Debian Chromium vulnerabilities
2,134 known vulnerabilities affecting debian/chromium.
Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8
Vulnerabilities
Page 60 of 107
CVE-2022-0308P3HIGHCVSS 8.8fixed in chromium 97.0.4692.99-1 (bookworm)2022
CVE-2022-0308 [HIGH] CVE-2022-0308: chromium - Use after free in Data Transfer in Google Chrome on Chrome OS prior to 97.0.4692...
Use after free in Data Transfer in Google Chrome on Chrome OS prior to 97.0.4692.99 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 97.0.4692.99-1)
bullseye: resolved (fixed in 97.0.4692.99-1~deb11u2)
forky: resolved (fixed i
debian
CVE-2022-0296P3HIGHCVSS 8.8fixed in chromium 97.0.4692.99-1 (bookworm)2022
CVE-2022-0296 [HIGH] CVE-2022-0296: chromium - Use after free in Printing in Google Chrome prior to 97.0.4692.99 allowed a remo...
Use after free in Printing in Google Chrome prior to 97.0.4692.99 allowed a remote attacker who convinced the user to engage is specific user interactions to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 97.0.4692.99-1)
bullseye: resolved (fixed in 97.0.4692.99-1~deb11u2)
forky: resolved (fixed in 97.0.4692.99-
debian
CVE-2022-0304P3HIGHCVSS 8.8fixed in chromium 97.0.4692.99-1 (bookworm)2022
CVE-2022-0304 [HIGH] CVE-2022-0304: chromium - Use after free in Bookmarks in Google Chrome prior to 97.0.4692.99 allowed a rem...
Use after free in Bookmarks in Google Chrome prior to 97.0.4692.99 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 97.0.4692.99-1)
bullseye: resolved (fixed in 97.0.4692.99-1~deb11u2)
forky: resolved (fixed in 97.0.4692.99-1
debian
CVE-2022-0295P3HIGHCVSS 8.8fixed in chromium 97.0.4692.99-1 (bookworm)2022
CVE-2022-0295 [HIGH] CVE-2022-0295: chromium - Use after free in Omnibox in Google Chrome prior to 97.0.4692.99 allowed a remot...
Use after free in Omnibox in Google Chrome prior to 97.0.4692.99 allowed a remote attacker who convinced the user to engage is specific user interactions to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 97.0.4692.99-1)
bullseye: resolved (fixed in 97.0.4692.99-1~deb11u2)
forky: resolved (fixed in 97.0.4692.99-1
debian
CVE-2022-0300P3HIGHCVSS 8.8fixed in chromium 97.0.4692.99-1 (bookworm)2022
CVE-2022-0300 [HIGH] CVE-2022-0300: chromium - Use after free in Text Input Method Editor in Google Chrome on Android prior to ...
Use after free in Text Input Method Editor in Google Chrome on Android prior to 97.0.4692.99 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 97.0.4692.99-1)
bullseye: resolved (fixed in 97.0.4692.99-1~deb11u2)
forky: resolve
debian
CVE-2022-0460P3HIGHCVSS 8.8fixed in chromium 98.0.4758.80-1 (bookworm)2022
CVE-2022-0460 [HIGH] CVE-2022-0460: chromium - Use after free in Window Dialogue in Google Chrome prior to 98.0.4758.80 allowed...
Use after free in Window Dialogue in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 98.0.4758.80-1)
bullseye: resolved (fixed in 98.0.4758.80-1~deb11u1)
forky: resolved (fixed in 98.0.4758.80-1)
sid: resolved (fixed in 98.0.4758.80-1)
trixie: resol
debian
CVE-2022-0465P3HIGHCVSS 8.8fixed in chromium 98.0.4758.80-1 (bookworm)2022
CVE-2022-0465 [HIGH] CVE-2022-0465: chromium - Use after free in Extensions in Google Chrome prior to 98.0.4758.80 allowed a re...
Use after free in Extensions in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to potentially exploit heap corruption via user interaction.
