Debian Chromium vulnerabilities
2,134 known vulnerabilities affecting debian/chromium.
Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8
Vulnerabilities
Page 50 of 107
CVE-2020-16038P3HIGHCVSS 8.8fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-16038 [HIGH] CVE-2020-16038: chromium - Use after free in media in Google Chrome on OS X prior to 87.0.4280.88 allowed a...
Use after free in media in Google Chrome on OS X prior to 87.0.4280.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (fixed in 87.0.4280.88-0.1)
trixie: resol
debian
CVE-2021-37956P3HIGHCVSS 8.8fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-37956 [HIGH] CVE-2021-37956: chromium - Use after free in Offline use in Google Chrome on Android prior to 94.0.4606.54 ...
Use after free in Offline use in Google Chrome on Android prior to 94.0.4606.54 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 97.0.4692.71-0.1)
bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1)
forky: resolved (fixed in 97.0.4692.71-0.
debian
CVE-2021-30567P3HIGHCVSS 8.8fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30567 [HIGH] CVE-2021-30567: chromium - Use after free in DevTools in Google Chrome prior to 92.0.4515.107 allowed an at...
Use after free in DevTools in Google Chrome prior to 92.0.4515.107 allowed an attacker who convinced a user to open DevTools to potentially exploit heap corruption via specific user gesture.
Scope: local
bookworm: resolved (fixed in 93.0.4577.82-1)
bullseye: resolved (fixed in 93.0.4577.82-1)
forky: resolved (fixed in 93.0.4577.82-1)
sid: resolved (fixed in 93.0.45
debian
CVE-2021-30535P3HIGHCVSS 8.8fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30535 [HIGH] CVE-2021-30535: chromium - Double free in ICU in Google Chrome prior to 91.0.4472.77 allowed a remote attac...
Double free in ICU in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 93.0.4577.82-1)
bullseye: resolved (fixed in 93.0.4577.82-1)
forky: resolved (fixed in 93.0.4577.82-1)
sid: resolved (fixed in 93.0.4577.82-1)
trixie: resolved (fixed in 93.0.45
debian
CVE-2021-30514P3HIGHCVSS 8.8fixed in chromium 90.0.4430.212-1 (bookworm)2021
CVE-2021-30514 [HIGH] CVE-2021-30514: chromium - Use after free in Autofill in Google Chrome prior to 90.0.4430.212 allowed a rem...
Use after free in Autofill in Google Chrome prior to 90.0.4430.212 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 90.0.4430.212-1)
bullseye: resolved (fixed in 90.0.4430.212-1)
forky: resolved (fixed in 90.0.4430.212-1)
sid: resolved (fixed
debian
CVE-2021-30523P3HIGHCVSS 8.8fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30523 [HIGH] CVE-2021-30523: chromium - Use after free in WebRTC in Google Chrome prior to 91.0.4472.77 allowed a remote...
Use after free in WebRTC in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to potentially exploit heap corruption via a crafted SCTP packet.
Scope: local
bookworm: resolved (fixed in 93.0.4577.82-1)
bullseye: resolved (fixed in 93.0.4577.82-1)
forky: resolved (fixed in 93.0.4577.82-1)
sid: resolved (fixed in 93.0.4577.82-1)
trixie: resolved (fixed in
debian
CVE-2021-30545P3HIGHCVSS 8.8fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30545 [HIGH] CVE-2021-30545: chromium - Use after free in Extensions in Google Chrome prior to 91.0.4472.101 allowed a r...
Use after free in Extensions in Google Chrome prior to 91.0.4472.101 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 93.0.4577.82-1)
bullseye: resolved (fixed in 93.0.4577.82-1)
forky: resolved (fixed in 93.0.4577.82-1)
sid: resolved (fixed i
debian
CVE-2022-1484P3HIGHCVSS 8.8fixed in chromium 101.0.4951.41-1 (bookworm)2022
CVE-2022-1484 [HIGH] CVE-2022-1484: chromium - Heap buffer overflow in Web UI Settings in Google Chrome prior to 101.0.4951.41 ...
Heap buffer overflow in Web UI Settings in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 101.0.4951.41-1)
bullseye: resolved (fixed in 101.0.4951.41-1~deb11u1)
forky: resolved (fixed in 101.0.4951.41-1)
sid: resolved (fixed in 101.0.4951.41-1)
tr
debian
CVE-2022-1310P3HIGHCVSS 8.8fixed in chromium 100.0.4896.88-1 (bookworm)2022
CVE-2022-1310 [HIGH] CVE-2022-1310: chromium - Use after free in regular expressions in Google Chrome prior to 100.0.4896.88 al...
Use after free in regular expressions in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 100.0.4896.88-1)
bullseye: resolved (fixed in 100.0.4896.88-1~deb11u1)
forky: resolved (fixed in 100.0.4896.88-1)
sid: resolved (fixed in 100.0.4896.88-1)
trix
debian
CVE-2021-4101P3HIGHCVSS 8.8fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-4101 [HIGH] CVE-2021-4101: chromium - Heap buffer overflow in Swiftshader in Google Chrome prior to 96.0.4664.110 allo...
