cbcvebase.

Debian Chromium vulnerabilities

2,134 known vulnerabilities affecting debian/chromium.

Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8

Vulnerabilities

Page 74 of 107
CVE-2021-21170P4MEDIUMCVSS 6.5fixed in chromium 89.0.4389.82-1 (bookworm)2021
CVE-2021-21170 [MEDIUM] CVE-2021-21170: chromium - Incorrect security UI in Loader in Google Chrome prior to 89.0.4389.72 allowed a... Incorrect security UI in Loader in Google Chrome prior to 89.0.4389.72 allowed a remote attacker who had compromised the renderer process to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. Scope: local bookworm: resolved (fixed in 89.0.4389.82-1) bullseye: resolved (fixed in 89.0.4389.82-1) forky: resolved (fixed in 89.0.4389.82-1) sid: resol
debian
CVE-2020-6561P4MEDIUMCVSS 6.5fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-6561 [MEDIUM] CVE-2020-6561: chromium - Inappropriate implementation in Content Security Policy in Google Chrome prior t... Inappropriate implementation in Content Security Policy in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to leak cross-origin data via a crafted HTML page. Scope: local bookworm: resolved (fixed in 87.0.4280.88-0.1) bullseye: resolved (fixed in 87.0.4280.88-0.1) forky: resolved (fixed in 87.0.4280.88-0.1) sid: resolved (fixed in 87.0.4280.88-0.1) tr
debian
CVE-2020-6484P4MEDIUMCVSS 6.5fixed in chromium 83.0.4103.83-1 (bookworm)2020
CVE-2020-6484 [MEDIUM] CVE-2020-6484: chromium - Insufficient data validation in ChromeDriver in Google Chrome prior to 83.0.4103... Insufficient data validation in ChromeDriver in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a crafted request. Scope: local bookworm: resolved (fixed in 83.0.4103.83-1) bullseye: resolved (fixed in 83.0.4103.83-1) forky: resolved (fixed in 83.0.4103.83-1) sid: resolved (fixed in 83.0.4103.83-1) trixie: resolve
debian
CVE-2019-13742P4MEDIUMCVSS 6.5fixed in chromium 79.0.3945.79-1 (bookworm)2019
CVE-2019-13742 [MEDIUM] CVE-2019-13742: chromium - Incorrect security UI in Omnibox in Google Chrome on iOS prior to 79.0.3945.79 a... Incorrect security UI in Omnibox in Google Chrome on iOS prior to 79.0.3945.79 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name. Scope: local bookworm: resolved (fixed in 79.0.3945.79-1) bullseye: resolved (fixed in 79.0.3945.79-1) forky: resolved (fixed in 79.0.3945.79-1) sid: resolved (fixed in 79.0.3945.79-1) t
debian
CVE-2023-6512P4MEDIUMCVSS 6.5fixed in chromium 120.0.6099.71-1~deb12u1 (bookworm)2023
CVE-2023-6512 [MEDIUM] CVE-2023-6512: chromium - Inappropriate implementation in Web Browser UI in Google Chrome prior to 120.0.6... Inappropriate implementation in Web Browser UI in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to potentially spoof the contents of an iframe dialog context menu via a crafted HTML page. (Chromium security severity: Low) Scope: local bookworm: resolved (fixed in 120.0.6099.71-1~deb12u1) bullseye: resolved (fixed in 120.0.6099.71-1~deb11u1) forky:
debian
CVE-2021-4059P4MEDIUMCVSS 6.5fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-4059 [MEDIUM] CVE-2021-4059: chromium - Insufficient data validation in loader in Google Chrome prior to 96.0.4664.93 al... Insufficient data validation in loader in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to leak cross-origin data via a crafted HTML page. Scope: local bookworm: resolved (fixed in 97.0.4692.71-0.1) bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1) forky: resolved (fixed in 97.0.4692.71-0.1) sid: resolved (fixed in 97.0.4692.71-0.1) trixie: res