Scope: local
bookworm: resolved (fixed in 98.0.4758.80-1)
bullseye: resolved (fixed in 98.0.4758.80-1~deb11u1)
forky: resolved (fixed in 98.0.4758.80-1)
sid: resolved (fixed in 98.0.4758.80-1)
trixie: resolved (fix
debian
CVE-2022-0469P3HIGHCVSS 8.8fixed in chromium 98.0.4758.80-1 (bookworm)2022
CVE-2022-0469 [HIGH] CVE-2022-0469: chromium - Use after free in Cast in Google Chrome prior to 98.0.4758.80 allowed a remote a...
Use after free in Cast in Google Chrome prior to 98.0.4758.80 allowed a remote attacker who convinced a user to engage in specific interactions to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 98.0.4758.80-1)
bullseye: resolved (fixed in 98.0.4758.80-1~deb11u1)
forky: resolved (fixed in 98.0.4758.80-1)
sid: res
debian
CVE-2022-0468P3HIGHCVSS 8.8fixed in chromium 98.0.4758.80-1 (bookworm)2022
CVE-2022-0468 [HIGH] CVE-2022-0468: chromium - Use after free in Payments in Google Chrome prior to 98.0.4758.80 allowed a remo...
Use after free in Payments in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 98.0.4758.80-1)
bullseye: resolved (fixed in 98.0.4758.80-1~deb11u1)
forky: resolved (fixed in 98.0.4758.80-1)
sid: resolved (fixed in 98.0.4758.80-1)
trixie: resolved (fi
debian
CVE-2022-1144P3HIGHCVSS 8.8fixed in chromium 100.0.4896.60-1 (bookworm)2022
CVE-2022-1144 [HIGH] CVE-2022-1144: chromium - Use after free in WebUI in Google Chrome prior to 100.0.4896.60 allowed a remote...
Use after free in WebUI in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via specific input into DevTools.
Scope: local
bookworm: resolved (fixed in 100.0.4896.60-1)
bullseye: resolved (fixed in 100.0.4896.60-1~deb11u1)
forky: resolved (fixed in 100.0.4
debian
CVE-2022-0463P3HIGHCVSS 8.8fixed in chromium 98.0.4758.80-1 (bookworm)2022
CVE-2022-0463 [HIGH] CVE-2022-0463: chromium - Use after free in Accessibility in Google Chrome prior to 98.0.4758.80 allowed a...
Use after free in Accessibility in Google Chrome prior to 98.0.4758.80 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via user interaction.
Scope: local
bookworm: resolved (fixed in 98.0.4758.80-1)
bullseye: resolved (fixed in 98.0.4758.80-1~deb11u1)
forky: resolved (fixed in 98.0.4758.80-1
debian
CVE-2023-2726P3HIGHCVSS 8.8fixed in chromium 113.0.5672.126-1 (bookworm)2023
CVE-2023-2726 [HIGH] CVE-2023-2726: chromium - Inappropriate implementation in WebApp Installs in Google Chrome prior to 113.0....
Inappropriate implementation in WebApp Installs in Google Chrome prior to 113.0.5672.126 allowed an attacker who convinced a user to install a malicious web app to bypass install dialog via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 113.0.5672.126-1)
bullseye: resolved (fixed in 113.0.5672.126-1~deb11u1)
forky:
debian
CVE-2023-0698P3HIGHCVSS 8.8fixed in chromium 110.0.5481.77-1 (bookworm)2023
CVE-2023-0698 [HIGH] CVE-2023-0698: chromium - Out of bounds read in WebRTC in Google Chrome prior to 110.0.5481.77 allowed a r...
Out of bounds read in WebRTC in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 110.0.5481.77-1)
bullseye: resolved (fixed in 110.0.5481.77-1~deb11u1)
forky: resolved (fixed in 110.0.5481.77-1)
sid: resolved (fix
debian
CVE-2022-1136P3HIGHCVSS 8.8fixed in chromium 100.0.4896.60-1 (bookworm)2022
CVE-2022-1136 [HIGH] CVE-2022-1136: chromium - Use after free in Tab Strip in Google Chrome prior to 100.0.4896.60 allowed an a...
