cbcvebase.

Debian Chromium vulnerabilities

2,134 known vulnerabilities affecting debian/chromium.

Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8

Vulnerabilities

Page 57 of 107
CVE-2020-15974P3HIGHCVSS 8.8fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-15974 [HIGH] CVE-2020-15974: chromium - Integer overflow in Blink in Google Chrome prior to 86.0.4240.75 allowed a remot... Integer overflow in Blink in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to bypass site isolation via a crafted HTML page. Scope: local bookworm: resolved (fixed in 87.0.4280.88-0.1) bullseye: resolved (fixed in 87.0.4280.88-0.1) forky: resolved (fixed in 87.0.4280.88-0.1) sid: resolved (fixed in 87.0.4280.88-0.1) trixie: resolved (fixed in 87.0.4
debian
CVE-2020-6450P3HIGHCVSS 8.8fixed in chromium 80.0.3987.162-1 (bookworm)2020
CVE-2020-6450 [HIGH] CVE-2020-6450: chromium - Use after free in WebAudio in Google Chrome prior to 80.0.3987.162 allowed a rem... Use after free in WebAudio in Google Chrome prior to 80.0.3987.162 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 80.0.3987.162-1) bullseye: resolved (fixed in 80.0.3987.162-1) forky: resolved (fixed in 80.0.3987.162-1) sid: resolved (fixed in 80.0.3987.162-1) trixie: resolved (fixed
debian
CVE-2019-13729P3HIGHCVSS 8.8fixed in chromium 79.0.3945.79-1 (bookworm)2019
CVE-2019-13729 [HIGH] CVE-2019-13729: chromium - Use-after-free in WebSockets in Google Chrome prior to 79.0.3945.79 allowed a re... Use-after-free in WebSockets in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 79.0.3945.79-1) bullseye: resolved (fixed in 79.0.3945.79-1) forky: resolved (fixed in 79.0.3945.79-1) sid: resolved (fixed in 79.0.3945.79-1) trixie: resolved (fixed
debian
CVE-2019-5760P3HIGHCVSS 8.8fixed in chromium 72.0.3626.81-1 (bookworm)2019
CVE-2019-5760 [HIGH] CVE-2019-5760: chromium - Insufficient checks of pointer validity in WebRTC in Google Chrome prior to 72.0... Insufficient checks of pointer validity in WebRTC in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 72.0.3626.81-1) bullseye: resolved (fixed in 72.0.3626.81-1) forky: resolved (fixed in 72.0.3626.81-1) sid: resolved (fixed in 72.0.3626.81-1) trixi
debian
CVE-2020-6377P3HIGHCVSS 8.8fixed in chromium 79.0.3945.130-1 (bookworm)2020
CVE-2020-6377 [HIGH] CVE-2020-6377: chromium - Use after free in audio in Google Chrome prior to 79.0.3945.117 allowed a remote... Use after free in audio in Google Chrome prior to 79.0.3945.117 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 79.0.3945.130-1) bullseye: resolved (fixed in 79.0.3945.130-1) forky: resolved (fixed in 79.0.3945.130-1) sid: resolved (fixed in 79.0.3945.130-1) trixie: resolved (fixed in
debian
CVE-2020-6451P3HIGHCVSS 8.8fixed in chromium 80.0.3987.162-1 (bookworm)2020
CVE-2020-6451 [HIGH] CVE-2020-6451: chromium - Use after free in WebAudio in Google Chrome prior to 80.0.3987.162 allowed a rem... Use after free in WebAudio in Google Chrome prior to 80.0.3987.162 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 80.0.3987.162-1) bullseye: resolved (fixed in 80.0.3987.162-1) forky: resolved (fixed in 80.0.3987.162-1) sid: resolved (fixed in 80.0.3987.162-1) trixie: resolved (fixed
debian
CVE-2019-5836P3HIGHCVSS 8.8fixed in chromium 75.0.3770.80-1 (bookworm)2019
