Debian Chromium vulnerabilities
2,134 known vulnerabilities affecting debian/chromium.
Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8
Vulnerabilities
Page 51 of 107
CVE-2021-37984P3HIGHCVSS 8.8fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-37984 [HIGH] CVE-2021-37984: chromium - Heap buffer overflow in PDFium in Google Chrome prior to 95.0.4638.54 allowed a ...
Heap buffer overflow in PDFium in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 97.0.4692.71-0.1)
bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1)
forky: resolved (fixed in 97.0.4692.71-0.1)
sid: resolved (fixed in 97.0.4692.71-0.1)
trixie
debian
CVE-2022-0470P3HIGHCVSS 8.8fixed in chromium 98.0.4758.80-1 (bookworm)2022
CVE-2022-0470 [HIGH] CVE-2022-0470: chromium - Out of bounds memory access in V8 in Google Chrome prior to 98.0.4758.80 allowed...
Out of bounds memory access in V8 in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 98.0.4758.80-1)
bullseye: resolved (fixed in 98.0.4758.80-1~deb11u1)
forky: resolved (fixed in 98.0.4758.80-1)
sid: resolved (fixed in 98.0.4758.80-1)
trixie: resol
debian
CVE-2022-2161P3HIGHCVSS 8.8fixed in chromium 103.0.5060.53-1 (bookworm)2022
CVE-2022-2161 [HIGH] CVE-2022-2161: chromium - Use after free in WebApp Provider in Google Chrome prior to 103.0.5060.53 allowe...
Use after free in WebApp Provider in Google Chrome prior to 103.0.5060.53 allowed a remote attacker who convinced the user to engage in specific user interactions to potentially exploit heap corruption via specific UI interactions.
Scope: local
bookworm: resolved (fixed in 103.0.5060.53-1)
bullseye: resolved (fixed in 103.0.5060.53-1~deb11u1)
forky: resolved (fixed i
debian
CVE-2021-30628P3HIGHCVSS 8.8fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30628 [HIGH] CVE-2021-30628: chromium - Stack buffer overflow in ANGLE in Google Chrome prior to 93.0.4577.82 allowed a ...
Stack buffer overflow in ANGLE in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit stack corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 93.0.4577.82-1)
bullseye: resolved (fixed in 93.0.4577.82-1)
forky: resolved (fixed in 93.0.4577.82-1)
sid: resolved (fixed in 93.0.4577.82-1)
trixie: resolved (fix
debian
CVE-2022-2007P3HIGHCVSS 8.8fixed in chromium 102.0.5005.115-1 (bookworm)2022
CVE-2022-2007 [HIGH] CVE-2022-2007: chromium - Use after free in WebGPU in Google Chrome prior to 102.0.5005.115 allowed a remo...
Use after free in WebGPU in Google Chrome prior to 102.0.5005.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 102.0.5005.115-1)
bullseye: resolved (fixed in 102.0.5005.115-1~deb11u1)
forky: resolved (fixed in 102.0.5005.115-1)
sid: resolved (fixed in 102.0.5005.115-1)
trixie: reso
debian
CVE-2021-37998P3HIGHCVSS 8.8fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-37998 [HIGH] CVE-2021-37998: chromium - Use after free in Garbage Collection in Google Chrome prior to 95.0.4638.69 allo...
Use after free in Garbage Collection in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 97.0.4692.71-0.1)
bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1)
forky: resolved (fixed in 97.0.4692.71-0.1)
sid: resolved (fixed in 97.0.4692.71-0.1)
debian
CVE-2022-0107P3HIGHCVSS 8.8fixed in chromium 97.0.4692.71-0.1 (bookworm)2022
CVE-2022-0107 [HIGH] CVE-2022-0107: chromium - Use after free in File Manager API in Google Chrome on Chrome OS prior to 97.0.4...
Use after free in File Manager API in Google Chrome on Chrome OS prior to 97.0.4692.71 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 97.0.4692.71-0.1)
bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1)
forky: resolved (fixed in 97.
debian
CVE-2022-1308P3HIGHCVSS 8.8fixed in chromium 100.0.4896.88-1 (bookworm)2022
CVE-2022-1308 [HIGH] CVE-2022-1308: chromium - Use after free in BFCache in Google Chrome prior to 100.0.4896.88 allowed a remo...
Use after free in BFCache in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 100.0.4896.88-1)
bullseye: resolved (fixed in 100.0.4896.88-1~deb11u1)
forky: resolved (fixed in 100.0.4896.88-1)
sid: resolved (fixed in 100.0.4896.88-1)
trixie: resolved
debian
CVE-2019-5858P3HIGHCVSS 8.8fixed in chromium 76.0.3809.87-1 (bookworm)2019
CVE-2019-5858 [HIGH] CVE-2019-5858: chromium - Incorrect security UI in MacOS services integration in Google Chrome on OS X pri...
Incorrect security UI in MacOS services integration in Google Chrome on OS X prior to 76.0.3809.87 allowed a local attacker to execute arbitrary code via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 76.0.3809.87-1)
bullseye: resolved (fixed in 76.0.3809.87-1)
forky: resolved (fixed in 76.0.3809.87-1)
sid: resolved (fixed in 76.0.3809.87-1)
trixie: r
debian
CVE-2022-1478P3HIGHCVSS 8.8fixed in chromium 101.0.4951.41-1 (bookworm)2022
CVE-2022-1478 [HIGH] CVE-2022-1478: chromium - Use after free in SwiftShader in Google Chrome prior to 101.0.4951.41 allowed a ...
