cbcvebase.

Debian Chromium vulnerabilities

2,134 known vulnerabilities affecting debian/chromium.

Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8

Vulnerabilities

Page 55 of 107
CVE-2022-4190P3HIGHCVSS 8.8fixed in chromium 108.0.5359.71-1 (bookworm)2022
CVE-2022-4190 [HIGH] CVE-2022-4190: chromium - Insufficient data validation in Directory in Google Chrome prior to 108.0.5359.7... Insufficient data validation in Directory in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to bypass file system restrictions via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 108.0.5359.71-1) bullseye: resolved (fixed in 108.0.5359.71-2~deb11u1) forky: resolved (fixed in 108.0.5359.71-1) sid: res
debian
CVE-2022-3448P3HIGHCVSS 8.8fixed in chromium 106.0.5249.119-1 (bookworm)2022
CVE-2022-3448 [HIGH] CVE-2022-3448: chromium - Use after free in Permissions API in Google Chrome prior to 106.0.5249.119 allow... Use after free in Permissions API in Google Chrome prior to 106.0.5249.119 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 106.0.5249.119-1) bullseye: resolved (fixed in 106.0.5249.119-1~deb11u1)
debian
CVE-2023-4366P3HIGHCVSS 8.8fixed in chromium 116.0.5845.96-1~deb12u1 (bookworm)2023
CVE-2023-4366 [HIGH] CVE-2023-4366: chromium - Use after free in Extensions in Google Chrome prior to 116.0.5845.96 allowed an ... Use after free in Extensions in Google Chrome prior to 116.0.5845.96 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 116.0.5845.96-1~deb12u1) bullseye: resolved (fixed in 116.0.5845.96-1~deb11u1) fork
debian
CVE-2022-2614P3HIGHCVSS 8.8fixed in chromium 104.0.5112.79-1 (bookworm)2022
CVE-2022-2614 [HIGH] CVE-2022-2614: chromium - Use after free in Sign-In Flow in Google Chrome prior to 104.0.5112.79 allowed a... Use after free in Sign-In Flow in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 104.0.5112.79-1) bullseye: resolved (fixed in 104.0.5112.79-1~deb11u1) forky: resolved (fixed in 104.0.5112.79-1) sid: resolved (fixed in 104.0.5112.79-1) trixie: res
debian
CVE-2022-2604P3HIGHCVSS 8.8fixed in chromium 104.0.5112.79-1 (bookworm)2022
CVE-2022-2604 [HIGH] CVE-2022-2604: chromium - Use after free in Safe Browsing in Google Chrome prior to 104.0.5112.79 allowed ... Use after free in Safe Browsing in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 104.0.5112.79-1) bullseye: resolved (fixed in 104.0.5112.79-1~deb11u1) forky: resolved (fixed in 104.0.5112.79-1) sid: resolved (fixed in 104.0.5112.79-1) trixie: re
debian
CVE-2022-2623P3HIGHCVSS 8.8fixed in chromium 104.0.5112.79-1 (bookworm)2022
CVE-2022-2623 [HIGH] CVE-2022-2623: chromium - Use after free in Offline in Google Chrome on Android prior to 104.0.5112.79 all... Use after free in Offline in Google Chrome on Android prior to 104.0.5112.79 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via specific UI interactions. Scope: local bookworm: resolved (fixed in 104.0.5112.79-1) bullseye: resolved (fixed in 104.0.5112.79-1~deb11u1) forky: resolved (fixed
debian
CVE-2023-0933P3HIGHCVSS 8.8fixed in chromium 110.0.5481.177-1 (bookworm)2023
CVE-2023-0933 [HIGH] CVE-2023-0933: chromium - Integer overflow in PDF in Google Chrome prior to 110.0.5481.177 allowed a remot... Integer overflow in PDF in Google Chrome prior to 110.0.5481.177 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 110.0.5481.177-1) bullseye: resolved (fixed in 110.0.5481.177-1~deb11u1) forky: resolved (fixed in 110.0.5481.177-1) sid: resolved (fixe
debian
CVE-2023-0927P3HIGHCVSS 8.8fixed in chromium 110.0.5481.177-1 (bookworm)2023
CVE-2023-0927 [HIGH] CVE-2023-0927: chromium - Use after free in Web Payments API in Google Chrome on Android prior to 110.0.54... Use after free in Web Payments API in Google Chrome on Android prior to 110.0.5481.177 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 110.0.5481.177-1) bullseye: resolved (fixed in 110.0.5481.177-1~deb11u1) f
debian
CVE-2022-3049P3HIGHCVSS 8.8fixed in chromium 105.0.5195.52-1 (bookworm)2022
CVE-2022-3049 [HIGH] CVE-2022-3049: chromium - Use after free in SplitScreen in Google Chrome on Chrome OS, Lacros prior to 105... Use after free in SplitScreen in Google Chrome on Chrome OS, Lacros prior to 105.0.5195.52 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 105.0.5195.52-1) bullseye: resolved (fixed in 105.0.5195.52-1~deb11u1) forky: resolved
debian
CVE-2023-1216P3HIGHCVSS 8.8fixed in chromium 111.0.5563.64-1 (bookworm)2023
CVE-2023-1216 [HIGH] CVE-2023-1216: chromium - Use after free in DevTools in Google Chrome prior to 111.0.5563.64 allowed a rem... Use after free in DevTools in Google Chrome prior to 111.0.5563.64 allowed a remote attacker who had convienced the user to engage in direct UI interaction to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 111.0.5563.64-1) bullseye: resolved (fixed in 111.0.5563.64-1~deb11u1) f