CVE-2019-5836 [HIGH] CVE-2019-5836: chromium - Heap buffer overflow in ANGLE in Google Chrome prior to 75.0.3770.80 allowed a r... Heap buffer overflow in ANGLE in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 75.0.3770.80-1) bullseye: resolved (fixed in 75.0.3770.80-1) forky: resolved (fixed in 75.0.3770.80-1) sid: resolved (fixed in 75.0.3770.80-1) trixie: resolved (fixed i
debian
CVE-2019-5764P3HIGHCVSS 8.8fixed in chromium 72.0.3626.81-1 (bookworm)2019
CVE-2019-5764 [HIGH] CVE-2019-5764: chromium - Incorrect pointer management in WebRTC in Google Chrome prior to 72.0.3626.81 al... Incorrect pointer management in WebRTC in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 72.0.3626.81-1) bullseye: resolved (fixed in 72.0.3626.81-1) forky: resolved (fixed in 72.0.3626.81-1) sid: resolved (fixed in 72.0.3626.81-1) trixie: resolved
debian
CVE-2019-5807P3HIGHCVSS 8.8fixed in chromium 74.0.3729.108-1 (bookworm)2019
CVE-2019-5807 [HIGH] CVE-2019-5807: chromium - Object lifetime issue in V8 in Google Chrome prior to 74.0.3729.108 allowed a re... Object lifetime issue in V8 in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 74.0.3729.108-1) bullseye: resolved (fixed in 74.0.3729.108-1) forky: resolved (fixed in 74.0.3729.108-1) sid: resolved (fixed in 74.0.3729.108-1) trixie: resolved (fixe
debian
CVE-2018-18347P3HIGHCVSS 8.8fixed in chromium 71.0.3578.80-1 (bookworm)2018
CVE-2018-18347 [HIGH] CVE-2018-18347: chromium - Incorrect handling of failed navigations with invalid URLs in Navigation in Goog... Incorrect handling of failed navigations with invalid URLs in Navigation in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to trick a user into executing javascript in an arbitrary origin via a crafted HTML page. Scope: local bookworm: resolved (fixed in 71.0.3578.80-1) bullseye: resolved (fixed in 71.0.3578.80-1) forky: resolved (fixed in 71.0.3578.
debian
CVE-2019-5828P3HIGHCVSS 8.8fixed in chromium 75.0.3770.80-1 (bookworm)2019
CVE-2019-5828 [HIGH] CVE-2019-5828: chromium - Object lifecycle issue in ServiceWorker in Google Chrome prior to 75.0.3770.80 a... Object lifecycle issue in ServiceWorker in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. Scope: local bookworm: resolved (fixed in 75.0.3770.80-1) bullseye: resolved (fixed in 75.0.3770.80-1) forky: resolved (fixed in 75.0.3770.80-1) sid: resolved (fixed in 75.0.3770.80-1) tri
debian
CVE-2020-15975P3HIGHCVSS 8.8fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-15975 [HIGH] CVE-2020-15975: chromium - Integer overflow in SwiftShader in Google Chrome prior to 86.0.4240.75 allowed a... Integer overflow in SwiftShader in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 87.0.4280.88-0.1) bullseye: resolved (fixed in 87.0.4280.88-0.1) forky: resolved (fixed in 87.0.4280.88-0.1) sid: resolved (fixed in 87.0.4280.88-0.1) trixie: resol
debian
CVE-2019-5813P3HIGHCVSS 8.8fixed in chromium 74.0.3729.108-1 (bookworm)2019
CVE-2019-5813 [HIGH] CVE-2019-5813: chromium - Use after free in V8 in Google Chrome prior to 74.0.3729.108 allowed a remote at... Use after free in V8 in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 74.0.3729.108-1) bullseye: resolved (fixed in 74.0.3729.108-1) forky: resolved (fixed in 74.0.3729.108-1) sid: resolved (fixed in 74.0.3729.108-1) trixie: resolved (fixed in 74
debian
CVE-2019-13732P3HIGHCVSS 8.8fixed in chromium 79.0.3945.79-1 (bookworm)2019