Use after free in Tab Strip in Google Chrome prior to 100.0.4896.60 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via specific set of user gestures.
Scope: local
bookworm: resolved (fixed in 100.0.4896.60-1)
bullseye: resolved (fixed in 100.0.4896.60-1~deb11u1)
forky: resolved (fixed in 100.0.4896.60-
debian
CVE-2021-38015P3HIGHCVSS 8.8fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-38015 [HIGH] CVE-2021-38015: chromium - Inappropriate implementation in input in Google Chrome prior to 96.0.4664.45 all...
Inappropriate implementation in input in Google Chrome prior to 96.0.4664.45 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension.
Scope: local
bookworm: resolved (fixed in 97.0.4692.71-0.1)
bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1)
forky: resolved (fixed in 97.0.4692
debian
CVE-2022-0605P3HIGHCVSS 8.8fixed in chromium 98.0.4758.102-1 (bookworm)2022
CVE-2022-0605 [HIGH] CVE-2022-0605: chromium - Use after free in Webstore API in Google Chrome prior to 98.0.4758.102 allowed a...
Use after free in Webstore API in Google Chrome prior to 98.0.4758.102 allowed an attacker who convinced a user to install a malicious extension and convinced a user to enage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 98.0.4758.102-1)
bullseye: resolved (fixed in 98.0.4758.102
debian
CVE-2022-4191P3HIGHCVSS 8.8fixed in chromium 108.0.5359.71-1 (bookworm)2022
CVE-2022-4191 [HIGH] CVE-2022-4191: chromium - Use after free in Sign-In in Google Chrome prior to 108.0.5359.71 allowed a remo...
Use after free in Sign-In in Google Chrome prior to 108.0.5359.71 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via profile destruction. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 108.0.5359.71-1)
bullseye: resolved (fixed in 108.0.5359.71-2~deb11u1)
forky
debian
CVE-2022-2621P3HIGHCVSS 8.8fixed in chromium 104.0.5112.79-1 (bookworm)2022
CVE-2022-2621 [HIGH] CVE-2022-2621: chromium - Use after free in Extensions in Google Chrome prior to 104.0.5112.79 allowed an ...
Use after free in Extensions in Google Chrome prior to 104.0.5112.79 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via specific UI interactions.
Scope: local
bookworm: resolved (fixed in 104.0.5112.79-1)
bullseye: resolved (fixed in 104.0.5112.79-1~deb11u1)
forky: resolved (fixed in 104.0.5112.79-1)
s
debian
CVE-2022-0302P3HIGHCVSS 8.8fixed in chromium 97.0.4692.99-1 (bookworm)2022
CVE-2022-0302 [HIGH] CVE-2022-0302: chromium - Use after free in Omnibox in Google Chrome prior to 97.0.4692.99 allowed an atta...
Use after free in Omnibox in Google Chrome prior to 97.0.4692.99 allowed an attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 97.0.4692.99-1)
bullseye: resolved (fixed in 97.0.4692.99-1~deb11u2)
forky: resolved (fixed in 97.0.4692.99-1)
sid: r
debian
CVE-2022-4177P3HIGHCVSS 8.8fixed in chromium 108.0.5359.71-1 (bookworm)2022
CVE-2022-4177 [HIGH] CVE-2022-4177: chromium - Use after free in Extensions in Google Chrome prior to 108.0.5359.71 allowed an ...
Use after free in Extensions in Google Chrome prior to 108.0.5359.71 allowed an attacker who convinced a user to install an extension to potentially exploit heap corruption via a crafted Chrome Extension and UI interaction. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 108.0.5359.71-1)
bullseye: resolved (fixed in 108.0.5359.71-2~deb11u
debian