cbcvebase.

Debian Chromium vulnerabilities

2,134 known vulnerabilities affecting debian/chromium.

Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8

Vulnerabilities

Page 59 of 107
CVE-2022-0805P3HIGHCVSS 8.8fixed in chromium 99.0.4844.51-1 (bookworm)2022
CVE-2022-0805 [HIGH] CVE-2022-0805: chromium - Use after free in Browser Switcher in Google Chrome prior to 99.0.4844.51 allowe... Use after free in Browser Switcher in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via user interaction. Scope: local bookworm: resolved (fixed in 99.0.4844.51-1) bullseye: resolved (fixed in 99.0.4844.51-1~deb11u1) forky: resolved (fixed in 99.0.4844.5
debian
CVE-2020-16023P3HIGHCVSS 8.8fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-16023 [HIGH] CVE-2020-16023: chromium - Use after free in WebCodecs in Google Chrome prior to 87.0.4280.66 allowed a rem... Use after free in WebCodecs in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 87.0.4280.88-0.1) bullseye: resolved (fixed in 87.0.4280.88-0.1) forky: resolved (fixed in 87.0.4280.88-0.1) sid: resolved (fixed in 87.0.4280.88-0.1) trixie: resolved
debian
CVE-2022-1874P3HIGHCVSS 8.8fixed in chromium 102.0.5005.61-1 (bookworm)2022
CVE-2022-1874 [HIGH] CVE-2022-1874: chromium - Insufficient policy enforcement in Safe Browsing in Google Chrome on Mac prior t... Insufficient policy enforcement in Safe Browsing in Google Chrome on Mac prior to 102.0.5005.61 allowed a remote attacker to bypass downloads protection policy via a crafted HTML page. Scope: local bookworm: resolved (fixed in 102.0.5005.61-1) bullseye: resolved (fixed in 102.0.5005.61-1~deb11u1) forky: resolved (fixed in 102.0.5005.61-1) sid: resolved (fixed in 102.
debian
CVE-2022-1490P3HIGHCVSS 8.8fixed in chromium 101.0.4951.41-1 (bookworm)2022
CVE-2022-1490 [HIGH] CVE-2022-1490: chromium - Use after free in Browser Switcher in Google Chrome prior to 101.0.4951.41 allow... Use after free in Browser Switcher in Google Chrome prior to 101.0.4951.41 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 101.0.4951.41-1) bullseye: resolved (fixed in 101.0.4951.41-1~deb11u1) forky: resolved (fixed in 101.0
debian
CVE-2022-1125P3HIGHCVSS 8.8fixed in chromium 100.0.4896.60-1 (bookworm)2022
CVE-2022-1125 [HIGH] CVE-2022-1125: chromium - Use after free in Portals in Google Chrome prior to 100.0.4896.60 allowed a remo... Use after free in Portals in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via user interaction. Scope: local bookworm: resolved (fixed in 100.0.4896.60-1) bullseye: resolved (fixed in 100.0.4896.60-1~deb11u1) forky: resolved (fixed in 100.0.4896.60-1)
debian
CVE-2021-37985P3HIGHCVSS 8.8fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-37985 [HIGH] CVE-2021-37985: chromium - Use after free in V8 in Google Chrome prior to 95.0.4638.54 allowed a remote att... Use after free in V8 in Google Chrome prior to 95.0.4638.54 allowed a remote attacker who had convinced a user to allow for connection to debugger to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 97.0.4692.71-0.1) bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1) forky: resolved (fixed in 97.0.4692.71-0.
debian
CVE-2021-37983P3HIGHCVSS 8.8fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-37983 [HIGH] CVE-2021-37983: chromium - Use after free in Dev Tools in Google Chrome prior to 95.0.4638.54 allowed a rem... Use after free in Dev Tools in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 97.0.4692.71-0.1) bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1) forky: resolved (fixed in 97.0.4692.71-0.1) sid: resolved (fixed in 97.0.4692.71-0.1) trixie: r
debian
CVE-2022-1491P3HIGHCVSS 8.8fixed in chromium 101.0.4951.41-1 (bookworm)2022
CVE-2022-1491 [HIGH] CVE-2022-1491: chromium - Use after free in Bookmarks in Google Chrome prior to 101.0.4951.41 allowed a re... Use after free in Bookmarks in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via specific and direct user interaction. Scope: local bookworm: resolved (fixed in 101.0.4951.41-1) bullseye: resolved (fixed in 101.0.4951.41-1~deb11u1) forky: resolved (fixed in 101.0.4951.41-1) sid: resolved (fixed in 101.0.4951.41-
debian
CVE-2020-16019P3HIGHCVSS 8.8fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-16019 [HIGH] CVE-2020-16019: chromium - Inappropriate implementation in filesystem in Google Chrome on ChromeOS prior to... Inappropriate implementation in filesystem in Google Chrome on ChromeOS prior to 87.0.4280.66 allowed a remote attacker who had compromised the browser process to bypass noexec restrictions via a malicious file. Scope: local bookworm: resolved (fixed in 87.0.4280.88-0.1) bullseye: resolved (fixed in 87.0.4280.88-0.1) forky: resolved (fixed in 87.0.4280.88-0.1) sid:
debian
CVE-2022-1493P3HIGHCVSS 8.8fixed in chromium 101.0.4951.41-1 (bookworm)2022
CVE-2022-1493 [HIGH] CVE-2022-1493: chromium - Use after free in Dev Tools in Google Chrome prior to 101.0.4951.41 allowed a re... Use after free in Dev Tools in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via specific and direct user interaction. Scope: local bookworm: resolved (fixed in 101.0.4951.41-1) bullseye: resolved (fixed in 101.0.4951.41-1~deb11u1) forky: resolved (fixed in 101.0.4951.41-1) sid: resolved (fixed in 101.0.4951.41-
