Debian Chromium vulnerabilities
2,134 known vulnerabilities affecting debian/chromium.
Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8
Vulnerabilities
Page 78 of 107
CVE-2021-4068P4MEDIUMCVSS 6.5fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-4068 [MEDIUM] CVE-2021-4068: chromium - Insufficient data validation in new tab page in Google Chrome prior to 96.0.4664...
Insufficient data validation in new tab page in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 97.0.4692.71-0.1)
bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1)
forky: resolved (fixed in 97.0.4692.71-0.1)
sid: resolved (fixed in 97.0.4692.71-0.1)
trixi
debian
CVE-2020-15984P4MEDIUMCVSS 6.5fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-15984 [MEDIUM] CVE-2020-15984: chromium - Insufficient policy enforcement in Omnibox in Google Chrome on iOS prior to 86.0...
Insufficient policy enforcement in Omnibox in Google Chrome on iOS prior to 86.0.4240.75 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted URL.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (fixed in 87.0.4280
debian
CVE-2019-13739P4MEDIUMCVSS 6.5fixed in chromium 79.0.3945.79-1 (bookworm)2019
CVE-2019-13739 [MEDIUM] CVE-2019-13739: chromium - Insufficient policy enforcement in Omnibox in Google Chrome prior to 79.0.3945.7...
Insufficient policy enforcement in Omnibox in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
Scope: local
bookworm: resolved (fixed in 79.0.3945.79-1)
bullseye: resolved (fixed in 79.0.3945.79-1)
forky: resolved (fixed in 79.0.3945.79-1)
sid: resolved (fixed in 79.0.3945.79-1)
debian
CVE-2019-5767P4MEDIUMCVSS 6.5fixed in chromium 72.0.3626.81-1 (bookworm)2019
CVE-2019-5767 [MEDIUM] CVE-2019-5767: chromium - Insufficient protection of permission UI in WebAPKs in Google Chrome on Android ...
Insufficient protection of permission UI in WebAPKs in Google Chrome on Android prior to 72.0.3626.81 allowed an attacker who convinced the user to install a malicious application to access privacy/security sensitive web APIs via a crafted APK.
Scope: local
bookworm: resolved (fixed in 72.0.3626.81-1)
bullseye: resolved (fixed in 72.0.3626.81-1)
forky: resolved (fi
debian
CVE-2021-30534P4MEDIUMCVSS 6.5fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30534 [MEDIUM] CVE-2021-30534: chromium - Insufficient policy enforcement in iFrameSandbox in Google Chrome prior to 91.0....
Insufficient policy enforcement in iFrameSandbox in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 93.0.4577.82-1)
bullseye: resolved (fixed in 93.0.4577.82-1)
forky: resolved (fixed in 93.0.4577.82-1)
sid: resolved (fixed in 93.0.4577.82-1)
trixie:
debian
CVE-2021-4054P4MEDIUMCVSS 6.5fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-4054 [MEDIUM] CVE-2021-4054: chromium - Incorrect security UI in autofill in Google Chrome prior to 96.0.4664.93 allowed...
Incorrect security UI in autofill in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 97.0.4692.71-0.1)
bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1)
forky: resolved (fixed in 97.0.4692.71-0.1)
sid: resolved (fixed in 97.0.4692.71-0.1)
trixie: resolve
debian
CVE-2024-4559P4MEDIUMCVSS 6.5fixed in chromium 124.0.6367.155-1~deb12u1 (bookworm)2024
CVE-2024-4559 [MEDIUM] CVE-2024-4559: chromium - Heap buffer overflow in WebAudio in Google Chrome prior to 124.0.6367.155 allowe...
Heap buffer overflow in WebAudio in Google Chrome prior to 124.0.6367.155 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 124.0.6367.155-1~deb12u1)
bullseye: open
forky: resolved (fixed in 124.0.6367.155-1)
sid: resolved (fixed in 124.0.6367.155-1)
debian
CVE-2024-3516P4MEDIUMCVSS 6.5fixed in chromium 123.0.6312.122-1~deb12u1 (bookworm)2024
CVE-2024-3516 [MEDIUM] CVE-2024-3516: chromium - Heap buffer overflow in ANGLE in Google Chrome prior to 123.0.6312.122 allowed a...
Heap buffer overflow in ANGLE in Google Chrome prior to 123.0.6312.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 123.0.6312.122-1~deb12u1)
bullseye: open
forky: resolved (fixed in 123.0.6312.122-1)
sid: resolved (fixed in 123.0.6312.122-1)
tr
debian
CVE-2022-0792P4MEDIUMCVSS 6.5fixed in chromium 99.0.4844.51-1 (bookworm)2022
CVE-2022-0792 [MEDIUM] CVE-2022-0792: chromium - Out of bounds read in ANGLE in Google Chrome prior to 99.0.4844.51 allowed a rem...
Out of bounds read in ANGLE in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 99.0.4844.51-1)
bullseye: resolved (fixed in 99.0.4844.51-1~deb11u1)
forky: resolved (fixed in 99.0.4844.51-1)
sid: resolved (fixed in 99.0.4844.51-1)
trixie: resolved
debian
CVE-2023-1817P4MEDIUMCVSS 6.5fixed in chromium 112.0.5615.49-1 (bookworm)2023
CVE-2023-1817 [MEDIUM] CVE-2023-1817: chromium - Insufficient policy enforcement in Intents in Google Chrome on Android prior to ...
Insufficient policy enforcement in Intents in Google Chrome on Android prior to 112.0.5615.49 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 112.0.5615.49-1)
bullseye: resolved (fixed in 112.0.5615.49-2~deb11u2)
forky: resolved (fixed in 112.0.5615.4
debian
CVE-2023-1822P4MEDIUMCVSS 6.5fixed in chromium 112.0.5615.49-1 (bookworm)2023
CVE-2023-1822 [MEDIUM] CVE-2023-1822: chromium - Incorrect security UI in Navigation in Google Chrome prior to 112.0.5615.49 allo...
