Debian Chromium vulnerabilities
2,134 known vulnerabilities affecting debian/chromium.
Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8
Vulnerabilities
Page 74 of 107
CVE-2021-21170P4MEDIUMCVSS 6.5fixed in chromium 89.0.4389.82-1 (bookworm)2021
CVE-2021-21170 [MEDIUM] CVE-2021-21170: chromium - Incorrect security UI in Loader in Google Chrome prior to 89.0.4389.72 allowed a...
Incorrect security UI in Loader in Google Chrome prior to 89.0.4389.72 allowed a remote attacker who had compromised the renderer process to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 89.0.4389.82-1)
bullseye: resolved (fixed in 89.0.4389.82-1)
forky: resolved (fixed in 89.0.4389.82-1)
sid: resol
debian
CVE-2020-6561P4MEDIUMCVSS 6.5fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-6561 [MEDIUM] CVE-2020-6561: chromium - Inappropriate implementation in Content Security Policy in Google Chrome prior t...
Inappropriate implementation in Content Security Policy in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (fixed in 87.0.4280.88-0.1)
tr
debian
CVE-2020-6484P4MEDIUMCVSS 6.5fixed in chromium 83.0.4103.83-1 (bookworm)2020
CVE-2020-6484 [MEDIUM] CVE-2020-6484: chromium - Insufficient data validation in ChromeDriver in Google Chrome prior to 83.0.4103...
Insufficient data validation in ChromeDriver in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a crafted request.
Scope: local
bookworm: resolved (fixed in 83.0.4103.83-1)
bullseye: resolved (fixed in 83.0.4103.83-1)
forky: resolved (fixed in 83.0.4103.83-1)
sid: resolved (fixed in 83.0.4103.83-1)
trixie: resolve
debian
CVE-2019-13742P4MEDIUMCVSS 6.5fixed in chromium 79.0.3945.79-1 (bookworm)2019
CVE-2019-13742 [MEDIUM] CVE-2019-13742: chromium - Incorrect security UI in Omnibox in Google Chrome on iOS prior to 79.0.3945.79 a...
Incorrect security UI in Omnibox in Google Chrome on iOS prior to 79.0.3945.79 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.
Scope: local
bookworm: resolved (fixed in 79.0.3945.79-1)
bullseye: resolved (fixed in 79.0.3945.79-1)
forky: resolved (fixed in 79.0.3945.79-1)
sid: resolved (fixed in 79.0.3945.79-1)
t
debian
CVE-2023-6512P4MEDIUMCVSS 6.5fixed in chromium 120.0.6099.71-1~deb12u1 (bookworm)2023
CVE-2023-6512 [MEDIUM] CVE-2023-6512: chromium - Inappropriate implementation in Web Browser UI in Google Chrome prior to 120.0.6...
Inappropriate implementation in Web Browser UI in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to potentially spoof the contents of an iframe dialog context menu via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 120.0.6099.71-1~deb12u1)
bullseye: resolved (fixed in 120.0.6099.71-1~deb11u1)
forky:
debian
CVE-2021-4059P4MEDIUMCVSS 6.5fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-4059 [MEDIUM] CVE-2021-4059: chromium - Insufficient data validation in loader in Google Chrome prior to 96.0.4664.93 al...
Insufficient data validation in loader in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 97.0.4692.71-0.1)
bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1)
forky: resolved (fixed in 97.0.4692.71-0.1)
sid: resolved (fixed in 97.0.4692.71-0.1)
trixie: res
debian
CVE-2023-4764P4MEDIUMCVSS 6.5fixed in chromium 116.0.5845.180-1~deb12u1 (bookworm)2023
CVE-2023-4764 [MEDIUM] CVE-2023-4764: chromium - Incorrect security UI in BFCache in Google Chrome prior to 116.0.5845.179 allowe...
Incorrect security UI in BFCache in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 116.0.5845.180-1~deb12u1)
bullseye: resolved (fixed in 116.0.5845.180-1~deb11u1)
forky: resolved (fixed in 116.0.5845.
debian
CVE-2024-3914P4MEDIUMCVSS 6.5fixed in chromium 124.0.6367.60-1~deb12u1 (bookworm)2024
CVE-2024-3914 [MEDIUM] CVE-2024-3914: chromium - Use after free in V8 in Google Chrome prior to 124.0.6367.60 allowed a remote at...
Use after free in V8 in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 124.0.6367.60-1~deb12u1)
bullseye: open
forky: resolved (fixed in 124.0.6367.60-1)
sid: resolved (fixed in 124.0.6367.60-1)
trixie: resolve
debian
CVE-2023-5484P4MEDIUMCVSS 6.5fixed in chromium 118.0.5993.70-1~deb12u1 (bookworm)2023
CVE-2023-5484 [MEDIUM] CVE-2023-5484: chromium - Inappropriate implementation in Navigation in Google Chrome prior to 118.0.5993....
Inappropriate implementation in Navigation in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 118.0.5993.70-1~deb12u1)
bullseye: resolved (fixed in 118.0.5993.70-1~deb11u1)
forky: resolved (fixed in 118.0.5993.70-1)
sid: resolv
debian
CVE-2024-4949P4MEDIUMCVSS 6.5fixed in chromium 125.0.6422.60-1~deb12u1 (bookworm)2024
CVE-2024-4949 [MEDIUM] CVE-2024-4949: chromium - Use after free in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote at...
