cbcvebase.

Debian Chromium vulnerabilities

2,134 known vulnerabilities affecting debian/chromium.

Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8

Vulnerabilities

Page 5 of 107
CVE-2019-5797P3HIGHCVSS 7.5PoCfixed in chromium 73.0.3683.75-1 (bookworm)2019
CVE-2019-5797 [HIGH] CVE-2019-5797: chromium - Double free in DOMStorage in Google Chrome prior to 73.0.3683.75 allowed a remot... Double free in DOMStorage in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 73.0.3683.75-1) bullseye: resolved (fixed in 73.0.3683.75-1) forky: resolved (fixed in 73.0.3683.75-1) sid: resolved (fixed in 73.0.3683.75-1) trixie: resolved (fixed in 73
debian
CVE-2024-1283P2CRITICALCVSS 9.8fixed in chromium 121.0.6167.160-1~deb12u1 (bookworm)2024
CVE-2024-1283 [CRITICAL] CVE-2024-1283: chromium - Heap buffer overflow in Skia in Google Chrome prior to 121.0.6167.160 allowed a ... Heap buffer overflow in Skia in Google Chrome prior to 121.0.6167.160 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 121.0.6167.160-1~deb12u1) bullseye: open forky: resolved (fixed in 121.0.6167.160-1) sid: resolved (fixed in 121.0.6167.160-1) t
debian
CVE-2020-6519P3MEDIUMCVSS 6.5PoCfixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-6519 [MEDIUM] CVE-2020-6519: chromium - Policy bypass in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote att... Policy bypass in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass content security policy via a crafted HTML page. Scope: local bookworm: resolved (fixed in 87.0.4280.88-0.1) bullseye: resolved (fixed in 87.0.4280.88-0.1) forky: resolved (fixed in 87.0.4280.88-0.1) sid: resolved (fixed in 87.0.4280.88-0.1) trixie: resolved (fixed in 87
debian
CVE-2023-6112P2HIGHCVSS 8.8fixed in chromium 119.0.6045.159-1~deb12u1 (bookworm)2023
CVE-2023-6112 [HIGH] CVE-2023-6112: chromium - Use after free in Navigation in Google Chrome prior to 119.0.6045.159 allowed a ... Use after free in Navigation in Google Chrome prior to 119.0.6045.159 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 119.0.6045.159-1~deb12u1) bullseye: resolved (fixed in 119.0.6045.159-1~deb11u1) forky: resolved (fixed in 119.0.6045.159-1) sid: re
debian
CVE-2023-2724P2HIGHCVSS 8.8fixed in chromium 113.0.5672.126-1 (bookworm)2023
CVE-2023-2724 [HIGH] CVE-2023-2724: chromium - Type confusion in V8 in Google Chrome prior to 113.0.5672.126 allowed a remote a... Type confusion in V8 in Google Chrome prior to 113.0.5672.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 113.0.5672.126-1) bullseye: resolved (fixed in 113.0.5672.126-1~deb11u1) forky: resolved (fixed in 113.0.5672.126-1) sid: resolved (fixed in
debian
CVE-2026-0907P2CRITICALCVSS 9.8fixed in chromium 144.0.7559.59-1~deb12u1 (bookworm)2026
CVE-2026-0907 [CRITICAL] CVE-2026-0907: chromium - Incorrect security UI in Split View in Google Chrome prior to 144.0.7559.59 allo... Incorrect security UI in Split View in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low) Scope: local bookworm: resolved (fixed in 144.0.7559.59-1~deb12u1) bullseye: open forky: resolved (fixed in 144.0.7559.59-1) sid: resolved (fixed in 144.0.7559.59-1) trixie: resolve
debian
CVE-2023-4355P2HIGHCVSS 8.8fixed in chromium 116.0.5845.96-1~deb12u1 (bookworm)2023
CVE-2023-4355 [HIGH] CVE-2023-4355: chromium - Out of bounds memory access in V8 in Google Chrome prior to 116.0.5845.96 allowe... Out of bounds memory access in V8 in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 116.0.5845.96-1~deb12u1) bullseye: resolved (fixed in 116.0.5845.96-1~deb11u1) forky: resolved (fixed in 116.0.5845.96-1) sid: r
debian
CVE-2023-4069P2HIGHCVSS 8.8fixed in chromium 115.0.5790.170-1~deb12u1 (bookworm)2023
CVE-2023-4069 [HIGH] CVE-2023-4069: chromium - Type Confusion in V8 in Google Chrome prior to 115.0.5790.170 allowed a remote a... Type Confusion in V8 in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 115.0.5790.170-1~deb12u1) bullseye: resolved (fixed in 115.0.5790.170-1~deb11u1) forky: resolved (fixed in 115.0.5790.170-1) sid: resolved (
debian
CVE-2023-2935P2HIGHCVSS 8.8fixed in chromium 114.0.5735.90-2~deb12u1 (bookworm)2023
CVE-2023-2935 [HIGH] CVE-2023-2935: chromium - Type Confusion in V8 in Google Chrome prior to 114.0.5735.90 allowed a remote at... Type Confusion in V8 in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 114.0.5735.90-2~deb12u1) bullseye: resolved (fixed in 114.0.5735.90-2~deb11u1) forky: resolved (fixed in 114.0.5735.90-1) sid: resolved (fixe
debian
CVE-2023-2936P2HIGHCVSS 8.8fixed in chromium 114.0.5735.90-2~deb12u1 (bookworm)2023
CVE-2023-2936 [HIGH] CVE-2023-2936: chromium - Type Confusion in V8 in Google Chrome prior to 114.0.5735.90 allowed a remote at... Type Confusion in V8 in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 114.0.5735.90-2~deb12u1) bullseye: resolved (fixed in 114.0.5735.90-2~deb11u1) forky: resolved (fixed in 114.0.5735.90-1) sid: resolved (fixe
