Debian Chromium vulnerabilities
2,134 known vulnerabilities affecting debian/chromium.
Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8
Vulnerabilities
Page 54 of 107
CVE-2022-1635P3HIGHCVSS 8.8fixed in chromium 101.0.4951.64-1 (bookworm)2022
CVE-2022-1635 [HIGH] CVE-2022-1635: chromium - Use after free in Permission Prompts in Google Chrome prior to 101.0.4951.64 all...
Use after free in Permission Prompts in Google Chrome prior to 101.0.4951.64 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via specific user interactions.
Scope: local
bookworm: resolved (fixed in 101.0.4951.64-1)
bullseye: resolved (fixed in 101.0.4951.64-1~deb11u1)
forky: resolved (fixed
debian
CVE-2022-1860P3HIGHCVSS 8.8fixed in chromium 102.0.5005.61-1 (bookworm)2022
CVE-2022-1860 [HIGH] CVE-2022-1860: chromium - Use after free in UI Foundations in Google Chrome on Chrome OS prior to 102.0.50...
Use after free in UI Foundations in Google Chrome on Chrome OS prior to 102.0.5005.61 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via specific user interactions.
Scope: local
bookworm: resolved (fixed in 102.0.5005.61-1)
bullseye: resolved (fixed in 102.0.5005.61-1~deb11u1)
forky: resolv
debian
CVE-2022-1861P3HIGHCVSS 8.8fixed in chromium 102.0.5005.61-1 (bookworm)2022
CVE-2022-1861 [HIGH] CVE-2022-1861: chromium - Use after free in Sharing in Google Chrome on Chrome OS prior to 102.0.5005.61 a...
Use after free in Sharing in Google Chrome on Chrome OS prior to 102.0.5005.61 allowed a remote attacker who convinced a user to enage in specific user interactions to potentially exploit heap corruption via specific user interaction.
Scope: local
bookworm: resolved (fixed in 102.0.5005.61-1)
bullseye: resolved (fixed in 102.0.5005.61-1~deb11u1)
forky: resolved (fixe
debian
CVE-2022-1142P3HIGHCVSS 8.8fixed in chromium 100.0.4896.60-1 (bookworm)2022
CVE-2022-1142 [HIGH] CVE-2022-1142: chromium - Heap buffer overflow in WebUI in Google Chrome prior to 100.0.4896.60 allowed a ...
Heap buffer overflow in WebUI in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via specific input into DevTools.
Scope: local
bookworm: resolved (fixed in 100.0.4896.60-1)
bullseye: resolved (fixed in 100.0.4896.60-1~deb11u1)
forky: resolved (fixed in 1
debian
CVE-2022-0459P3HIGHCVSS 8.8fixed in chromium 98.0.4758.80-1 (bookworm)2022
CVE-2022-0459 [HIGH] CVE-2022-0459: chromium - Use after free in Screen Capture in Google Chrome prior to 98.0.4758.80 allowed ...
Use after free in Screen Capture in Google Chrome prior to 98.0.4758.80 allowed a remote attacker who had compromised the renderer process and convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 98.0.4758.80-1)
bullseye: resolved (fixed in 98.0.4758.80-1~deb1
debian
CVE-2022-0297P3HIGHCVSS 8.8fixed in chromium 97.0.4692.99-1 (bookworm)2022
CVE-2022-0297 [HIGH] CVE-2022-0297: chromium - Use after free in Vulkan in Google Chrome prior to 97.0.4692.99 allowed a remote...
Use after free in Vulkan in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 97.0.4692.99-1)
bullseye: resolved (fixed in 97.0.4692.99-1~deb11u2)
forky: resolved (fixed in 97.0.4692.99-1)
sid: resolved (fixed in 97.0.4692.99-1)
trixie: resolved (fixe
debian
CVE-2022-0293P3HIGHCVSS 8.8fixed in chromium 97.0.4692.99-1 (bookworm)2022
CVE-2022-0293 [HIGH] CVE-2022-0293: chromium - Use after free in Web packaging in Google Chrome prior to 97.0.4692.99 allowed a...