Use after free in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 125.0.6422.60-1~deb12u1)
bullseye: open
forky: resolved (fixed in 125.0.6422.60-1)
sid: resolved (fixed in 125.0.6422.60-1)
trixie: resol
debian
CVE-2022-1869P4MEDIUMCVSS 6.5fixed in chromium 102.0.5005.61-1 (bookworm)2022
CVE-2022-1869 [MEDIUM] CVE-2022-1869: chromium - Type Confusion in V8 in Google Chrome prior to 102.0.5005.61 allowed a remote at...
Type Confusion in V8 in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 102.0.5005.61-1)
bullseye: resolved (fixed in 102.0.5005.61-1~deb11u1)
forky: resolved (fixed in 102.0.5005.61-1)
sid: resolved (fixed in 102.0.5005.61-1)
trixie: resolved (f
debian
CVE-2023-1814P4MEDIUMCVSS 6.5fixed in chromium 112.0.5615.49-1 (bookworm)2023
CVE-2023-1814 [MEDIUM] CVE-2023-1814: chromium - Insufficient validation of untrusted input in Safe Browsing in Google Chrome pri...
Insufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to bypass download checking via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 112.0.5615.49-1)
bullseye: resolved (fixed in 112.0.5615.49-2~deb11u2)
forky: resolved (fixed in 112.0.5615.4
debian
CVE-2022-1867P4MEDIUMCVSS 6.5fixed in chromium 102.0.5005.61-1 (bookworm)2022
CVE-2022-1867 [MEDIUM] CVE-2022-1867: chromium - Insufficient validation of untrusted input in Data Transfer in Google Chrome pri...
Insufficient validation of untrusted input in Data Transfer in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to bypass same origin policy via a crafted clipboard content.
Scope: local
bookworm: resolved (fixed in 102.0.5005.61-1)
bullseye: resolved (fixed in 102.0.5005.61-1~deb11u1)
forky: resolved (fixed in 102.0.5005.61-1)
sid: resolved (fixed in
debian
CVE-2023-5483P4MEDIUMCVSS 6.5fixed in chromium 118.0.5993.70-1~deb12u1 (bookworm)2023
CVE-2023-5483 [MEDIUM] CVE-2023-5483: chromium - Inappropriate implementation in Intents in Google Chrome prior to 118.0.5993.70 ...
Inappropriate implementation in Intents in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 118.0.5993.70-1~deb12u1)
bullseye: resolved (fixed in 118.0.5993.70-1~deb11u1)
forky: resolved (fixed in 118.0.5993.70-1)
s
debian
CVE-2023-5481P4MEDIUMCVSS 6.5fixed in chromium 118.0.5993.70-1~deb12u1 (bookworm)2023
CVE-2023-5481 [MEDIUM] CVE-2023-5481: chromium - Inappropriate implementation in Downloads in Google Chrome prior to 118.0.5993.7...
Inappropriate implementation in Downloads in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 118.0.5993.70-1~deb12u1)
bullseye: resolved (fixed in 118.0.5993.70-1~deb11u1)
forky: resolved (fixed in 118.0.5993.70-1)
sid: resolve
debian
CVE-2024-2630P4MEDIUMCVSS 6.5fixed in chromium 123.0.6312.86-1~deb12u1 (bookworm)2024
CVE-2024-2630 [MEDIUM] CVE-2024-2630: chromium - Inappropriate implementation in iOS in Google Chrome prior to 123.0.6312.58 allo...
Inappropriate implementation in iOS in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 123.0.6312.86-1~deb12u1)
bullseye: open
forky: resolved (fixed in 123.0.6312.58-1)
sid: resolved (fixed in 123.0.6312.58-1)
trixie: res
debian
CVE-2024-1671P4MEDIUMCVSS 6.5fixed in chromium 122.0.6261.57-1~deb12u1 (bookworm)2024
CVE-2024-1671 [MEDIUM] CVE-2024-1671: chromium - Inappropriate implementation in Site Isolation in Google Chrome prior to 122.0.6...
Inappropriate implementation in Site Isolation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 122.0.6261.57-1~deb12u1)
bullseye: open
forky: resolved (fixed in 122.0.6261.57-1)
sid: resolved (fixed in 122.0.626
debian
CVE-2023-1813P4MEDIUMCVSS 6.5fixed in chromium 112.0.5615.49-1 (bookworm)2023
CVE-2023-1813 [MEDIUM] CVE-2023-1813: chromium - Inappropriate implementation in Extensions in Google Chrome prior to 112.0.5615....
Inappropriate implementation in Extensions in Google Chrome prior to 112.0.5615.49 allowed an attacker who convinced a user to install a malicious extension to bypass file access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 112.0.5615.49-1)
bullseye: resolved (fixed in 112.0.5615.49-2~deb11u2)
debian
CVE-2023-2940P4MEDIUMCVSS 6.5fixed in chromium 114.0.5735.90-2~deb12u1 (bookworm)2023
CVE-2023-2940 [MEDIUM] CVE-2023-2940: chromium - Inappropriate implementation in Downloads in Google Chrome prior to 114.0.5735.9...
Inappropriate implementation in Downloads in Google Chrome prior to 114.0.5735.90 allowed an attacker who convinced a user to install a malicious extension to bypass file access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 114.0.5735.90-2~deb12u1)
bullseye: resolved (fixed in 114.0.5735.90-2~de
debian
CVE-2023-5487P4MEDIUMCVSS 6.5fixed in chromium 118.0.5993.70-1~deb12u1 (bookworm)2023
CVE-2023-5487 [MEDIUM] CVE-2023-5487: chromium - Inappropriate implementation in Fullscreen in Google Chrome prior to 118.0.5993....
Inappropriate implementation in Fullscreen in Google Chrome prior to 118.0.5993.70 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 118.0.5993.70-1~deb12u1)
bullseye: resolved (fixed in 118.0.5993.
debian