Debian Chromium vulnerabilities
2,134 known vulnerabilities affecting debian/chromium.
Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8
Vulnerabilities
Page 81 of 107
CVE-2020-6408P4MEDIUMCVSS 6.5fixed in chromium 80.0.3987.106-1 (bookworm)2020
CVE-2020-6408 [MEDIUM] CVE-2020-6408: chromium - Insufficient policy enforcement in CORS in Google Chrome prior to 80.0.3987.87 a...
Insufficient policy enforcement in CORS in Google Chrome prior to 80.0.3987.87 allowed a local attacker to obtain potentially sensitive information via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 80.0.3987.106-1)
bullseye: resolved (fixed in 80.0.3987.106-1)
forky: resolved (fixed in 80.0.3987.106-1)
sid: resolved (fixed in 80.0.3987.106-1)
trixi
debian
CVE-2019-5818P4MEDIUMCVSS 6.5fixed in chromium 74.0.3729.108-1 (bookworm)2019
CVE-2019-5818 [MEDIUM] CVE-2019-5818: chromium - Uninitialized data in media in Google Chrome prior to 74.0.3729.108 allowed a re...
Uninitialized data in media in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted video file.
Scope: local
bookworm: resolved (fixed in 74.0.3729.108-1)
bullseye: resolved (fixed in 74.0.3729.108-1)
forky: resolved (fixed in 74.0.3729.108-1)
sid: resolved (fixed in 74.0.3729.1
debian
CVE-2019-5784P4MEDIUMCVSS 6.5fixed in chromium 72.0.3626.109-1 (bookworm)2019
CVE-2019-5784 [MEDIUM] CVE-2019-5784: chromium - Incorrect handling of deferred code in V8 in Google Chrome prior to 72.0.3626.96...
Incorrect handling of deferred code in V8 in Google Chrome prior to 72.0.3626.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 72.0.3626.109-1)
bullseye: resolved (fixed in 72.0.3626.109-1)
forky: resolved (fixed in 72.0.3626.109-1)
sid: resolved (fixed in 72.0.3626.109-1)
trixie:
debian
CVE-2020-6564P4MEDIUMCVSS 6.5fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-6564 [MEDIUM] CVE-2020-6564: chromium - Inappropriate implementation in permissions in Google Chrome prior to 85.0.4183....
Inappropriate implementation in permissions in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to spoof the contents of a permission dialog via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (fixed in 87.0.4280.88-
debian
CVE-2019-5837P4MEDIUMCVSS 6.5fixed in chromium 75.0.3770.80-1 (bookworm)2019
CVE-2019-5837 [MEDIUM] CVE-2019-5837: chromium - Resource size information leakage in Blink in Google Chrome prior to 75.0.3770.8...
Resource size information leakage in Blink in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 75.0.3770.80-1)
bullseye: resolved (fixed in 75.0.3770.80-1)
forky: resolved (fixed in 75.0.3770.80-1)
sid: resolved (fixed in 75.0.3770.80-1)
trixie: resolved (fixed
debian
CVE-2020-6557P4MEDIUMCVSS 6.5fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-6557 [MEDIUM] CVE-2020-6557: chromium - Inappropriate implementation in networking in Google Chrome prior to 86.0.4240.7...
Inappropriate implementation in networking in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (fixed in 87.0.4280.88-0.1)
trixie: resolv
debian
CVE-2020-6568P4MEDIUMCVSS 6.5fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-6568 [MEDIUM] CVE-2020-6568: chromium - Insufficient policy enforcement in intent handling in Google Chrome on Android p...
Insufficient policy enforcement in intent handling in Google Chrome on Android prior to 85.0.4183.83 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (fixed in 87.0.4
debian
CVE-2020-6562P4MEDIUMCVSS 6.5fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-6562 [MEDIUM] CVE-2020-6562: chromium - Insufficient policy enforcement in Blink in Google Chrome prior to 85.0.4183.83 ...
Insufficient policy enforcement in Blink in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (fixed in 87.0.4280.88-0.1)
trixie: resolved
debian
CVE-2020-6565P4MEDIUMCVSS 6.5fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-6565 [MEDIUM] CVE-2020-6565: chromium - Inappropriate implementation in Omnibox in Google Chrome on iOS prior to 85.0.41...
Inappropriate implementation in Omnibox in Google Chrome on iOS prior to 85.0.4183.83 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (fixed in 87.0.428
debian
CVE-2020-6494P4MEDIUMCVSS 6.5fixed in chromium 83.0.4103.106-1 (bookworm)2020
CVE-2020-6494 [MEDIUM] CVE-2020-6494: chromium - Incorrect security UI in payments in Google Chrome on Android prior to 83.0.4103...