Use after free in Web packaging in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 97.0.4692.99-1)
bullseye: resolved (fixed in 97.0.4692.99-1~deb11u2)
forky: resolved (fixed in 97.0.4692.99-1)
sid: resolved (fixed in 97.0.4692.99-1)
trixie: resolve
debian
CVE-2022-0298P3HIGHCVSS 8.8fixed in chromium 97.0.4692.99-1 (bookworm)2022
CVE-2022-0298 [HIGH] CVE-2022-0298: chromium - Use after free in Scheduling in Google Chrome prior to 97.0.4692.99 allowed a re...
Use after free in Scheduling in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 97.0.4692.99-1)
bullseye: resolved (fixed in 97.0.4692.99-1~deb11u2)
forky: resolved (fixed in 97.0.4692.99-1)
sid: resolved (fixed in 97.0.4692.99-1)
trixie: resolved (
debian
CVE-2021-4099P3HIGHCVSS 8.8fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-4099 [HIGH] CVE-2021-4099: chromium - Use after free in Swiftshader in Google Chrome prior to 96.0.4664.110 allowed a ...
Use after free in Swiftshader in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 97.0.4692.71-0.1)
bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1)
forky: resolved (fixed in 97.0.4692.71-0.1)
sid: resolved (fixed in 97.0.4692.71-0.1)
trixie:
debian
CVE-2022-0453P3HIGHCVSS 8.8fixed in chromium 98.0.4758.80-1 (bookworm)2022
CVE-2022-0453 [HIGH] CVE-2022-0453: chromium - Use after free in Reader Mode in Google Chrome prior to 98.0.4758.80 allowed a r...
Use after free in Reader Mode in Google Chrome prior to 98.0.4758.80 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 98.0.4758.80-1)
bullseye: resolved (fixed in 98.0.4758.80-1~deb11u1)
forky: resolved (fixed in 98.0.4758.80-1)
sid: resolved (f
debian
CVE-2022-0457P3HIGHCVSS 8.8fixed in chromium 98.0.4758.80-1 (bookworm)2022
CVE-2022-0457 [HIGH] CVE-2022-0457: chromium - Type confusion in V8 in Google Chrome prior to 98.0.4758.80 allowed a remote att...
Type confusion in V8 in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 98.0.4758.80-1)
bullseye: resolved (fixed in 98.0.4758.80-1~deb11u1)
forky: resolved (fixed in 98.0.4758.80-1)
sid: resolved (fixed in 98.0.4758.80-1)
trixie: resolved (fixed in
debian
CVE-2022-0458P3HIGHCVSS 8.8fixed in chromium 98.0.4758.80-1 (bookworm)2022
CVE-2022-0458 [HIGH] CVE-2022-0458: chromium - Use after free in Thumbnail Tab Strip in Google Chrome prior to 98.0.4758.80 all...
Use after free in Thumbnail Tab Strip in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 98.0.4758.80-1)
bullseye: resolved (fixed in 98.0.4758.80-1~deb11u1)
forky: resolved (fixed in 98.0.4758.80-1)
sid: resolved (fixed in 98.0.4758.80-1)
trixie: r
debian
CVE-2022-1638P3HIGHCVSS 8.8fixed in chromium 101.0.4951.64-1 (bookworm)2022
CVE-2022-1638 [HIGH] CVE-2022-1638: chromium - Heap buffer overflow in V8 Internationalization in Google Chrome prior to 101.0....
Heap buffer overflow in V8 Internationalization in Google Chrome prior to 101.0.4951.64 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 101.0.4951.64-1)
bullseye: resolved (fixed in 101.0.4951.64-1~deb11u1)
forky: resolved (fixed in 101.0.4951.64-1)
sid: resolved (fixed in 101.0.4951.
debian
CVE-2022-3055P3HIGHCVSS 8.8fixed in chromium 105.0.5195.52-1 (bookworm)2022
CVE-2022-3055 [HIGH] CVE-2022-3055: chromium - Use after free in Passwords in Google Chrome prior to 105.0.5195.52 allowed a re...