debian
CVE-2024-0517P2HIGHCVSS 8.8fixed in chromium 120.0.6099.224-1~deb12u1 (bookworm)2024
CVE-2024-0517 [HIGH] CVE-2024-0517: chromium - Out of bounds write in V8 in Google Chrome prior to 120.0.6099.224 allowed a rem... Out of bounds write in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 120.0.6099.224-1~deb12u1) bullseye: resolved (fixed in 120.0.6099.224-1~deb11u1) forky: resolved (fixed in 120.0.6099.224-1) sid: resol
debian
CVE-2021-38001P2HIGHCVSS 8.8fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-38001 [HIGH] CVE-2021-38001: chromium - Type confusion in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote att... Type confusion in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 97.0.4692.71-0.1) bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1) forky: resolved (fixed in 97.0.4692.71-0.1) sid: resolved (fixed in 97.0.4692.71-0.1) trixie: resolved
debian
CVE-2022-2998P2HIGHCVSS 8.8fixed in chromium 104.0.5112.101-1 (bookworm)2022
CVE-2022-2998 [HIGH] CVE-2022-2998: chromium - Use after free in Browser Creation in Google Chrome prior to 104.0.5112.101 allo... Use after free in Browser Creation in Google Chrome prior to 104.0.5112.101 allowed a remote attacker who had convinced a user to engage in a specific UI interaction to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 104.0.5112.101-1) bullseye: resolved (fixed in 104.0.5112.101-1~deb11u1) forky: resolved (fixed i
debian
CVE-2022-4178P2HIGHCVSS 8.8fixed in chromium 108.0.5359.71-1 (bookworm)2022
CVE-2022-4178 [HIGH] CVE-2022-4178: chromium - Use after free in Mojo in Google Chrome prior to 108.0.5359.71 allowed a remote ... Use after free in Mojo in Google Chrome prior to 108.0.5359.71 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 108.0.5359.71-1) bullseye: resolved (fixed in 108.0.5359.71-2~deb11u1) forky: resolved (fixed in 1
debian
CVE-2022-3654P2HIGHCVSS 8.8fixed in chromium 107.0.5304.68-1 (bookworm)2022
CVE-2022-3654 [HIGH] CVE-2022-3654: chromium - Use after free in Layout in Google Chrome prior to 107.0.5304.62 allowed a remot... Use after free in Layout in Google Chrome prior to 107.0.5304.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 107.0.5304.68-1) bullseye: resolved (fixed in 107.0.5304.68-1~deb11u1) forky: resolved (fixed in 107.0.5304.68-1) sid: resolved (fixed in
debian
CVE-2020-6551P2HIGHCVSS 8.8fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-6551 [HIGH] CVE-2020-6551: chromium - Use after free in WebXR in Google Chrome prior to 84.0.4147.125 allowed a remote... Use after free in WebXR in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 87.0.4280.88-0.1) bullseye: resolved (fixed in 87.0.4280.88-0.1) forky: resolved (fixed in 87.0.4280.88-0.1) sid: resolved (fixed in 87.0.4280.88-0.1) trixie: resolved (fixe
debian
CVE-2020-6550P2HIGHCVSS 8.8fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-6550 [HIGH] CVE-2020-6550: chromium - Use after free in IndexedDB in Google Chrome prior to 84.0.4147.125 allowed a re... Use after free in IndexedDB in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 87.0.4280.88-0.1) bullseye: resolved (fixed in 87.0.4280.88-0.1) forky: resolved (fixed in 87.0.4280.88-0.1) sid: resolved (fixed in 87.0.4280.88-0.1) trixie: resolved (
debian
CVE-2022-0289P2HIGHCVSS 8.8fixed in chromium 97.0.4692.99-1 (bookworm)2022
CVE-2022-0289 [HIGH] CVE-2022-0289: chromium - Use after free in Safe browsing in Google Chrome prior to 97.0.4692.99 allowed a... Use after free in Safe browsing in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 97.0.4692.99-1) bullseye: resolved (fixed in 97.0.4692.99-1~deb11u2) forky: resolved (fixed in 97.0.4692.99-1) sid: resolved (fixed in 97.0.4692.99-1) trixie: resolve
debian
CVE-2023-4427P2HIGHCVSS 8.1fixed in chromium 116.0.5845.110-1~deb12u1 (bookworm)2023
CVE-2023-4427 [HIGH] CVE-2023-4427: chromium - Out of bounds memory access in V8 in Google Chrome prior to 116.0.5845.110 allow... Out of bounds memory access in V8 in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 116.0.5845.110-1~deb12u1) bullseye: resolved (fixed in 116.0.5845.110-1~deb11u1) forky: resolved (fixed in 116.0.5845.110-1) s
debian
CVE-2021-21132P2CRITICALCVSS 9.6fixed in chromium 88.0.4324.96-0.1 (bookworm)2021
CVE-2021-21132 [CRITICAL] CVE-2021-21132: chromium - Inappropriate implementation in DevTools in Google Chrome prior to 88.0.4324.96 ... Inappropriate implementation in DevTools in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially perform a sandbox escape via a crafted Chrome Extension. Scope: local bookworm: resolved (fixed in 88.0.4324.96-0.1) bullseye: resolved (fixed in 88.0.4324.96-0.1) forky: resolved (fixed in 88.0.4324.96-0.1) sid: resolved (fixed in 88.0.4324.
debian
Debian Chromium vulnerabilities | cvebase