cbcvebase.

Debian Chromium vulnerabilities

2,134 known vulnerabilities affecting debian/chromium.

Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8

Vulnerabilities

Page 67 of 107
CVE-2021-21190P3HIGHCVSS 8.8fixed in chromium 89.0.4389.82-1 (bookworm)2021
CVE-2021-21190 [HIGH] CVE-2021-21190: chromium - Uninitialized data in PDFium in Google Chrome prior to 89.0.4389.72 allowed a re... Uninitialized data in PDFium in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted PDF file. Scope: local bookworm: resolved (fixed in 89.0.4389.82-1) bullseye: resolved (fixed in 89.0.4389.82-1) forky: resolved (fixed in 89.0.4389.82-1) sid: resolved (fixed in 89.0.4389.82-1)
debian
CVE-2019-13741P3HIGHCVSS 8.8fixed in chromium 79.0.3945.79-1 (bookworm)2019
CVE-2019-13741 [HIGH] CVE-2019-13741: chromium - Insufficient validation of untrusted input in Blink in Google Chrome prior to 79... Insufficient validation of untrusted input in Blink in Google Chrome prior to 79.0.3945.79 allowed a local attacker to bypass same origin policy via crafted clipboard content. Scope: local bookworm: resolved (fixed in 79.0.3945.79-1) bullseye: resolved (fixed in 79.0.3945.79-1) forky: resolved (fixed in 79.0.3945.79-1) sid: resolved (fixed in 79.0.3945.79-1) trixie
debian
CVE-2022-1486P3HIGHCVSS 8.8fixed in chromium 101.0.4951.41-1 (bookworm)2022
CVE-2022-1486 [HIGH] CVE-2022-1486: chromium - Type confusion in V8 in Google Chrome prior to 101.0.4951.41 allowed a remote at... Type confusion in V8 in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. Scope: local bookworm: resolved (fixed in 101.0.4951.41-1) bullseye: resolved (fixed in 101.0.4951.41-1~deb11u1) forky: resolved (fixed in 101.0.4951.41-1) sid: resolved (fixed in 101.0.4951.41
debian
CVE-2019-13682P3HIGHCVSS 8.8fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-13682 [HIGH] CVE-2019-13682: chromium - Insufficient policy enforcement in external protocol handling in Google Chrome p... Insufficient policy enforcement in external protocol handling in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to bypass same origin policy via a crafted HTML page. Scope: local bookworm: resolved (fixed in 78.0.3904.87-1) bullseye: resolved (fixed in 78.0.3904.87-1) forky: resolved (fixed in 78.0.3904.87-1) sid: resolved (fixed in 78.0.3904.87-1) t
debian
CVE-2019-13692P3HIGHCVSS 8.8fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-13692 [HIGH] CVE-2019-13692: chromium - Insufficient policy enforcement in reader mode in Google Chrome prior to 77.0.38... Insufficient policy enforcement in reader mode in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to bypass site isolation via a crafted HTML page. Scope: local bookworm: resolved (fixed in 78.0.3904.87-1) bullseye: resolved (fixed in 78.0.3904.87-1) forky: resolved (fixed in 78.0.3904.87-1) sid: resolved (fixed in 78.0.3904.87-1) trixie: resolved (fi
debian
CVE-2018-20066P3HIGHCVSS 8.8fixed in chromium 71.0.3578.80-1 (bookworm)2018
CVE-2018-20066 [HIGH] CVE-2018-20066: chromium - Incorrect object lifecycle in Extensions in Google Chrome prior to 71.0.3578.80 ... Incorrect object lifecycle in Extensions in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 71.0.3578.80-1) bullseye: resolved (fixed in 71.0.3578.80-1) forky: resolved (fixed in 71.0.3578.80-1) sid: resolved (fixed in 71.0.3578.80-1) trixie: reso
debian
CVE-2021-21202P3HIGHCVSS 8.6fixed in chromium 90.0.4430.72-1 (bookworm)2021