Use after free in Passwords in Google Chrome prior to 105.0.5195.52 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 105.0.5195.52-1)
bullseye: resolved (fixed in 105.0.5195.52-1~deb11u1)
forky: resolved (fixed in 105.0.5195.52
debian
CVE-2022-2399P3HIGHCVSS 8.8fixed in chromium 100.0.4896.88-1 (bookworm)2022
CVE-2022-2399 [HIGH] CVE-2022-2399: chromium - Use after free in WebGPU in Google Chrome prior to 100.0.4896.88 allowed a remot...
Use after free in WebGPU in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 100.0.4896.88-1)
bullseye: resolved (fixed in 100.0.4896.88-1~deb11u1)
forky: resolved (fixed in 100.0.4896.88-1)
sid: resolved (fixed in 100.0.4896.88-1)
trixie: resolved
debian
CVE-2022-3051P3HIGHCVSS 8.8fixed in chromium 105.0.5195.52-1 (bookworm)2022
CVE-2022-3051 [HIGH] CVE-2022-3051: chromium - Heap buffer overflow in Exosphere in Google Chrome on Chrome OS, Lacros prior to...
Heap buffer overflow in Exosphere in Google Chrome on Chrome OS, Lacros prior to 105.0.5195.52 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via crafted UI interactions.
Scope: local
bookworm: resolved (fixed in 105.0.5195.52-1)
bullseye: resolved (fixed in 105.0.5195.52-1~deb11u1)
forky: r
debian
CVE-2022-2854P3HIGHCVSS 8.8fixed in chromium 104.0.5112.101-1 (bookworm)2022
CVE-2022-2854 [HIGH] CVE-2022-2854: chromium - Use after free in SwiftShader in Google Chrome prior to 104.0.5112.101 allowed a...
Use after free in SwiftShader in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 104.0.5112.101-1)
bullseye: resolved (fixed in 104.0.5112.101-1~deb11u1)
forky: resolved (fixed in 104.0.5112.101-1)
sid: resolved (fixed in 104.0.5112.101-1)
trixie:
debian
CVE-2022-2857P3HIGHCVSS 8.8fixed in chromium 104.0.5112.101-1 (bookworm)2022
CVE-2022-2857 [HIGH] CVE-2022-2857: chromium - Use after free in Blink in Google Chrome prior to 104.0.5112.101 allowed a remot...
Use after free in Blink in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 104.0.5112.101-1)
bullseye: resolved (fixed in 104.0.5112.101-1~deb11u1)
forky: resolved (fixed in 104.0.5112.101-1)
sid: resolved (fixed in 104.0.5112.101-1)
trixie: resol
debian
CVE-2022-3058P3HIGHCVSS 8.8fixed in chromium 105.0.5195.52-1 (bookworm)2022
CVE-2022-3058 [HIGH] CVE-2022-3058: chromium - Use after free in Sign-In Flow in Google Chrome prior to 105.0.5195.52 allowed a...
Use after free in Sign-In Flow in Google Chrome prior to 105.0.5195.52 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via crafted UI interaction.
Scope: local
bookworm: resolved (fixed in 105.0.5195.52-1)
bullseye: resolved (fixed in 105.0.5195.52-1~deb11u1)
forky: resolved (fixed in 105.0.5
debian
CVE-2022-2603P3HIGHCVSS 8.8fixed in chromium 104.0.5112.79-1 (bookworm)2022
CVE-2022-2603 [HIGH] CVE-2022-2603: chromium - Use after free in Omnibox in Google Chrome prior to 104.0.5112.79 allowed a remo...
Use after free in Omnibox in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 104.0.5112.79-1)
bullseye: resolved (fixed in 104.0.5112.79-1~deb11u1)
forky: resolved (fixed in 104.0.5112.79-1)
sid: resolved (fixed in 104.0.5112.79-1)
trixie: resolved
debian