Heap buffer overflow in Swiftshader in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 97.0.4692.71-0.1)
bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1)
forky: resolved (fixed in 97.0.4692.71-0.1)
sid: resolved (fixed in 97.0.4692.71-0.1)
tr
debian
CVE-2022-0809P3HIGHCVSS 8.8fixed in chromium 99.0.4844.51-1 (bookworm)2022
CVE-2022-0809 [HIGH] CVE-2022-0809: chromium - Out of bounds memory access in WebXR in Google Chrome prior to 99.0.4844.51 allo...
Out of bounds memory access in WebXR in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 99.0.4844.51-1)
bullseye: resolved (fixed in 99.0.4844.51-1~deb11u1)
forky: resolved (fixed in 99.0.4844.51-1)
sid: resolved (fixed in 99.0.4844.51-1)
trixie: re
debian
CVE-2022-1477P3HIGHCVSS 8.8fixed in chromium 101.0.4951.41-1 (bookworm)2022
CVE-2022-1477 [HIGH] CVE-2022-1477: chromium - Use after free in Vulkan in Google Chrome prior to 101.0.4951.41 allowed a remot...
Use after free in Vulkan in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 101.0.4951.41-1)
bullseye: resolved (fixed in 101.0.4951.41-1~deb11u1)
forky: resolved (fixed in 101.0.4951.41-1)
sid: resolved (fixed in 101.0.4951.41-1)
trixie: resolved
debian
CVE-2022-0796P3HIGHCVSS 8.8fixed in chromium 99.0.4844.51-1 (bookworm)2022
CVE-2022-0796 [HIGH] CVE-2022-0796: chromium - Use after free in Media in Google Chrome prior to 99.0.4844.51 allowed a remote ...
Use after free in Media in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 99.0.4844.51-1)
bullseye: resolved (fixed in 99.0.4844.51-1~deb11u1)
forky: resolved (fixed in 99.0.4844.51-1)
sid: resolved (fixed in 99.0.4844.51-1)
trixie: resolved (fixed
debian
CVE-2022-2011P3HIGHCVSS 8.8fixed in chromium 102.0.5005.115-1 (bookworm)2022
CVE-2022-2011 [HIGH] CVE-2022-2011: chromium - Use after free in ANGLE in Google Chrome prior to 102.0.5005.115 allowed a remot...
Use after free in ANGLE in Google Chrome prior to 102.0.5005.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 102.0.5005.115-1)
bullseye: resolved (fixed in 102.0.5005.115-1~deb11u1)
forky: resolved (fixed in 102.0.5005.115-1)
sid: resolved (fixed in 102.0.5005.115-1)
trixie: resol
debian
CVE-2022-0976P3HIGHCVSS 8.8fixed in chromium 99.0.4844.74-1 (bookworm)2022
CVE-2022-0976 [HIGH] CVE-2022-0976: chromium - Heap buffer overflow in GPU in Google Chrome prior to 99.0.4844.74 allowed a rem...
Heap buffer overflow in GPU in Google Chrome prior to 99.0.4844.74 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 99.0.4844.74-1)
bullseye: resolved (fixed in 99.0.4844.74-1~deb11u1)
forky: resolved (fixed in 99.0.4844.74-1)
sid: resolved (fixed in 99.0.4844.74-1)
trixie: resolved (f
debian
CVE-2022-1481P3HIGHCVSS 8.8fixed in chromium 101.0.4951.41-1 (bookworm)2022
CVE-2022-1481 [HIGH] CVE-2022-1481: chromium - Use after free in Sharing in Google Chrome on Mac prior to 101.0.4951.41 allowed...
Use after free in Sharing in Google Chrome on Mac prior to 101.0.4951.41 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 101.0.4951.41-1)
bullseye: resolved (fixed in 101.0.4951.41-1~deb11u1)
forky: resolved (fixed in 101.0.4
debian
CVE-2020-16035P3HIGHCVSS 8.8fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-16035 [HIGH] CVE-2020-16035: chromium - Insufficient data validation in cros-disks in Google Chrome on ChromeOS prior to...
Insufficient data validation in cros-disks in Google Chrome on ChromeOS prior to 87.0.4280.66 allowed a remote attacker who had compromised the browser process to bypass noexec restrictions via a malicious file.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid:
debian
CVE-2021-37978P3HIGHCVSS 8.8fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-37978 [HIGH] CVE-2021-37978: chromium - Heap buffer overflow in Blink in Google Chrome prior to 94.0.4606.81 allowed a r...
Heap buffer overflow in Blink in Google Chrome prior to 94.0.4606.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 97.0.4692.71-0.1)
bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1)
forky: resolved (fixed in 97.0.4692.71-0.1)
sid: resolved (fixed in 97.0.4692.71-0.1)
trixie:
debian
CVE-2020-16015P3HIGHCVSS 8.8fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-16015 [HIGH] CVE-2020-16015: chromium - Insufficient data validation in WASM in Google Chrome prior to 87.0.4280.66 allo...
Insufficient data validation in WASM in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (fixed in 87.0.4280.88-0.1)
trixie:
debian
CVE-2021-30626P3HIGHCVSS 8.8fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30626 [HIGH] CVE-2021-30626: chromium - Out of bounds memory access in ANGLE in Google Chrome prior to 93.0.4577.82 allo...
Out of bounds memory access in ANGLE in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 93.0.4577.82-1)
bullseye: resolved (fixed in 93.0.4577.82-1)
forky: resolved (fixed in 93.0.4577.82-1)
sid: resolved (fixed in 93.0.4577.82-1)
trixie: resolved
debian