cbcvebase.

Debian Chromium vulnerabilities

2,134 known vulnerabilities affecting debian/chromium.

Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8

Vulnerabilities

Page 53 of 107
CVE-2021-4079P3HIGHCVSS 8.8fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-4079 [HIGH] CVE-2021-4079: chromium - Out of bounds write in WebRTC in Google Chrome prior to 96.0.4664.93 allowed a r... Out of bounds write in WebRTC in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via crafted WebRTC packets. Scope: local bookworm: resolved (fixed in 97.0.4692.71-0.1) bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1) forky: resolved (fixed in 97.0.4692.71-0.1) sid: resolved (fixed in 97.0.4692.71-0.1) trixie
debian
CVE-2022-1636P3HIGHCVSS 8.8fixed in chromium 101.0.4951.64-1 (bookworm)2022
CVE-2022-1636 [HIGH] CVE-2022-1636: chromium - Use after free in Performance APIs in Google Chrome prior to 101.0.4951.64 allow... Use after free in Performance APIs in Google Chrome prior to 101.0.4951.64 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 101.0.4951.64-1) bullseye: resolved (fixed in 101.0.4951.64-1~deb11u1) forky: resolved (fixed in 101.0.4951.64-1) sid: resolved (fixed in 101.0.4951.64-1) trixie:
debian
CVE-2022-1143P3HIGHCVSS 8.8fixed in chromium 100.0.4896.60-1 (bookworm)2022
CVE-2022-1143 [HIGH] CVE-2022-1143: chromium - Heap buffer overflow in WebUI in Google Chrome prior to 100.0.4896.60 allowed a ... Heap buffer overflow in WebUI in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via specific input into DevTools. Scope: local bookworm: resolved (fixed in 100.0.4896.60-1) bullseye: resolved (fixed in 100.0.4896.60-1~deb11u1) forky: resolved (fixed in 1
debian
CVE-2021-38014P3HIGHCVSS 8.8fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-38014 [HIGH] CVE-2021-38014: chromium - Out of bounds write in Swiftshader in Google Chrome prior to 96.0.4664.45 allowe... Out of bounds write in Swiftshader in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 97.0.4692.71-0.1) bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1) forky: resolved (fixed in 97.0.4692.71-0.1) sid: resolved (fixed in 97.0.4692.71-0.1) tr
debian
CVE-2022-0607P3HIGHCVSS 8.8fixed in chromium 98.0.4758.102-1 (bookworm)2022
CVE-2022-0607 [HIGH] CVE-2022-0607: chromium - Use after free in GPU in Google Chrome prior to 98.0.4758.102 allowed a remote a... Use after free in GPU in Google Chrome prior to 98.0.4758.102 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 98.0.4758.102-1) bullseye: resolved (fixed in 98.0.4758.102-1~deb11u1) forky: resolved (fixed in 98.0.4758.102-1) sid: resolved (fixed in 98.0.4758.102-1) trixie: resolved (fi
debian
CVE-2022-0603P3HIGHCVSS 8.8fixed in chromium 98.0.4758.102-1 (bookworm)2022
CVE-2022-0603 [HIGH] CVE-2022-0603: chromium - Use after free in File Manager in Google Chrome on Chrome OS prior to 98.0.4758.... Use after free in File Manager in Google Chrome on Chrome OS prior to 98.0.4758.102 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 98.0.4758.102-1) bullseye: resolved (fixed in 98.0.4758.102-1~deb11u1) forky: resolved (fixed in 98.0.4758.102-1) sid: resolved (fixed in 98.0.4758.102-1
debian
CVE-2022-0606P3HIGHCVSS 8.8fixed in chromium 98.0.4758.102-1 (bookworm)2022
