Debian Chromium vulnerabilities

2,176 known vulnerabilities affecting debian/chromium.

Total CVEs
2,176
CISA KEV
65
actively exploited
Public exploits
14
Exploited in wild
56
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW56UNKNOWN8

Vulnerabilities

Page 58 of 109
CVE-2022-3200HIGHCVSS 8.8fixed in chromium 105.0.5195.125-1 (bookworm)2022
CVE-2022-3200 [HIGH] CVE-2022-3200: chromium - Heap buffer overflow in Internals in Google Chrome prior to 105.0.5195.125 allow... Heap buffer overflow in Internals in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 105.0.5195.125-1) bullseye: resolved (fixed in 105.0.5195.125-1~deb11u1) forky: resolved (fixed in 105.0.5195.125-1) sid: resol
debian
CVE-2022-0101HIGHCVSS 8.8fixed in chromium 97.0.4692.71-0.1 (bookworm)2022
CVE-2022-0101 [HIGH] CVE-2022-0101: chromium - Heap buffer overflow in Bookmarks in Google Chrome prior to 97.0.4692.71 allowed... Heap buffer overflow in Bookmarks in Google Chrome prior to 97.0.4692.71 allowed a remote attacker who convinced a user to perform specific user gesture to potentially exploit heap corruption via specific user gesture. Scope: local bookworm: resolved (fixed in 97.0.4692.71-0.1) bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1) forky: resolved (fixed in 97.0.4692
debian
CVE-2022-0463HIGHCVSS 8.8fixed in chromium 98.0.4758.80-1 (bookworm)2022
CVE-2022-0463 [HIGH] CVE-2022-0463: chromium - Use after free in Accessibility in Google Chrome prior to 98.0.4758.80 allowed a... Use after free in Accessibility in Google Chrome prior to 98.0.4758.80 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via user interaction. Scope: local bookworm: resolved (fixed in 98.0.4758.80-1) bullseye: resolved (fixed in 98.0.4758.80-1~deb11u1) forky: resolved (fixed in 98.0.4758.80-1
debian
CVE-2022-1859HIGHCVSS 8.8fixed in chromium 102.0.5005.61-1 (bookworm)2022
CVE-2022-1859 [HIGH] CVE-2022-1859: chromium - Use after free in Performance Manager in Google Chrome prior to 102.0.5005.61 al... Use after free in Performance Manager in Google Chrome prior to 102.0.5005.61 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 102.0.5005.61-1) bullseye: resolved (fixed in 102.0.5005.61-1~deb11u1) forky: resolved (fixed in 10
debian
CVE-2022-4192HIGHCVSS 8.8fixed in chromium 108.0.5359.71-1 (bookworm)2022
CVE-2022-4192 [HIGH] CVE-2022-4192: chromium - Use after free in Live Caption in Google Chrome prior to 108.0.5359.71 allowed a... Use after free in Live Caption in Google Chrome prior to 108.0.5359.71 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via UI interaction. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 108.0.5359.71-1) bullseye: resolved (fixed in 108.0.5359.71-2~deb11u1) forky
debian
CVE-2022-1640HIGHCVSS 8.8fixed in chromium 101.0.4951.64-1 (bookworm)2022
CVE-2022-1640 [HIGH] CVE-2022-1640: chromium - Use after free in Sharing in Google Chrome prior to 101.0.4951.64 allowed a remo... Use after free in Sharing in Google Chrome prior to 101.0.4951.64 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 101.0.4951.64-1) bullseye: resolved (fixed in 101.0.4951.64-1~deb11u1) forky: resolved (fixed in 101.0.4951.64-1
debian
CVE-2022-4440HIGHCVSS 8.8fixed in chromium 108.0.5359.124-1 (bookworm)2022
CVE-2022-4440 [HIGH] CVE-2022-4440: chromium - Use after free in Profiles in Google Chrome prior to 108.0.5359.124 allowed a re... Use after free in Profiles in Google Chrome prior to 108.0.5359.124 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 108.0.5359.124-1) bullseye: resolved (fixed in 108.0.5359.124-1~deb11u1) forky: resolved (fixed in 108.0.5359.124-1) sid: resolved (
