cbcvebase.

Debian Chromium vulnerabilities

2,134 known vulnerabilities affecting debian/chromium.

Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8

Vulnerabilities

Page 63 of 107
CVE-2021-37992P3HIGHCVSS 8.8fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-37992 [HIGH] CVE-2021-37992: chromium - Out of bounds read in WebAudio in Google Chrome prior to 95.0.4638.54 allowed a ... Out of bounds read in WebAudio in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 97.0.4692.71-0.1) bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1) forky: resolved (fixed in 97.0.4692.71-0.1) sid: resolved (fixed in 97.0.4692.71-0.1) trixie
debian
CVE-2021-30525P3HIGHCVSS 8.8fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30525 [HIGH] CVE-2021-30525: chromium - Use after free in TabGroups in Google Chrome prior to 91.0.4472.77 allowed an at... Use after free in TabGroups in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 93.0.4577.82-1) bullseye: resolved (fixed in 93.0.4577.82-1) forky: resolved (fixed in 93.0.4577.82-1) sid: resolved (fi
debian
CVE-2021-30550P3HIGHCVSS 8.8fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30550 [HIGH] CVE-2021-30550: chromium - Use after free in Accessibility in Google Chrome prior to 91.0.4472.101 allowed ... Use after free in Accessibility in Google Chrome prior to 91.0.4472.101 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 93.0.4577.82-1) bullseye: resolved (fixed in 93.0.4577.82-1) forky: resolved (fixed in 93.0.4577.82-1) sid: resolve
debian
CVE-2021-30509P3HIGHCVSS 8.8fixed in chromium 90.0.4430.212-1 (bookworm)2021
CVE-2021-30509 [HIGH] CVE-2021-30509: chromium - Out of bounds write in Tab Strip in Google Chrome prior to 90.0.4430.212 allowed... Out of bounds write in Tab Strip in Google Chrome prior to 90.0.4430.212 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory write via a crafted HTML page and a crafted Chrome extension. Scope: local bookworm: resolved (fixed in 90.0.4430.212-1) bullseye: resolved (fixed in 90.0.4430.212-1) forky: resolved (f
debian
CVE-2020-16022P3HIGHCVSS 8.8fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-16022 [HIGH] CVE-2020-16022: chromium - Insufficient policy enforcement in networking in Google Chrome prior to 87.0.428... Insufficient policy enforcement in networking in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to potentially bypass firewall controls via a crafted HTML page. Scope: local bookworm: resolved (fixed in 87.0.4280.88-0.1) bullseye: resolved (fixed in 87.0.4280.88-0.1) forky: resolved (fixed in 87.0.4280.88-0.1) sid: resolved (fixed in 87.0.4280.88-0.1
debian
CVE-2022-3046P3HIGHCVSS 8.8fixed in chromium 105.0.5195.52-1 (bookworm)2022
CVE-2022-3046 [HIGH] CVE-2022-3046: chromium - Use after free in Browser Tag in Google Chrome prior to 105.0.5195.52 allowed an... Use after free in Browser Tag in Google Chrome prior to 105.0.5195.52 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 105.0.5195.52-1) bullseye: resolved (fixed in 105.0.5195.52-1~deb11u1) forky: resolved (fixed in 105.0.5195.52-1) sid:
debian
CVE-2021-38016P3HIGHCVSS 8.8fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-38016 [HIGH] CVE-2021-38016: chromium - Insufficient policy enforcement in background fetch in Google Chrome prior to 96... Insufficient policy enforcement in background fetch in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to bypass same origin policy via a crafted HTML page. Scope: local bookworm: resolved (fixed in 97.0.4692.71-0.1) bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1) forky: resolved (fixed in 97.0.4692.71-0.1) sid: resolved (fixed in 97.0.4692.71-
debian
CVE-2021-38017P3HIGHCVSS 8.8fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-38017 [HIGH] CVE-2021-38017: chromium - Insufficient policy enforcement in iframe sandbox in Google Chrome prior to 96.0... Insufficient policy enforcement in iframe sandbox in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. Scope: local bookworm: resolved (fixed in 97.0.4692.71-0.1) bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1) forky: resolved (fixed in 97.0.4692.71-0.1) sid: resolved (fixed in 97.0.4692.
debian
CVE-2021-30543P3HIGHCVSS 8.8fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30543 [HIGH] CVE-2021-30543: chromium - Use after free in Tab Strip in Google Chrome prior to 91.0.4472.77 allowed an at... Use after free in Tab Strip in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 93.0.4577.82-1) bullseye: resolved (fixed in 93.0.4577.82-1) forky: resolved (fixed in 93.0.4577.82-1) sid: resolved (fi
debian
CVE-2021-30542P3HIGHCVSS 8.8fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30542 [HIGH] CVE-2021-30542: chromium - Use after free in Tab Strip in Google Chrome prior to 91.0.4472.77 allowed an at... Use after free in Tab Strip in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 93.0.4577.82-1) bullseye: resolved (fixed in 93.0.4577.82-1) forky: resolved (fixed in 93.0.4577.82-1) sid: resolved (fi
debian
