Debian Chromium vulnerabilities
2,134 known vulnerabilities affecting debian/chromium.
Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8
Vulnerabilities
Page 62 of 107
CVE-2019-13727P3HIGHCVSS 8.8fixed in chromium 79.0.3945.79-1 (bookworm)2019
CVE-2019-13727 [HIGH] CVE-2019-13727: chromium - Insufficient policy enforcement in WebSockets in Google Chrome prior to 79.0.394...
Insufficient policy enforcement in WebSockets in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to bypass same origin policy via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 79.0.3945.79-1)
bullseye: resolved (fixed in 79.0.3945.79-1)
forky: resolved (fixed in 79.0.3945.79-1)
sid: resolved (fixed in 79.0.3945.79-1)
trixie: resolved
debian
CVE-2018-18339P3HIGHCVSS 8.8fixed in chromium 71.0.3578.80-1 (bookworm)2018
CVE-2018-18339 [HIGH] CVE-2018-18339: chromium - Incorrect object lifecycle in WebAudio in Google Chrome prior to 71.0.3578.80 al...
Incorrect object lifecycle in WebAudio in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 71.0.3578.80-1)
bullseye: resolved (fixed in 71.0.3578.80-1)
forky: resolved (fixed in 71.0.3578.80-1)
sid: resolved (fixed in 71.0.3578.80-1)
trixie: resolv
debian
CVE-2018-18338P3HIGHCVSS 8.8fixed in chromium 71.0.3578.80-1 (bookworm)2018
CVE-2018-18338 [HIGH] CVE-2018-18338: chromium - Incorrect, thread-unsafe use of SkImage in Canvas in Google Chrome prior to 71.0...
Incorrect, thread-unsafe use of SkImage in Canvas in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 71.0.3578.80-1)
bullseye: resolved (fixed in 71.0.3578.80-1)
forky: resolved (fixed in 71.0.3578.80-1)
sid: resolved (fixed in 71.0.3578.80-1)
tri
debian
CVE-2018-18354P3HIGHCVSS 8.8fixed in chromium 71.0.3578.80-1 (bookworm)2018
CVE-2018-18354 [HIGH] CVE-2018-18354: chromium - Insufficient validate of external protocols in Shell Integration in Google Chrom...
Insufficient validate of external protocols in Shell Integration in Google Chrome on Windows prior to 71.0.3578.80 allowed a remote attacker to launch external programs via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 71.0.3578.80-1)
bullseye: resolved (fixed in 71.0.3578.80-1)
forky: resolved (fixed in 71.0.3578.80-1)
sid: resolved (fixed in 71.0
debian
CVE-2020-6454P3HIGHCVSS 8.8fixed in chromium 81.0.4044.92-1 (bookworm)2020
CVE-2020-6454 [HIGH] CVE-2020-6454: chromium - Use after free in extensions in Google Chrome prior to 81.0.4044.92 allowed an a...
Use after free in extensions in Google Chrome prior to 81.0.4044.92 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension.
Scope: local
bookworm: resolved (fixed in 81.0.4044.92-1)
bullseye: resolved (fixed in 81.0.4044.92-1)
forky: resolved (fixed in 81.0.4044.92-1)
sid: resolv
debian
CVE-2018-18340P3HIGHCVSS 8.8fixed in chromium 71.0.3578.80-1 (bookworm)2018
CVE-2018-18340 [HIGH] CVE-2018-18340: chromium - Incorrect object lifecycle in MediaRecorder in Google Chrome prior to 71.0.3578....
Incorrect object lifecycle in MediaRecorder in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 71.0.3578.80-1)
bullseye: resolved (fixed in 71.0.3578.80-1)
forky: resolved (fixed in 71.0.3578.80-1)
sid: resolved (fixed in 71.0.3578.80-1)
trixie: r
debian
CVE-2018-18343P3HIGHCVSS 8.8fixed in chromium 71.0.3578.80-1 (bookworm)2018
CVE-2018-18343 [HIGH] CVE-2018-18343: chromium - Incorrect handing of paths leading to a use after free in Skia in Google Chrome ...
Incorrect handing of paths leading to a use after free in Skia in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 71.0.3578.80-1)
bullseye: resolved (fixed in 71.0.3578.80-1)
forky: resolved (fixed in 71.0.3578.80-1)
sid: resolved (fixed in 71.0.3
debian
CVE-2019-5824P3HIGHCVSS 8.8fixed in chromium 75.0.3770.80-1 (bookworm)2019
CVE-2019-5824 [HIGH] CVE-2019-5824: chromium - Parameter passing error in media in Google Chrome prior to 74.0.3729.131 allowed...
Parameter passing error in media in Google Chrome prior to 74.0.3729.131 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 75.0.3770.80-1)
bullseye: resolved (fixed in 75.0.3770.80-1)
forky: resolved (fixed in 75.0.3770.80-1)
sid: resolved (fixed in 75.0.3770.80-1)
trixie: resolved (fix
debian
CVE-2020-6420P3HIGHCVSS 8.8fixed in chromium 80.0.3987.132-1 (bookworm)2020
CVE-2020-6420 [HIGH] CVE-2020-6420: chromium - Insufficient policy enforcement in media in Google Chrome prior to 80.0.3987.132...