debian
CVE-2022-4174HIGHCVSS 8.8fixed in chromium 108.0.5359.71-1 (bookworm)2022
CVE-2022-4174 [HIGH] CVE-2022-4174: chromium - Type confusion in V8 in Google Chrome prior to 108.0.5359.71 allowed a remote at... Type confusion in V8 in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 108.0.5359.71-1) bullseye: resolved (fixed in 108.0.5359.71-2~deb11u1) forky: resolved (fixed in 108.0.5359.71-1) sid: resolved (fixed in 108
debian
CVE-2022-3197HIGHCVSS 8.8fixed in chromium 105.0.5195.125-1 (bookworm)2022
CVE-2022-3197 [HIGH] CVE-2022-3197: chromium - Use after free in PDF in Google Chrome prior to 105.0.5195.125 allowed a remote ... Use after free in PDF in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 105.0.5195.125-1) bullseye: resolved (fixed in 105.0.5195.125-1~deb11u1) forky: resolved (fixed in 105.0.5195.125-1) sid: resolved (fixed in
debian
CVE-2022-2415HIGHCVSS 8.8fixed in chromium 103.0.5060.53-1 (bookworm)2022
CVE-2022-2415 [HIGH] CVE-2022-2415: chromium - Heap buffer overflow in WebGL in Google Chrome prior to 103.0.5060.53 allowed a ... Heap buffer overflow in WebGL in Google Chrome prior to 103.0.5060.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 103.0.5060.53-1) bullseye: resolved (fixed in 103.0.5060.53-1~deb11u1) forky: resolved (fixed in 103.0.5060.53-1) sid: resolved (fixed in 103.0.5060.53-1) trixie: reso
debian
CVE-2022-3652HIGHCVSS 8.8fixed in chromium 107.0.5304.68-1 (bookworm)2022
CVE-2022-3652 [HIGH] CVE-2022-3652: chromium - Type confusion in V8 in Google Chrome prior to 107.0.5304.62 allowed a remote at... Type confusion in V8 in Google Chrome prior to 107.0.5304.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 107.0.5304.68-1) bullseye: resolved (fixed in 107.0.5304.68-1~deb11u1) forky: resolved (fixed in 107.0.5304.68-1) sid: resolved (fixed in 107
debian
CVE-2022-0105HIGHCVSS 8.8fixed in chromium 97.0.4692.71-0.1 (bookworm)2022
CVE-2022-0105 [HIGH] CVE-2022-0105: chromium - Use after free in PDF Accessibility in Google Chrome prior to 97.0.4692.71 allow... Use after free in PDF Accessibility in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 97.0.4692.71-0.1) bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1) forky: resolved (fixed in 97.0.4692.71-0.1) sid: resolved (fixed in 97.0.4692.71-0.1) tri
debian
CVE-2022-1858MEDIUMCVSS 6.5fixed in chromium 102.0.5005.61-1 (bookworm)2022
CVE-2022-1858 [MEDIUM] CVE-2022-1858: chromium - Out of bounds read in DevTools in Google Chrome prior to 102.0.5005.61 allowed a... Out of bounds read in DevTools in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to perform an out of bounds memory read via specific user interaction. Scope: local bookworm: resolved (fixed in 102.0.5005.61-1) bullseye: resolved (fixed in 102.0.5005.61-1~deb11u1) forky: resolved (fixed in 102.0.5005.61-1) sid: resolved (fixed in 102.0.5005.61-1) tr
debian
CVE-2022-0109MEDIUMCVSS 6.5fixed in chromium 97.0.4692.71-0.1 (bookworm)2022
CVE-2022-0109 [MEDIUM] CVE-2022-0109: chromium - Inappropriate implementation in Autofill in Google Chrome prior to 97.0.4692.71 ... Inappropriate implementation in Autofill in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to obtain potentially sensitive information via a crafted HTML page. Scope: local bookworm: resolved (fixed in 97.0.4692.71-0.1) bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1) forky: resolved (fixed in 97.0.4692.71-0.1) sid: resolved (fixed in 97.0.4692