Use after free in SwiftShader in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 101.0.4951.41-1)
bullseye: resolved (fixed in 101.0.4951.41-1~deb11u1)
forky: resolved (fixed in 101.0.4951.41-1)
sid: resolved (fixed in 101.0.4951.41-1)
trixie: reso
debian
CVE-2022-1479P3HIGHCVSS 8.8fixed in chromium 101.0.4951.41-1 (bookworm)2022
CVE-2022-1479 [HIGH] CVE-2022-1479: chromium - Use after free in ANGLE in Google Chrome prior to 101.0.4951.41 allowed a remote...
Use after free in ANGLE in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 101.0.4951.41-1)
bullseye: resolved (fixed in 101.0.4951.41-1~deb11u1)
forky: resolved (fixed in 101.0.4951.41-1)
sid: resolved (fixed in 101.0.4951.41-1)
trixie: resolved (
debian
CVE-2022-0098P3HIGHCVSS 8.8fixed in chromium 97.0.4692.71-0.1 (bookworm)2022
CVE-2022-0098 [HIGH] CVE-2022-0098: chromium - Use after free in Screen Capture in Google Chrome on Chrome OS prior to 97.0.469...
Use after free in Screen Capture in Google Chrome on Chrome OS prior to 97.0.4692.71 allowed an attacker who convinced a user to perform specific user gestures to potentially exploit heap corruption via specific user gestures.
Scope: local
bookworm: resolved (fixed in 97.0.4692.71-0.1)
bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1)
forky: resolved (fixed in 9
debian
CVE-2022-0791P3HIGHCVSS 8.8fixed in chromium 99.0.4844.51-1 (bookworm)2022
CVE-2022-0791 [HIGH] CVE-2022-0791: chromium - Use after free in Omnibox in Google Chrome prior to 99.0.4844.51 allowed a remot...
Use after free in Omnibox in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via user interactions.
Scope: local
bookworm: resolved (fixed in 99.0.4844.51-1)
bullseye: resolved (fixed in 99.0.4844.51-1~deb11u1)
forky: resolved (fixed in 99.0.4844.51-1)
si
debian
CVE-2023-1815P3HIGHCVSS 8.8fixed in chromium 112.0.5615.49-1 (bookworm)2023
CVE-2023-1815 [HIGH] CVE-2023-1815: chromium - Use after free in Networking APIs in Google Chrome prior to 112.0.5615.49 allowe...
Use after free in Networking APIs in Google Chrome prior to 112.0.5615.49 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 112.0.5615.49-1)
bullseye: resolved (fixed in 112.0.5615.49-2~deb11u
debian
CVE-2021-38012P3HIGHCVSS 8.8fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-38012 [HIGH] CVE-2021-38012: chromium - Type confusion in V8 in Google Chrome prior to 96.0.4664.45 allowed a remote att...
Type confusion in V8 in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 97.0.4692.71-0.1)
bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1)
forky: resolved (fixed in 97.0.4692.71-0.1)
sid: resolved (fixed in 97.0.4692.71-0.1)
trixie: resolved
debian
CVE-2021-38007P3HIGHCVSS 8.8fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-38007 [HIGH] CVE-2021-38007: chromium - Type confusion in V8 in Google Chrome prior to 96.0.4664.45 allowed a remote att...
Type confusion in V8 in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 97.0.4692.71-0.1)
bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1)
forky: resolved (fixed in 97.0.4692.71-0.1)
sid: resolved (fixed in 97.0.4692.71-0.1)
trixie: resolved
debian
CVE-2022-3041P3HIGHCVSS 8.8fixed in chromium 105.0.5195.52-1 (bookworm)2022
CVE-2022-3041 [HIGH] CVE-2022-3041: chromium - Use after free in WebSQL in Google Chrome prior to 105.0.5195.52 allowed a remot...
Use after free in WebSQL in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 105.0.5195.52-1)
bullseye: resolved (fixed in 105.0.5195.52-1~deb11u1)
forky: resolved (fixed in 105.0.5195.52-1)
sid: resolved (fixed in 105.0.5195.52-1)
trixie: resolved
debian
CVE-2022-3040P3HIGHCVSS 8.8fixed in chromium 105.0.5195.52-1 (bookworm)2022
CVE-2022-3040 [HIGH] CVE-2022-3040: chromium - Use after free in Layout in Google Chrome prior to 105.0.5195.52 allowed a remot...
Use after free in Layout in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 105.0.5195.52-1)
bullseye: resolved (fixed in 105.0.5195.52-1~deb11u1)
forky: resolved (fixed in 105.0.5195.52-1)
sid: resolved (fixed in 105.0.5195.52-1)
trixie: resolved
debian
CVE-2022-1641P3HIGHCVSS 8.8fixed in chromium 101.0.4951.64-1 (bookworm)2022
CVE-2022-1641 [HIGH] CVE-2022-1641: chromium - Use after free in Web UI Diagnostics in Google Chrome on Chrome OS prior to 101....
Use after free in Web UI Diagnostics in Google Chrome on Chrome OS prior to 101.0.4951.64 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via specific user interaction.
Scope: local
bookworm: resolved (fixed in 101.0.4951.64-1)
bullseye: resolved (fixed in 101.0.4951.64-1~deb11u1)
forky: reso
debian
CVE-2022-1855P3HIGHCVSS 8.8fixed in chromium 102.0.5005.61-1 (bookworm)2022
CVE-2022-1855 [HIGH] CVE-2022-1855: chromium - Use after free in Messaging in Google Chrome prior to 102.0.5005.61 allowed a re...
Use after free in Messaging in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 102.0.5005.61-1)
bullseye: resolved (fixed in 102.0.5005.61-1~deb11u1)
forky: resolved (fixed in 102.0.5005.61-1)
sid: resolved (fixed in 102.0.5005.61-1)
trixie: resolv
debian