CVE-2021-21202 [HIGH] CVE-2021-21202: chromium - Use after free in extensions in Google Chrome prior to 90.0.4430.72 allowed an a... Use after free in extensions in Google Chrome prior to 90.0.4430.72 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension. Scope: local bookworm: resolved (fixed in 90.0.4430.72-1) bullseye: resolved (fixed in 90.0.4430.72-1) forky: resolved (fixed in 90.0.4430.72-1) sid: res
debian
CVE-2021-21207P3HIGHCVSS 8.6fixed in chromium 90.0.4430.72-1 (bookworm)2021
CVE-2021-21207 [HIGH] CVE-2021-21207: chromium - Use after free in IndexedDB in Google Chrome prior to 90.0.4430.72 allowed an at... Use after free in IndexedDB in Google Chrome prior to 90.0.4430.72 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension. Scope: local bookworm: resolved (fixed in 90.0.4430.72-1) bullseye: resolved (fixed in 90.0.4430.72-1) forky: resolved (fixed in 90.0.4430.72-1) sid: reso
debian
CVE-2020-16041P3HIGHCVSS 8.1fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-16041 [HIGH] CVE-2020-16041: chromium - Out of bounds read in networking in Google Chrome prior to 87.0.4280.88 allowed ... Out of bounds read in networking in Google Chrome prior to 87.0.4280.88 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. Scope: local bookworm: resolved (fixed in 87.0.4280.88-0.1) bullseye: resolved (fixed in 87.0.4280.88-0.1) forky: resolved (fixed in 87.0.4
debian
CVE-2020-6554P3HIGHCVSS 8.6fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-6554 [HIGH] CVE-2020-6554: chromium - Use after free in extensions in Google Chrome prior to 84.0.4147.125 allowed a r... Use after free in extensions in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially perform a sandbox escape via a crafted Chrome Extension. Scope: local bookworm: resolved (fixed in 87.0.4280.88-0.1) bullseye: resolved (fixed in 87.0.4280.88-0.1) forky: resolved (fixed in 87.0.4280.88-0.1) sid: resolved (fixed in 87.0.4280.88-0.1) trixie: r
debian
CVE-2021-21138P3HIGHCVSS 8.6fixed in chromium 88.0.4324.96-0.1 (bookworm)2021
CVE-2021-21138 [HIGH] CVE-2021-21138: chromium - Use after free in DevTools in Google Chrome prior to 88.0.4324.96 allowed a loca... Use after free in DevTools in Google Chrome prior to 88.0.4324.96 allowed a local attacker to potentially perform a sandbox escape via a crafted file. Scope: local bookworm: resolved (fixed in 88.0.4324.96-0.1) bullseye: resolved (fixed in 88.0.4324.96-0.1) forky: resolved (fixed in 88.0.4324.96-0.1) sid: resolved (fixed in 88.0.4324.96-0.1) trixie: resolved (fixed
debian
CVE-2023-2135P3HIGHCVSS 7.5fixed in chromium 112.0.5615.138-1 (bookworm)2023
CVE-2023-2135 [HIGH] CVE-2023-2135: chromium - Use after free in DevTools in Google Chrome prior to 112.0.5615.137 allowed a re... Use after free in DevTools in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who convinced a user to enable specific preconditions to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 112.0.5615.138-1) bullseye: resolved (fixed in 112.0.5615.138-1~deb11u1) forky:
debian
CVE-2024-6778P3HIGHCVSS 7.5fixed in chromium 126.0.6478.182-1~deb12u1 (bookworm)2024
CVE-2024-6778 [HIGH] CVE-2024-6778: chromium - Race in DevTools in Google Chrome prior to 126.0.6478.182 allowed an attacker wh... Race in DevTools in Google Chrome prior to 126.0.6478.182 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via a crafted Chrome Extension. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 126.0.6478.182-1~deb12u1) bullseye: open forky: resolved (fixed in 126.0.6478.1
debian