debian
CVE-2023-4764P4MEDIUMCVSS 6.5fixed in chromium 116.0.5845.180-1~deb12u1 (bookworm)2023
CVE-2023-4764 [MEDIUM] CVE-2023-4764: chromium - Incorrect security UI in BFCache in Google Chrome prior to 116.0.5845.179 allowe... Incorrect security UI in BFCache in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 116.0.5845.180-1~deb12u1) bullseye: resolved (fixed in 116.0.5845.180-1~deb11u1) forky: resolved (fixed in 116.0.5845.
debian
CVE-2024-3914P4MEDIUMCVSS 6.5fixed in chromium 124.0.6367.60-1~deb12u1 (bookworm)2024
CVE-2024-3914 [MEDIUM] CVE-2024-3914: chromium - Use after free in V8 in Google Chrome prior to 124.0.6367.60 allowed a remote at... Use after free in V8 in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 124.0.6367.60-1~deb12u1) bullseye: open forky: resolved (fixed in 124.0.6367.60-1) sid: resolved (fixed in 124.0.6367.60-1) trixie: resolve
debian
CVE-2023-5484P4MEDIUMCVSS 6.5fixed in chromium 118.0.5993.70-1~deb12u1 (bookworm)2023
CVE-2023-5484 [MEDIUM] CVE-2023-5484: chromium - Inappropriate implementation in Navigation in Google Chrome prior to 118.0.5993.... Inappropriate implementation in Navigation in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 118.0.5993.70-1~deb12u1) bullseye: resolved (fixed in 118.0.5993.70-1~deb11u1) forky: resolved (fixed in 118.0.5993.70-1) sid: resolv
debian
CVE-2024-4949P4MEDIUMCVSS 6.5fixed in chromium 125.0.6422.60-1~deb12u1 (bookworm)2024
CVE-2024-4949 [MEDIUM] CVE-2024-4949: chromium - Use after free in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote at... Use after free in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 125.0.6422.60-1~deb12u1) bullseye: open forky: resolved (fixed in 125.0.6422.60-1) sid: resolved (fixed in 125.0.6422.60-1) trixie: resol
debian
CVE-2022-1869P4MEDIUMCVSS 6.5fixed in chromium 102.0.5005.61-1 (bookworm)2022
CVE-2022-1869 [MEDIUM] CVE-2022-1869: chromium - Type Confusion in V8 in Google Chrome prior to 102.0.5005.61 allowed a remote at... Type Confusion in V8 in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 102.0.5005.61-1) bullseye: resolved (fixed in 102.0.5005.61-1~deb11u1) forky: resolved (fixed in 102.0.5005.61-1) sid: resolved (fixed in 102.0.5005.61-1) trixie: resolved (f
debian
CVE-2023-1814P4MEDIUMCVSS 6.5fixed in chromium 112.0.5615.49-1 (bookworm)2023
CVE-2023-1814 [MEDIUM] CVE-2023-1814: chromium - Insufficient validation of untrusted input in Safe Browsing in Google Chrome pri... Insufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to bypass download checking via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 112.0.5615.49-1) bullseye: resolved (fixed in 112.0.5615.49-2~deb11u2) forky: resolved (fixed in 112.0.5615.4
debian
CVE-2022-1867P4MEDIUMCVSS 6.5fixed in chromium 102.0.5005.61-1 (bookworm)2022
CVE-2022-1867 [MEDIUM] CVE-2022-1867: chromium - Insufficient validation of untrusted input in Data Transfer in Google Chrome pri... Insufficient validation of untrusted input in Data Transfer in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to bypass same origin policy via a crafted clipboard content. Scope: local bookworm: resolved (fixed in 102.0.5005.61-1) bullseye: resolved (fixed in 102.0.5005.61-1~deb11u1) forky: resolved (fixed in 102.0.5005.61-1) sid: resolved (fixed in