CVE-2019-13732 [HIGH] CVE-2019-13732: chromium - Use-after-free in WebAudio in Google Chrome prior to 79.0.3945.79 allowed a remo... Use-after-free in WebAudio in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 79.0.3945.79-1) bullseye: resolved (fixed in 79.0.3945.79-1) forky: resolved (fixed in 79.0.3945.79-1) sid: resolved (fixed in 79.0.3945.79-1) trixie: resolved (fixed in
debian
CVE-2019-13747P3HIGHCVSS 8.8fixed in chromium 79.0.3945.79-1 (bookworm)2019
CVE-2019-13747 [HIGH] CVE-2019-13747: chromium - Uninitialized data in rendering in Google Chrome on Android prior to 79.0.3945.7... Uninitialized data in rendering in Google Chrome on Android prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 79.0.3945.79-1) bullseye: resolved (fixed in 79.0.3945.79-1) forky: resolved (fixed in 79.0.3945.79-1) sid: resolved (fixed in 79.0.3945.79-1) trixie: re
debian
CVE-2019-5829P3HIGHCVSS 8.8fixed in chromium 75.0.3770.80-1 (bookworm)2019
CVE-2019-5829 [HIGH] CVE-2019-5829: chromium - Integer overflow in download manager in Google Chrome prior to 75.0.3770.80 allo... Integer overflow in download manager in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. Scope: local bookworm: resolved (fixed in 75.0.3770.80-1) bullseye: resolved (fixed in 75.0.3770.80-1) forky: resolved (fixed in 75.0.3770.80-1) sid: resolved (fixed in 75.0.3770.80-1) trixie
debian
CVE-2021-30576P3HIGHCVSS 8.8fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30576 [HIGH] CVE-2021-30576: chromium - Use after free in DevTools in Google Chrome prior to 92.0.4515.107 allowed an at... Use after free in DevTools in Google Chrome prior to 92.0.4515.107 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 93.0.4577.82-1) bullseye: resolved (fixed in 93.0.4577.82-1) forky: resolved (fixed in 93.0.4577.82-1) sid: resolved (fi
debian
CVE-2021-30581P3HIGHCVSS 8.8fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30581 [HIGH] CVE-2021-30581: chromium - Use after free in DevTools in Google Chrome prior to 92.0.4515.107 allowed an at... Use after free in DevTools in Google Chrome prior to 92.0.4515.107 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 93.0.4577.82-1) bullseye: resolved (fixed in 93.0.4577.82-1) forky: resolved (fixed in 93.0.4577.82-1) sid: resolved (fi
debian
CVE-2019-5795P3HIGHCVSS 8.8fixed in chromium 73.0.3683.75-1 (bookworm)2019
CVE-2019-5795 [HIGH] CVE-2019-5795: chromium - Integer overflow in PDFium in Google Chrome prior to 73.0.3683.75 allowed a remo... Integer overflow in PDFium in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially perform out of bounds memory access via a crafted PDF file. Scope: local bookworm: resolved (fixed in 73.0.3683.75-1) bullseye: resolved (fixed in 73.0.3683.75-1) forky: resolved (fixed in 73.0.3683.75-1) sid: resolved (fixed in 73.0.3683.75-1) trixie: resolved
debian
CVE-2019-5792P3HIGHCVSS 8.8fixed in chromium 73.0.3683.75-1 (bookworm)2019
CVE-2019-5792 [HIGH] CVE-2019-5792: chromium - Integer overflow in PDFium in Google Chrome prior to 73.0.3683.75 allowed a remo... Integer overflow in PDFium in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially perform out of bounds memory access via a crafted PDF file. Scope: local bookworm: resolved (fixed in 73.0.3683.75-1) bullseye: resolved (fixed in 73.0.3683.75-1) forky: resolved (fixed in 73.0.3683.75-1) sid: resolved (fixed in 73.0.3683.75-1) trixie: resolved
debian
Debian Chromium vulnerabilities | cvebase