CVE-2021-37991P3HIGHCVSS 7.5fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-37991 [HIGH] CVE-2021-37991: chromium - Race in V8 in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to p... Race in V8 in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 97.0.4692.71-0.1) bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1) forky: resolved (fixed in 97.0.4692.71-0.1) sid: resolved (fixed in 97.0.4692.71-0.1) trixie: resolved (fixed in
debian
CVE-2023-0705P3HIGHCVSS 7.5fixed in chromium 110.0.5481.77-1 (bookworm)2023
CVE-2023-0705 [HIGH] CVE-2023-0705: chromium - Integer overflow in Core in Google Chrome prior to 110.0.5481.77 allowed a remot... Integer overflow in Core in Google Chrome prior to 110.0.5481.77 allowed a remote attacker who had one a race condition to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low) Scope: local bookworm: resolved (fixed in 110.0.5481.77-1) bullseye: resolved (fixed in 110.0.5481.77-1~deb11u1) forky: resolved (fixed in 110.0.5481.7
debian
CVE-2026-1220P3UNKNOWNfixed in chromium 144.0.7559.96-1~deb12u1 (bookworm)2026
CVE-2026-1220 CVE-2026-1220: chromium bookworm: resolved (fixed in 144.0.7559.96-1~deb12u1) bullseye: open forky: resolved (fixed in 144.0.7559.96-1) sid: resolved (fixed in 144.0.7559.96-1) trixie: resolved (fixed in 144.0.7559.96-1~deb13u1)
debian
CVE-2021-21131P3MEDIUMCVSS 6.5fixed in chromium 88.0.4324.96-0.1 (bookworm)2021
CVE-2021-21131 [MEDIUM] CVE-2021-21131: chromium - Insufficient policy enforcement in File System API in Google Chrome prior to 88.... Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. Scope: local bookworm: resolved (fixed in 88.0.4324.96-0.1) bullseye: resolved (fixed in 88.0.4324.96-0.1) forky: resolved (fixed in 88.0.4324.96-0.1) sid: resolved (fixed in 88.0.4324.96-0.
debian
CVE-2019-5854P3HIGHCVSS 8.8fixed in chromium 76.0.3809.87-1 (bookworm)2019
CVE-2019-5854 [HIGH] CVE-2019-5854: chromium - Integer overflow in PDFium in Google Chrome prior to 76.0.3809.87 allowed a remo... Integer overflow in PDFium in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. Scope: local bookworm: resolved (fixed in 76.0.3809.87-1) bullseye: resolved (fixed in 76.0.3809.87-1) forky: resolved (fixed in 76.0.3809.87-1) sid: resolved (fixed in 76.0.3809.87-1) trixie: resolved (fixed in 76
debian
CVE-2021-30506P3HIGHCVSS 8.8fixed in chromium 90.0.4430.212-1 (bookworm)2021
CVE-2021-30506 [HIGH] CVE-2021-30506: chromium - Incorrect security UI in Web App Installs in Google Chrome on Android prior to 9... Incorrect security UI in Web App Installs in Google Chrome on Android prior to 90.0.4430.212 allowed an attacker who convinced a user to install a web application to inject scripts or HTML into a privileged page via a crafted HTML page. Scope: local bookworm: resolved (fixed in 90.0.4430.212-1) bullseye: resolved (fixed in 90.0.4430.212-1) forky: resolved (fixed in
debian
CVE-2018-20065P3HIGHCVSS 8.8fixed in chromium 71.0.3578.80-1 (bookworm)2018
CVE-2018-20065 [HIGH] CVE-2018-20065: chromium - Handling of URI action in PDFium in Google Chrome prior to 71.0.3578.80 allowed ... Handling of URI action in PDFium in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to initiate potentially unsafe navigations without a user gesture via a crafted PDF file. Scope: local bookworm: resolved (fixed in 71.0.3578.80-1) bullseye: resolved (fixed in 71.0.3578.80-1) forky: resolved (fixed in 71.0.3578.80-1) sid: resolved (fixed in 71.0.3578.
debian
Debian Chromium vulnerabilities | cvebase