Insufficient policy enforcement in media in Google Chrome prior to 80.0.3987.132 allowed a remote attacker to bypass same origin policy via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 80.0.3987.132-1)
bullseye: resolved (fixed in 80.0.3987.132-1)
forky: resolved (fixed in 80.0.3987.132-1)
sid: resolved (fixed in 80.0.3987.132-1)
trixie: resolved (f
debian
CVE-2020-6379P3HIGHCVSS 8.8fixed in chromium 79.0.3945.130-1 (bookworm)2020
CVE-2020-6379 [HIGH] CVE-2020-6379: chromium - Use after free in V8 in Google Chrome prior to 79.0.3945.130 allowed a remote at...
Use after free in V8 in Google Chrome prior to 79.0.3945.130 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 79.0.3945.130-1)
bullseye: resolved (fixed in 79.0.3945.130-1)
forky: resolved (fixed in 79.0.3945.130-1)
sid: resolved (fixed in 79.0.3945.130-1)
trixie: resolved (fixed in 79
debian
CVE-2021-30507P3HIGHCVSS 8.8fixed in chromium 90.0.4430.212-1 (bookworm)2021
CVE-2021-30507 [HIGH] CVE-2021-30507: chromium - Inappropriate implementation in Offline in Google Chrome on Android prior to 90....
Inappropriate implementation in Offline in Google Chrome on Android prior to 90.0.4430.212 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 90.0.4430.212-1)
bullseye: resolved (fixed in 90.0.4430.212-1)
forky: resolved (fixed in 90.0.4430.212-1)
sid: resolv
debian
CVE-2022-0608P3HIGHCVSS 8.8fixed in chromium 98.0.4758.102-1 (bookworm)2022
CVE-2022-0608 [HIGH] CVE-2022-0608: chromium - Integer overflow in Mojo in Google Chrome prior to 98.0.4758.102 allowed a remot...
Integer overflow in Mojo in Google Chrome prior to 98.0.4758.102 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 98.0.4758.102-1)
bullseye: resolved (fixed in 98.0.4758.102-1~deb11u1)
forky: resolved (fixed in 98.0.4758.102-1)
sid: resolved (fixed in 98.0.4758.102-1)
trixie: resolved
debian
CVE-2019-13699P3HIGHCVSS 8.8fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-13699 [HIGH] CVE-2019-13699: chromium - Use after free in media in Google Chrome prior to 78.0.3904.70 allowed a remote ...
Use after free in media in Google Chrome prior to 78.0.3904.70 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 78.0.3904.87-1)
bullseye: resolved (fixed in 78.0.3904.87-1)
forky: resolved (fixed in 78.0.3904.87-1)
sid: resolved (fixed in 78.0
debian
CVE-2021-30529P3HIGHCVSS 8.8fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30529 [HIGH] CVE-2021-30529: chromium - Use after free in Bookmarks in Google Chrome prior to 91.0.4472.77 allowed an at...
Use after free in Bookmarks in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 93.0.4577.82-1)
bullseye: resolved (fixed in 93.0.4577.82-1)
forky: resolved (fixed in 93.0.4577.82-1)
sid: resolved (fi
debian
CVE-2021-30526P3HIGHCVSS 8.8fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30526 [HIGH] CVE-2021-30526: chromium - Out of bounds write in TabStrip in Google Chrome prior to 91.0.4472.77 allowed a...
Out of bounds write in TabStrip in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory write via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 93.0.4577.82-1)
bullseye: resolved (fixed in 93.0.4577.82-1)
forky: resolved (fixed in 93.0.4577.82-1)
sid: resolv
debian
CVE-2021-30552P3HIGHCVSS 8.8fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30552 [HIGH] CVE-2021-30552: chromium - Use after free in Extensions in Google Chrome prior to 91.0.4472.101 allowed an ...
Use after free in Extensions in Google Chrome prior to 91.0.4472.101 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 93.0.4577.82-1)
bullseye: resolved (fixed in 93.0.4577.82-1)
forky: resolved (fixed in 93.0.4577.82-1)
sid: resolved (
debian
CVE-2021-30524P3HIGHCVSS 8.8fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30524 [HIGH] CVE-2021-30524: chromium - Use after free in TabStrip in Google Chrome prior to 91.0.4472.77 allowed an att...
Use after free in TabStrip in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 93.0.4577.82-1)
bullseye: resolved (fixed in 93.0.4577.82-1)
forky: resolved (fixed in 93.0.4577.82-1)
sid: resolved (fix
debian
CVE-2021-30527P3HIGHCVSS 8.8fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30527 [HIGH] CVE-2021-30527: chromium - Use after free in WebUI in Google Chrome prior to 91.0.4472.77 allowed an attack...
Use after free in WebUI in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 93.0.4577.82-1)
bullseye: resolved (fixed in 93.0.4577.82-1)
forky: resolved (fixed in 93.0.4577.82-1)
sid: resolved (fixed
debian
CVE-2021-4052P3HIGHCVSS 8.8fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-4052 [HIGH] CVE-2021-4052: chromium - Use after free in web apps in Google Chrome prior to 96.0.4664.93 allowed an att...
Use after free in web apps in Google Chrome prior to 96.0.4664.93 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension.
Scope: local
bookworm: resolved (fixed in 97.0.4692.71-0.1)
bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1)
forky: resolved (fixed in 97.0.4692.71-0.1)
debian
CVE-2020-16029P3HIGHCVSS 8.8fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-16029 [HIGH] CVE-2020-16029: chromium - Inappropriate implementation in PDFium in Google Chrome prior to 87.0.4280.66 al...
Inappropriate implementation in PDFium in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to bypass navigation restrictions via a crafted PDF file.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (fixed in 87.0.4280.88-0.1)
trixie: reso
debian