CVE-2022-0606 [HIGH] CVE-2022-0606: chromium - Use after free in ANGLE in Google Chrome prior to 98.0.4758.102 allowed a remote... Use after free in ANGLE in Google Chrome prior to 98.0.4758.102 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 98.0.4758.102-1) bullseye: resolved (fixed in 98.0.4758.102-1~deb11u1) forky: resolved (fixed in 98.0.4758.102-1) sid: resolved (fixed in 98.0.4758.102-1) trixie: resolved (
debian
CVE-2022-4192P3HIGHCVSS 8.8fixed in chromium 108.0.5359.71-1 (bookworm)2022
CVE-2022-4192 [HIGH] CVE-2022-4192: chromium - Use after free in Live Caption in Google Chrome prior to 108.0.5359.71 allowed a... Use after free in Live Caption in Google Chrome prior to 108.0.5359.71 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via UI interaction. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 108.0.5359.71-1) bullseye: resolved (fixed in 108.0.5359.71-2~deb11u1) forky
debian
CVE-2022-0979P3HIGHCVSS 8.8fixed in chromium 99.0.4844.74-1 (bookworm)2022
CVE-2022-0979 [HIGH] CVE-2022-0979: chromium - Use after free in Safe Browsing in Google Chrome on Android prior to 99.0.4844.7... Use after free in Safe Browsing in Google Chrome on Android prior to 99.0.4844.74 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 99.0.4844.74-1) bullseye: resolved (fixed in 99.0.4844.74-1~deb11u1) forky: resolved (fixed in
debian
CVE-2021-37987P3HIGHCVSS 8.8fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-37987 [HIGH] CVE-2021-37987: chromium - Use after free in Network APIs in Google Chrome prior to 95.0.4638.54 allowed a ... Use after free in Network APIs in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 97.0.4692.71-0.1) bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1) forky: resolved (fixed in 97.0.4692.71-0.1) sid: resolved (fixed in 97.0.4692.71-0.1) trixie
debian
CVE-2022-2858P3HIGHCVSS 8.8fixed in chromium 104.0.5112.101-1 (bookworm)2022
CVE-2022-2858 [HIGH] CVE-2022-2858: chromium - Use after free in Sign-In Flow in Google Chrome prior to 104.0.5112.101 allowed ... Use after free in Sign-In Flow in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to potentially exploit heap corruption via specific UI interaction. Scope: local bookworm: resolved (fixed in 104.0.5112.101-1) bullseye: resolved (fixed in 104.0.5112.101-1~deb11u1) forky: resolved (fixed in 104.0.5112.101-1) sid: resolved (fixed in 104.0.5112.101-1) tr
debian
CVE-2022-1857P3HIGHCVSS 8.8fixed in chromium 102.0.5005.61-1 (bookworm)2022
CVE-2022-1857 [HIGH] CVE-2022-1857: chromium - Insufficient policy enforcement in File System API in Google Chrome prior to 102... Insufficient policy enforcement in File System API in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to bypass file system restrictions via a crafted HTML page. Scope: local bookworm: resolved (fixed in 102.0.5005.61-1) bullseye: resolved (fixed in 102.0.5005.61-1~deb11u1) forky: resolved (fixed in 102.0.5005.61-1) sid: resolved (fixed in 102.0.5005.6
debian
CVE-2022-1866P3HIGHCVSS 8.8fixed in chromium 102.0.5005.61-1 (bookworm)2022
CVE-2022-1866 [HIGH] CVE-2022-1866: chromium - Use after free in Tablet Mode in Google Chrome on Chrome OS prior to 102.0.5005.... Use after free in Tablet Mode in Google Chrome on Chrome OS prior to 102.0.5005.61 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via specific user interactions. Scope: local bookworm: resolved (fixed in 102.0.5005.61-1) bullseye: resolved (fixed in 102.0.5005.61-1~deb11u1) forky: resolved
debian
CVE-2022-3039P3HIGHCVSS 8.8fixed in chromium 105.0.5195.52-1 (bookworm)2022