debian
CVE-2022-1135P3HIGHCVSS 8.8fixed in chromium 100.0.4896.60-1 (bookworm)2022
CVE-2022-1135 [HIGH] CVE-2022-1135: chromium - Use after free in Shopping Cart in Google Chrome prior to 100.0.4896.60 allowed ... Use after free in Shopping Cart in Google Chrome prior to 100.0.4896.60 allowed a remote attacker to potentially exploit heap corruption via standard feature user interaction. Scope: local bookworm: resolved (fixed in 100.0.4896.60-1) bullseye: resolved (fixed in 100.0.4896.60-1~deb11u1) forky: resolved (fixed in 100.0.4896.60-1) sid: resolved (fixed in 100.0.4896.60
debian
CVE-2022-2477P3HIGHCVSS 8.8fixed in chromium 103.0.5060.134-1 (bookworm)2022
CVE-2022-2477 [HIGH] CVE-2022-2477: chromium - Use after free in Guest View in Google Chrome prior to 103.0.5060.134 allowed an... Use after free in Guest View in Google Chrome prior to 103.0.5060.134 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 103.0.5060.134-1) bullseye: resolved (fixed in 103.0.5060.134-1~deb11u1) forky: resolved (fixed in 103.0.5060.134-1) si
debian
CVE-2021-37988P3HIGHCVSS 8.8fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-37988 [HIGH] CVE-2021-37988: chromium - Use after free in Profiles in Google Chrome prior to 95.0.4638.54 allowed a remo... Use after free in Profiles in Google Chrome prior to 95.0.4638.54 allowed a remote attacker who convinced a user to engage in specific gestures to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 97.0.4692.71-0.1) bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1) forky: resolved (fixed in 97.0.4692.71-0.1)
debian
CVE-2021-37993P3HIGHCVSS 8.8fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-37993 [HIGH] CVE-2021-37993: chromium - Use after free in PDF Accessibility in Google Chrome prior to 95.0.4638.54 allow... Use after free in PDF Accessibility in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 97.0.4692.71-0.1) bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1) forky: resolved (fixed in 97.0.4692.71-0.1) sid: resolved (fixed in 97.0.4692.71-0.1) t
debian
CVE-2021-38011P3HIGHCVSS 8.8fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-38011 [HIGH] CVE-2021-38011: chromium - Use after free in storage foundation in Google Chrome prior to 96.0.4664.45 allo... Use after free in storage foundation in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 97.0.4692.71-0.1) bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1) forky: resolved (fixed in 97.0.4692.71-0.1) sid: resolved (fixed in 97.0.4692.71-0.1)
debian
CVE-2022-0464P3HIGHCVSS 8.8fixed in chromium 98.0.4758.80-1 (bookworm)2022
CVE-2022-0464 [HIGH] CVE-2022-0464: chromium - Use after free in Accessibility in Google Chrome prior to 98.0.4758.80 allowed a... Use after free in Accessibility in Google Chrome prior to 98.0.4758.80 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via user interaction. Scope: local bookworm: resolved (fixed in 98.0.4758.80-1) bullseye: resolved (fixed in 98.0.4758.80-1~deb11u1) forky: resolved (fixed in 98.0.4758.80-1
debian
CVE-2022-2163P3HIGHCVSS 8.8fixed in chromium 103.0.5060.53-1 (bookworm)2022
CVE-2022-2163 [HIGH] CVE-2022-2163: chromium - Use after free in Cast UI and Toolbar in Google Chrome prior to 103.0.5060.134 a... Use after free in Cast UI and Toolbar in Google Chrome prior to 103.0.5060.134 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via UI interaction. Scope: local bookworm: resolved (fixed in 103.0.5060.53-1) bullseye: resolved (fixed in 103.0.5060.134-1~deb11u1) forky: resolved (fixed in 103.0.5060.53-1)
debian
CVE-2022-1634P3HIGHCVSS 8.8fixed in chromium 101.0.4951.64-1 (bookworm)2022
CVE-2022-1634 [HIGH] CVE-2022-1634: chromium - Use after free in Browser UI in Google Chrome prior to 101.0.4951.64 allowed a r... Use after free in Browser UI in Google Chrome prior to 101.0.4951.64 allowed a remote attacker who had convinced a user to engage in specific UI interaction to potentially exploit heap corruption via specific user interactions. Scope: local bookworm: resolved (fixed in 101.0.4951.64-1) bullseye: resolved (fixed in 101.0.4951.64-1~deb11u1) forky: resolved (fixed in 10
debian
CVE-2022-0972P3HIGHCVSS 8.8fixed in chromium 99.0.4844.74-1 (bookworm)2022
CVE-2022-0972 [HIGH] CVE-2022-0972: chromium - Use after free in Extensions in Google Chrome prior to 99.0.4844.74 allowed an a... Use after free in Extensions in Google Chrome prior to 99.0.4844.74 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 99.0.4844.74-1) bullseye: resolved (fixed in 99.0.4844.74-1~deb11u1) forky: resolved (fixed in 99.0.4844.74-1) sid: resol
debian
CVE-2022-0307P3HIGHCVSS 8.8fixed in chromium 97.0.4692.99-1 (bookworm)2022
CVE-2022-0307 [HIGH] CVE-2022-0307: chromium - Use after free in Optimization Guide in Google Chrome prior to 97.0.4692.99 allo... Use after free in Optimization Guide in Google Chrome prior to 97.0.4692.99 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 97.0.4692.99-1) bullseye: resolved (fixed in 97.0.4692.99-1~deb11u2) forky: resolved (fixed in 97.0.4
debian
Debian Chromium vulnerabilities | cvebase