debian
CVE-2022-3042P3HIGHCVSS 8.8fixed in chromium 105.0.5195.52-1 (bookworm)2022
CVE-2022-3042 [HIGH] CVE-2022-3042: chromium - Use after free in PhoneHub in Google Chrome on Chrome OS prior to 105.0.5195.52 ... Use after free in PhoneHub in Google Chrome on Chrome OS prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 105.0.5195.52-1) bullseye: resolved (fixed in 105.0.5195.52-1~deb11u1) forky: resolved (fixed in 105.0.5195.52-1) sid: resolved (fixed in 105.0.5195.52-1) tr
debian
CVE-2023-0137P3HIGHCVSS 8.8fixed in chromium 109.0.5414.74-1 (bookworm)2023
CVE-2023-0137 [HIGH] CVE-2023-0137: chromium - Heap buffer overflow in Platform Apps in Google Chrome on Chrome OS prior to 109... Heap buffer overflow in Platform Apps in Google Chrome on Chrome OS prior to 109.0.5414.74 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 109.0.5414.74-1) bullseye: resolved (fixed in 109.0.5414.74-2
debian
CVE-2023-0129P3HIGHCVSS 8.8fixed in chromium 109.0.5414.74-1 (bookworm)2023
CVE-2023-0129 [HIGH] CVE-2023-0129: chromium - Heap buffer overflow in Network Service in Google Chrome prior to 109.0.5414.74 ... Heap buffer overflow in Network Service in Google Chrome prior to 109.0.5414.74 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page and specific interactions. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 109.0.5414.74-1) bullseye: resolved (fixed in 10
debian
CVE-2022-4179P3HIGHCVSS 8.8fixed in chromium 108.0.5359.71-1 (bookworm)2022
CVE-2022-4179 [HIGH] CVE-2022-4179: chromium - Use after free in Audio in Google Chrome prior to 108.0.5359.71 allowed an attac... Use after free in Audio in Google Chrome prior to 108.0.5359.71 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 108.0.5359.71-1) bullseye: resolved (fixed in 108.0.5359.71-2~deb11u1) forky: resol
debian
CVE-2022-4180P3HIGHCVSS 8.8fixed in chromium 108.0.5359.71-1 (bookworm)2022
CVE-2022-4180 [HIGH] CVE-2022-4180: chromium - Use after free in Mojo in Google Chrome prior to 108.0.5359.71 allowed an attack... Use after free in Mojo in Google Chrome prior to 108.0.5359.71 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 108.0.5359.71-1) bullseye: resolved (fixed in 108.0.5359.71-2~deb11u1) forky: resolv
debian
CVE-2022-3658P3HIGHCVSS 8.8fixed in chromium 107.0.5304.68-1 (bookworm)2022
CVE-2022-3658 [HIGH] CVE-2022-3658: chromium - Use after free in Feedback service on Chrome OS in Google Chrome on Chrome OS pr... Use after free in Feedback service on Chrome OS in Google Chrome on Chrome OS prior to 107.0.5304.62 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via specific UI interaction. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 107.0.5304.68-1) bullseye: resolved (fixed in 1
debian
CVE-2023-1227P3HIGHCVSS 8.8fixed in chromium 111.0.5563.64-1 (bookworm)2023
CVE-2023-1227 [HIGH] CVE-2023-1227: chromium - Use after free in Core in Google Chrome on Lacros prior to 111.0.5563.64 allowed... Use after free in Core in Google Chrome on Lacros prior to 111.0.5563.64 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via crafted UI interaction. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 111.0.5563.64-1) bullseye: resolved (fixed in 111.0.5563.64-1~deb1
debian
CVE-2022-3071P3HIGHCVSS 8.8fixed in chromium 105.0.5195.52-1 (bookworm)2022
CVE-2022-3071 [HIGH] CVE-2022-3071: chromium - Use after free in Tab Strip in Google Chrome on Chrome OS, Lacros prior to 105.0... Use after free in Tab Strip in Google Chrome on Chrome OS, Lacros prior to 105.0.5195.52 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via crafted UI interaction. Scope: local bookworm: resolved (fixed in 105.0.5195.52-1) bullseye: resolved (fixed in 105.0.5195.52-1~deb11u1) forky: resolved
debian
CVE-2022-2609P3HIGHCVSS 8.8fixed in chromium 104.0.5112.79-1 (bookworm)2022
CVE-2022-2609 [HIGH] CVE-2022-2609: chromium - Use after free in Nearby Share in Google Chrome on Chrome OS prior to 104.0.5112... Use after free in Nearby Share in Google Chrome on Chrome OS prior to 104.0.5112.79 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via specific UI interactions. Scope: local bookworm: resolved (fixed in 104.0.5112.79-1) bullseye: resolved (fixed in 104.0.5112.79-1~deb11u1) forky: resolved
debian
CVE-2022-2607P3HIGHCVSS 8.8fixed in chromium 104.0.5112.79-1 (bookworm)2022
CVE-2022-2607 [HIGH] CVE-2022-2607: chromium - Use after free in Tab Strip in Google Chrome on Chrome OS prior to 104.0.5112.79... Use after free in Tab Strip in Google Chrome on Chrome OS prior to 104.0.5112.79 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via specific UI interactions. Scope: local bookworm: resolved (fixed in 104.0.5112.79-1) bullseye: resolved (fixed in 104.0.5112.79-1~deb11u1) forky: resolved (fi
debian
Debian Chromium vulnerabilities | cvebase