CVE-2022-3039 [HIGH] CVE-2022-3039: chromium - Use after free in WebSQL in Google Chrome prior to 105.0.5195.52 allowed a remot... Use after free in WebSQL in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 105.0.5195.52-1) bullseye: resolved (fixed in 105.0.5195.52-1~deb11u1) forky: resolved (fixed in 105.0.5195.52-1) sid: resolved (fixed in 105.0.5195.52-1) trixie: resolved
debian
CVE-2022-2855P3HIGHCVSS 8.8fixed in chromium 104.0.5112.101-1 (bookworm)2022
CVE-2022-2855 [HIGH] CVE-2022-2855: chromium - Use after free in ANGLE in Google Chrome prior to 104.0.5112.101 allowed a remot... Use after free in ANGLE in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 104.0.5112.101-1) bullseye: resolved (fixed in 104.0.5112.101-1~deb11u1) forky: resolved (fixed in 104.0.5112.101-1) sid: resolved (fixed in 104.0.5112.101-1) trixie: resol
debian
CVE-2022-2624P3HIGHCVSS 8.8fixed in chromium 104.0.5112.79-1 (bookworm)2022
CVE-2022-2624 [HIGH] CVE-2022-2624: chromium - Heap buffer overflow in PDF in Google Chrome prior to 104.0.5112.79 allowed a re... Heap buffer overflow in PDF in Google Chrome prior to 104.0.5112.79 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via a crafted PDF file. Scope: local bookworm: resolved (fixed in 104.0.5112.79-1) bullseye: resolved (fixed in 104.0.5112.79-1~deb11u1) forky: resolved (fixed in 104.0.5112.7
debian
CVE-2022-0310P3HIGHCVSS 8.8fixed in chromium 97.0.4692.99-1 (bookworm)2022
CVE-2022-0310 [HIGH] CVE-2022-0310: chromium - Heap buffer overflow in Task Manager in Google Chrome prior to 97.0.4692.99 allo... Heap buffer overflow in Task Manager in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to potentially exploit heap corruption via specific user interactions. Scope: local bookworm: resolved (fixed in 97.0.4692.99-1) bullseye: resolved (fixed in 97.0.4692.99-1~deb11u2) forky: resolved (fixed in 97.0.4692.99-1) sid: resolved (fixed in 97.0.4692.99-1) tri
debian
CVE-2022-1859P3HIGHCVSS 8.8fixed in chromium 102.0.5005.61-1 (bookworm)2022
CVE-2022-1859 [HIGH] CVE-2022-1859: chromium - Use after free in Performance Manager in Google Chrome prior to 102.0.5005.61 al... Use after free in Performance Manager in Google Chrome prior to 102.0.5005.61 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 102.0.5005.61-1) bullseye: resolved (fixed in 102.0.5005.61-1~deb11u1) forky: resolved (fixed in 10
debian
CVE-2022-3052P3HIGHCVSS 8.8fixed in chromium 105.0.5195.52-1 (bookworm)2022
CVE-2022-3052 [HIGH] CVE-2022-3052: chromium - Heap buffer overflow in Window Manager in Google Chrome on Chrome OS, Lacros pri... Heap buffer overflow in Window Manager in Google Chrome on Chrome OS, Lacros prior to 105.0.5195.52 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via crafted UI interactions. Scope: local bookworm: resolved (fixed in 105.0.5195.52-1) bullseye: resolved (fixed in 105.0.5195.52-1~deb11u1) for
debian
CVE-2022-3050P3HIGHCVSS 8.8fixed in chromium 105.0.5195.52-1 (bookworm)2022
CVE-2022-3050 [HIGH] CVE-2022-3050: chromium - Heap buffer overflow in WebUI in Google Chrome on Chrome OS prior to 105.0.5195.... Heap buffer overflow in WebUI in Google Chrome on Chrome OS prior to 105.0.5195.52 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via crafted UI interactions. Scope: local bookworm: resolved (fixed in 105.0.5195.52-1) bullseye: resolved (fixed in 105.0.5195.52-1~deb11u1) forky: resolved (fix
debian
Debian Chromium vulnerabilities | cvebase