVE-2023-0701 [HIGH] CVE-2023-0701: chromium - Heap buffer overflow in WebUI in Google Chrome prior to 110.0.5481.77 allowed a ... Heap buffer overflow in WebUI in Google Chrome prior to 110.0.5481.77 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via UI interaction . (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 110.0.5481.77-1) bullseye: resolved (fixed in 110.0.5481.77-1~deb11u1) fork
debian
CVE-2024-7973P3HIGHCVSS 8.8fixed in chromium 128.0.6613.84-1~deb12u1 (bookworm)2024
CVE-2024-7973 [HIGH] CVE-2024-7973: chromium - Heap buffer overflow in PDFium in Google Chrome prior to 128.0.6613.84 allowed a... Heap buffer overflow in PDFium in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to perform an out of bounds memory read via a crafted PDF file. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 128.0.6613.84-1~deb12u1) bullseye: open forky: resolved (fixed in 128.0.6613.84-1) sid: resolved (fixed in 128.0.6613.84-1) trixi
debian
CVE-2023-0702P3HIGHCVSS 8.8fixed in chromium 110.0.5481.77-1 (bookworm)2023
CVE-2023-0702 [HIGH] CVE-2023-0702: chromium - Type confusion in Data Transfer in Google Chrome prior to 110.0.5481.77 allowed ... Type confusion in Data Transfer in Google Chrome prior to 110.0.5481.77 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 110.0.5481.77-1) bullseye: resolved (fixed in 110.0.5481.77-1~deb11u1
debian
CVE-2022-3200P3HIGHCVSS 8.8fixed in chromium 105.0.5195.125-1 (bookworm)2022
CVE-2022-3200 [HIGH] CVE-2022-3200: chromium - Heap buffer overflow in Internals in Google Chrome prior to 105.0.5195.125 allow... Heap buffer overflow in Internals in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 105.0.5195.125-1) bullseye: resolved (fixed in 105.0.5195.125-1~deb11u1) forky: resolved (fixed in 105.0.5195.125-1) sid: resol
debian
CVE-2023-0138P3HIGHCVSS 8.8fixed in chromium 109.0.5414.74-1 (bookworm)2023
CVE-2023-0138 [HIGH] CVE-2023-0138: chromium - Heap buffer overflow in libphonenumber in Google Chrome prior to 109.0.5414.74 a... Heap buffer overflow in libphonenumber in Google Chrome prior to 109.0.5414.74 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low) Scope: local bookworm: resolved (fixed in 109.0.5414.74-1) bullseye: resolved (fixed in 109.0.5414.74-2~deb11u1) forky: resolved (fixed in 109.0.5414.74-1) sid: resol
debian
CVE-2022-3043P3HIGHCVSS 8.8fixed in chromium 105.0.5195.52-1 (bookworm)2022
CVE-2022-3043 [HIGH] CVE-2022-3043: chromium - Heap buffer overflow in Screen Capture in Google Chrome on Chrome OS prior to 10... Heap buffer overflow in Screen Capture in Google Chrome on Chrome OS prior to 105.0.5195.52 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 105.0.5195.52-1) bullseye: resolved (fixed in 105.0.5195.52-1~deb11u1) forky: resolved
debian
CVE-2023-0703P3HIGHCVSS 8.8fixed in chromium 110.0.5481.77-1 (bookworm)2023
CVE-2023-0703 [HIGH] CVE-2023-0703: chromium - Type confusion in DevTools in Google Chrome prior to 110.0.5481.77 allowed a rem... Type confusion in DevTools in Google Chrome prior to 110.0.5481.77 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via UI interactions. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 110.0.5481.77-1) bullseye: resolved (fixed in 110.0.5481.77-1~deb11u1) forky:
debian
CVE-2022-3653P3HIGHCVSS 8.8fixed in chromium 107.0.5304.68-1 (bookworm)2022
CVE-2022-3653 [HIGH] CVE-2022-3653: chromium - Heap buffer overflow in Vulkan in Google Chrome prior to 107.0.5304.62 allowed a... Heap buffer overflow in Vulkan in Google Chrome prior to 107.0.5304.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 107.0.5304.68-1) bullseye: resolved (fixed in 107.0.5304.68-1~deb11u1) forky: resolved (fixed in 107.0.5304.68-1) sid: resolved (fi
debian
Debian Chromium vulnerabilities | cvebase