debian
CVE-2022-4955MEDIUMCVSS 6.5fixed in chromium 108.0.5359.71-1 (bookworm)2022
CVE-2022-4955 [MEDIUM] CVE-2022-4955: chromium - Inappropriate implementation in DevTools in Google Chrome prior to 108.0.5359.71... Inappropriate implementation in DevTools in Google Chrome prior to 108.0.5359.71 allowed an attacker who convinced a user to install a malicious extension to bypass file access restrictions via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 108.0.5359.71-1) bullseye: resolved (fixed in 108.0.5359.71-2~deb11u1) fo
debian
CVE-2022-3443MEDIUMCVSS 4.3fixed in chromium 106.0.5249.61-1 (bookworm)2022
CVE-2022-3443 [MEDIUM] CVE-2022-3443: chromium - Insufficient data validation in File System API in Google Chrome prior to 106.0.... Insufficient data validation in File System API in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to bypass File System restrictions via a crafted HTML page. (Chromium security severity: Low) Scope: local bookworm: resolved (fixed in 106.0.5249.61-1) bullseye: resolved (fixed in 106.0.5249.61-1~deb11u1) forky: resolved (fixed in 106.0.5249.61-1) sid
debian
CVE-2022-1873MEDIUMCVSS 6.5fixed in chromium 102.0.5005.61-1 (bookworm)2022
CVE-2022-1873 [MEDIUM] CVE-2022-1873: chromium - Insufficient policy enforcement in COOP in Google Chrome prior to 102.0.5005.61 ... Insufficient policy enforcement in COOP in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to leak cross-origin data via a crafted HTML page. Scope: local bookworm: resolved (fixed in 102.0.5005.61-1) bullseye: resolved (fixed in 102.0.5005.61-1~deb11u1) forky: resolved (fixed in 102.0.5005.61-1) sid: resolved (fixed in 102.0.5005.61-1) trixie: resol
debian
CVE-2022-1138MEDIUMCVSS 6.5fixed in chromium 100.0.4896.60-1 (bookworm)2022
CVE-2022-1138 [MEDIUM] CVE-2022-1138: chromium - Inappropriate implementation in Web Cursor in Google Chrome prior to 100.0.4896.... Inappropriate implementation in Web Cursor in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who had compromised the renderer process to obscure the contents of the Omnibox (URL bar) via a crafted HTML page. Scope: local bookworm: resolved (fixed in 100.0.4896.60-1) bullseye: resolved (fixed in 100.0.4896.60-1~deb11u1) forky: resolved (fixed in 100.
debian
CVE-2022-3313MEDIUMCVSS 6.5fixed in chromium 106.0.5249.61-1 (bookworm)2022
CVE-2022-3313 [MEDIUM] CVE-2022-3313: chromium - Incorrect security UI in full screen in Google Chrome prior to 106.0.5249.62 all... Incorrect security UI in full screen in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 106.0.5249.61-1) bullseye: resolved (fixed in 106.0.5249.61-1~deb11u1) forky: resolved (fixed in 106.0.5249.61-1) sid: resolved (fixed in 1
debian
CVE-2022-1499MEDIUMCVSS 6.3fixed in chromium 101.0.4951.41-1 (bookworm)2022
CVE-2022-1499 [MEDIUM] CVE-2022-1499: chromium - Inappropriate implementation in WebAuthentication in Google Chrome prior to 101.... Inappropriate implementation in WebAuthentication in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to bypass same origin policy via a crafted HTML page. Scope: local bookworm: resolved (fixed in 101.0.4951.41-1) bullseye: resolved (fixed in 101.0.4951.41-1~deb11u1) forky: resolved (fixed in 101.0.4951.41-1) sid: resolved (fixed in 101.0.4951.41-1)
debian