CVE-2020-6419P3HIGHCVSS 8.8fixed in chromium 81.0.4044.92-1 (bookworm)2020
CVE-2020-6419 [HIGH] CVE-2020-6419: chromium - Out of bounds write in V8 in Google Chrome prior to 81.0.4044.92 allowed a remot... Out of bounds write in V8 in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 81.0.4044.92-1) bullseye: resolved (fixed in 81.0.4044.92-1) forky: resolved (fixed in 81.0.4044.92-1) sid: resolved (fixed in 81.0.4044.92-1) trixie: resolved (fixed in 81
debian
CVE-2022-0793P3HIGHCVSS 8.8fixed in chromium 99.0.4844.51-1 (bookworm)2022
CVE-2022-0793 [HIGH] CVE-2022-0793: chromium - Use after free in Cast in Google Chrome prior to 99.0.4844.51 allowed an attacke... Use after free in Cast in Google Chrome prior to 99.0.4844.51 allowed an attacker who convinced a user to install a malicious extension and engage in specific user interaction to potentially exploit heap corruption via a crafted Chrome Extension. Scope: local bookworm: resolved (fixed in 99.0.4844.51-1) bullseye: resolved (fixed in 99.0.4844.51-1~deb11u1) forky: reso
debian
CVE-2022-1876P3HIGHCVSS 8.8fixed in chromium 102.0.5005.61-1 (bookworm)2022
CVE-2022-1876 [HIGH] CVE-2022-1876: chromium - Heap buffer overflow in DevTools in Google Chrome prior to 102.0.5005.61 allowed... Heap buffer overflow in DevTools in Google Chrome prior to 102.0.5005.61 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 102.0.5005.61-1) bullseye: resolved (fixed in 102.0.5005.61-1~deb11u1) forky: resolved (fixed in 102.0.5005.61-1) si
debian
CVE-2022-0798P3HIGHCVSS 8.8fixed in chromium 99.0.4844.51-1 (bookworm)2022
CVE-2022-0798 [HIGH] CVE-2022-0798: chromium - Use after free in MediaStream in Google Chrome prior to 99.0.4844.51 allowed an ... Use after free in MediaStream in Google Chrome prior to 99.0.4844.51 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. Scope: local bookworm: resolved (fixed in 99.0.4844.51-1) bullseye: resolved (fixed in 99.0.4844.51-1~deb11u1) forky: resolved (fixed in 99.0.4844.51-1) si
debian
CVE-2022-0980P3HIGHCVSS 8.8fixed in chromium 99.0.4844.74-1 (bookworm)2022
CVE-2022-0980 [HIGH] CVE-2022-0980: chromium - Use after free in New Tab Page in Google Chrome prior to 99.0.4844.74 allowed an... Use after free in New Tab Page in Google Chrome prior to 99.0.4844.74 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via specific user interactions. Scope: local bookworm: resolved (fixed in 99.0.4844.74-1) bullseye: resolved (fixed in 99.0.4844.74-1~deb11u1) forky: resolved (fixed in 99.0.4844.74-1) s
debian
CVE-2022-1864P3HIGHCVSS 8.8fixed in chromium 102.0.5005.61-1 (bookworm)2022
CVE-2022-1864 [HIGH] CVE-2022-1864: chromium - Use after free in WebApp Installs in Google Chrome prior to 102.0.5005.61 allowe... Use after free in WebApp Installs in Google Chrome prior to 102.0.5005.61 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension and specific user interaction. Scope: local bookworm: resolved (fixed in 102.0.5005.61-1) bullseye: resolved (fixed in 102.0.5005.61-1~deb11u1) forky:
debian
CVE-2022-1863P3HIGHCVSS 8.8fixed in chromium 102.0.5005.61-1 (bookworm)2022
CVE-2022-1863 [HIGH] CVE-2022-1863: chromium - Use after free in Tab Groups in Google Chrome prior to 102.0.5005.61 allowed an ... Use after free in Tab Groups in Google Chrome prior to 102.0.5005.61 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension and specific user interaction. Scope: local bookworm: resolved (fixed in 102.0.5005.61-1) bullseye: resolved (fixed in 102.0.5005.61-1~deb11u1) forky: resol
debian
CVE-2022-1865P3HIGHCVSS 8.8fixed in chromium 102.0.5005.61-1 (bookworm)2022
CVE-2022-1865 [HIGH] CVE-2022-1865: chromium - Use after free in Bookmarks in Google Chrome prior to 102.0.5005.61 allowed an a... Use after free in Bookmarks in Google Chrome prior to 102.0.5005.61 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension and specific user interaction. Scope: local bookworm: resolved (fixed in 102.0.5005.61-1) bullseye: resolved (fixed in 102.0.5005.61-1~deb11u1) forky: resolv
debian
CVE-2023-0474P3HIGHCVSS 8.8fixed in chromium 109.0.5414.119-1 (bookworm)2023
CVE-2023-0474 [HIGH] CVE-2023-0474: chromium - Use after free in GuestView in Google Chrome prior to 109.0.5414.119 allowed an ... Use after free in GuestView in Google Chrome prior to 109.0.5414.119 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a Chrome web app. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 109.0.5414.119-1) bullseye: resolved (fixed in 109.0.5414.119-1~deb11u1) forky: resolv
debian
CVE-2021-21177P3MEDIUMCVSS 6.5fixed in chromium 89.0.4389.82-1 (bookworm)2021
CVE-2021-21177 [MEDIUM] CVE-2021-21177: chromium - Insufficient policy enforcement in Autofill in Google Chrome prior to 89.0.4389.... Insufficient policy enforcement in Autofill in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. Scope: local bookworm: resolved (fixed in 89.0.4389.82-1) bullseye: resolved (fixed in 89.0.4389.82-1) forky: resolved (fixed in 89.0.4389.82-1) sid: resolved (fixed i
debian
Debian Chromium vulnerabilities | cvebase