debian
CVE-2023-5483P4MEDIUMCVSS 6.5fixed in chromium 118.0.5993.70-1~deb12u1 (bookworm)2023
CVE-2023-5483 [MEDIUM] CVE-2023-5483: chromium - Inappropriate implementation in Intents in Google Chrome prior to 118.0.5993.70 ... Inappropriate implementation in Intents in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 118.0.5993.70-1~deb12u1) bullseye: resolved (fixed in 118.0.5993.70-1~deb11u1) forky: resolved (fixed in 118.0.5993.70-1) s
debian
CVE-2023-5481P4MEDIUMCVSS 6.5fixed in chromium 118.0.5993.70-1~deb12u1 (bookworm)2023
CVE-2023-5481 [MEDIUM] CVE-2023-5481: chromium - Inappropriate implementation in Downloads in Google Chrome prior to 118.0.5993.7... Inappropriate implementation in Downloads in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 118.0.5993.70-1~deb12u1) bullseye: resolved (fixed in 118.0.5993.70-1~deb11u1) forky: resolved (fixed in 118.0.5993.70-1) sid: resolve
debian
CVE-2024-2630P4MEDIUMCVSS 6.5fixed in chromium 123.0.6312.86-1~deb12u1 (bookworm)2024
CVE-2024-2630 [MEDIUM] CVE-2024-2630: chromium - Inappropriate implementation in iOS in Google Chrome prior to 123.0.6312.58 allo... Inappropriate implementation in iOS in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 123.0.6312.86-1~deb12u1) bullseye: open forky: resolved (fixed in 123.0.6312.58-1) sid: resolved (fixed in 123.0.6312.58-1) trixie: res
debian
CVE-2024-1671P4MEDIUMCVSS 6.5fixed in chromium 122.0.6261.57-1~deb12u1 (bookworm)2024
CVE-2024-1671 [MEDIUM] CVE-2024-1671: chromium - Inappropriate implementation in Site Isolation in Google Chrome prior to 122.0.6... Inappropriate implementation in Site Isolation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 122.0.6261.57-1~deb12u1) bullseye: open forky: resolved (fixed in 122.0.6261.57-1) sid: resolved (fixed in 122.0.626
debian
CVE-2023-1813P4MEDIUMCVSS 6.5fixed in chromium 112.0.5615.49-1 (bookworm)2023
CVE-2023-1813 [MEDIUM] CVE-2023-1813: chromium - Inappropriate implementation in Extensions in Google Chrome prior to 112.0.5615.... Inappropriate implementation in Extensions in Google Chrome prior to 112.0.5615.49 allowed an attacker who convinced a user to install a malicious extension to bypass file access restrictions via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 112.0.5615.49-1) bullseye: resolved (fixed in 112.0.5615.49-2~deb11u2)
debian
CVE-2023-2940P4MEDIUMCVSS 6.5fixed in chromium 114.0.5735.90-2~deb12u1 (bookworm)2023
CVE-2023-2940 [MEDIUM] CVE-2023-2940: chromium - Inappropriate implementation in Downloads in Google Chrome prior to 114.0.5735.9... Inappropriate implementation in Downloads in Google Chrome prior to 114.0.5735.90 allowed an attacker who convinced a user to install a malicious extension to bypass file access restrictions via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 114.0.5735.90-2~deb12u1) bullseye: resolved (fixed in 114.0.5735.90-2~de
debian
CVE-2023-5487P4MEDIUMCVSS 6.5fixed in chromium 118.0.5993.70-1~deb12u1 (bookworm)2023
CVE-2023-5487 [MEDIUM] CVE-2023-5487: chromium - Inappropriate implementation in Fullscreen in Google Chrome prior to 118.0.5993.... Inappropriate implementation in Fullscreen in Google Chrome prior to 118.0.5993.70 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 118.0.5993.70-1~deb12u1) bullseye: resolved (fixed in 118.0.5993.
debian
Debian Chromium vulnerabilities | cvebase