Incorrect security UI in Navigation in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 112.0.5615.49-1)
bullseye: resolved (fixed in 112.0.5615.49-2~deb11u2)
forky: resolved (fixed in 112.0.5615.49-1)
sid: resolved (fixed in
debian
CVE-2022-3056P4MEDIUMCVSS 6.5fixed in chromium 105.0.5195.52-1 (bookworm)2022
CVE-2022-3056 [MEDIUM] CVE-2022-3056: chromium - Insufficient policy enforcement in Content Security Policy in Google Chrome prio...
Insufficient policy enforcement in Content Security Policy in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to bypass content security policy via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 105.0.5195.52-1)
bullseye: resolved (fixed in 105.0.5195.52-1~deb11u1)
forky: resolved (fixed in 105.0.5195.52-1)
sid: resolved (fixed in 105
debian
CVE-2024-4059P4MEDIUMCVSS 6.5fixed in chromium 124.0.6367.78-1~deb12u1 (bookworm)2024
CVE-2024-4059 [MEDIUM] CVE-2024-4059: chromium - Out of bounds read in V8 API in Google Chrome prior to 124.0.6367.78 allowed a r...
Out of bounds read in V8 API in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to leak cross-site data via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 124.0.6367.78-1~deb12u1)
bullseye: open
forky: resolved (fixed in 124.0.6367.78-1)
sid: resolved (fixed in 124.0.6367.78-1)
trixie: resolved (fixe
debian
CVE-2023-1823P4MEDIUMCVSS 6.5fixed in chromium 112.0.5615.49-1 (bookworm)2023
CVE-2023-1823 [MEDIUM] CVE-2023-1823: chromium - Inappropriate implementation in FedCM in Google Chrome prior to 112.0.5615.49 al...
Inappropriate implementation in FedCM in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 112.0.5615.49-1)
bullseye: resolved (fixed in 112.0.5615.49-2~deb11u2)
forky: resolved (fixed in 112.0.5615.49-1)
sid: resolved
debian
CVE-2023-0704P4MEDIUMCVSS 6.5fixed in chromium 110.0.5481.77-1 (bookworm)2023
CVE-2023-0704 [MEDIUM] CVE-2023-0704: chromium - Insufficient policy enforcement in DevTools in Google Chrome prior to 110.0.5481...
Insufficient policy enforcement in DevTools in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to bypass same origin policy and proxy settings via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 110.0.5481.77-1)
bullseye: resolved (fixed in 110.0.5481.77-1~deb11u1)
forky: resolved (fixed in 110.0.5481.
debian
CVE-2023-1819P4MEDIUMCVSS 6.5fixed in chromium 112.0.5615.49-1 (bookworm)2023
CVE-2023-1819 [MEDIUM] CVE-2023-1819: chromium - Out of bounds read in Accessibility in Google Chrome prior to 112.0.5615.49 allo...
Out of bounds read in Accessibility in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 112.0.5615.49-1)
bullseye: resolved (fixed in 112.0.5615.49-2~deb11u2)
forky: resolved (fixed in 112.0.5615.49-1)
sid: re
debian
CVE-2022-1139P4MEDIUMCVSS 6.5fixed in chromium 100.0.4896.60-1 (bookworm)2022
CVE-2022-1139 [MEDIUM] CVE-2022-1139: chromium - Inappropriate implementation in Background Fetch API in Google Chrome prior to 1...
Inappropriate implementation in Background Fetch API in Google Chrome prior to 100.0.4896.60 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 100.0.4896.60-1)
bullseye: resolved (fixed in 100.0.4896.60-1~deb11u1)
forky: resolved (fixed in 100.0.4896.60-1)
sid: resolved (fixed in 100.0.4896.60-1)
debian
CVE-2022-1138P4MEDIUMCVSS 6.5fixed in chromium 100.0.4896.60-1 (bookworm)2022
CVE-2022-1138 [MEDIUM] CVE-2022-1138: chromium - Inappropriate implementation in Web Cursor in Google Chrome prior to 100.0.4896....
Inappropriate implementation in Web Cursor in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who had compromised the renderer process to obscure the contents of the Omnibox (URL bar) via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 100.0.4896.60-1)
bullseye: resolved (fixed in 100.0.4896.60-1~deb11u1)
forky: resolved (fixed in 100.
debian
CVE-2022-1482P4MEDIUMCVSS 6.5fixed in chromium 101.0.4951.41-1 (bookworm)2022
CVE-2022-1482 [MEDIUM] CVE-2022-1482: chromium - Inappropriate implementation in WebGL in Google Chrome prior to 101.0.4951.41 al...
Inappropriate implementation in WebGL in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 101.0.4951.41-1)
bullseye: resolved (fixed in 101.0.4951.41-1~deb11u1)
forky: resolved (fixed in 101.0.4951.41-1)
sid: resolved (fixed in 101.0.4951.41-1)
tr
debian
CVE-2020-6444P4MEDIUMCVSS 6.3fixed in chromium 81.0.4044.92-1 (bookworm)2020
CVE-2020-6444 [MEDIUM] CVE-2020-6444: chromium - Uninitialized use in WebRTC in Google Chrome prior to 81.0.4044.92 allowed a rem...
Uninitialized use in WebRTC in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 81.0.4044.92-1)
bullseye: resolved (fixed in 81.0.4044.92-1)
forky: resolved (fixed in 81.0.4044.92-1)
sid: resolved (fixed in 81.0.4044.92-1)
trixie: resolved (fixed i
debian