Incorrect security UI in payments in Google Chrome on Android prior to 83.0.4103.97 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 83.0.4103.106-1)
bullseye: resolved (fixed in 83.0.4103.106-1)
forky: resolved (fixed in 83.0.4103.106-1)
sid: resolved (fixed in 83.0.4103.106
debian
CVE-2020-6472P4MEDIUMCVSS 6.5fixed in chromium 83.0.4103.83-1 (bookworm)2020
CVE-2020-6472 [MEDIUM] CVE-2020-6472: chromium - Insufficient policy enforcement in developer tools in Google Chrome prior to 83....
Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from process memory or disk via a crafted Chrome Extension.
Scope: local
bookworm: resolved (fixed in 83.0.4103.83-1)
bullseye: resolved (fixed in 83.0.4103.83
debian
CVE-2019-13744P4MEDIUMCVSS 6.5fixed in chromium 79.0.3945.79-1 (bookworm)2019
CVE-2019-13744 [MEDIUM] CVE-2019-13744: chromium - Insufficient policy enforcement in cookies in Google Chrome prior to 79.0.3945.7...
Insufficient policy enforcement in cookies in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 79.0.3945.79-1)
bullseye: resolved (fixed in 79.0.3945.79-1)
forky: resolved (fixed in 79.0.3945.79-1)
sid: resolved (fixed in 79.0.3945.79-1)
trixie: resolved (fix
debian
CVE-2019-5844P4MEDIUMCVSS 6.5fixed in chromium 73.0.3683.75-1 (bookworm)2019
CVE-2019-5844 [MEDIUM] CVE-2019-5844: chromium - Out of bounds access in SwiftShader in Google Chrome prior to 73.0.3683.75 allow...
Out of bounds access in SwiftShader in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 73.0.3683.75-1)
bullseye: resolved (fixed in 73.0.3683.75-1)
forky: resolved (fixed in 73.0.3683.75-1)
sid: resolved (fixed in 73.0.3683.75-1)
trixie: resolved
debian
CVE-2019-5846P4MEDIUMCVSS 6.5fixed in chromium 73.0.3683.75-1 (bookworm)2019
CVE-2019-5846 [MEDIUM] CVE-2019-5846: chromium - Out of bounds access in SwiftShader in Google Chrome prior to 73.0.3683.75 allow...
Out of bounds access in SwiftShader in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 73.0.3683.75-1)
bullseye: resolved (fixed in 73.0.3683.75-1)
forky: resolved (fixed in 73.0.3683.75-1)
sid: resolved (fixed in 73.0.3683.75-1)
trixie: resolved
debian
CVE-2019-5845P4MEDIUMCVSS 6.5fixed in chromium 73.0.3683.75-1 (bookworm)2019
CVE-2019-5845 [MEDIUM] CVE-2019-5845: chromium - Out of bounds access in SwiftShader in Google Chrome prior to 73.0.3683.75 allow...
Out of bounds access in SwiftShader in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 73.0.3683.75-1)
bullseye: resolved (fixed in 73.0.3683.75-1)
forky: resolved (fixed in 73.0.3683.75-1)
sid: resolved (fixed in 73.0.3683.75-1)
trixie: resolved
debian
CVE-2019-5830P4MEDIUMCVSS 6.5fixed in chromium 75.0.3770.80-1 (bookworm)2019
CVE-2019-5830 [MEDIUM] CVE-2019-5830: chromium - Insufficient policy enforcement in CORS in Google Chrome prior to 75.0.3770.80 a...
Insufficient policy enforcement in CORS in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 75.0.3770.80-1)
bullseye: resolved (fixed in 75.0.3770.80-1)
forky: resolved (fixed in 75.0.3770.80-1)
sid: resolved (fixed in 75.0.3770.80-1)
trixie: resolved (fixed in
debian
CVE-2020-15982P4MEDIUMCVSS 6.5fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-15982 [MEDIUM] CVE-2020-15982: chromium - Inappropriate implementation in cache in Google Chrome prior to 86.0.4240.75 all...
Inappropriate implementation in cache in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (fixed i
debian
CVE-2019-13737P4MEDIUMCVSS 6.5fixed in chromium 79.0.3945.79-1 (bookworm)2019
CVE-2019-13737 [MEDIUM] CVE-2019-13737: chromium - Insufficient policy enforcement in autocomplete in Google Chrome prior to 79.0.3...
Insufficient policy enforcement in autocomplete in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 79.0.3945.79-1)
bullseye: resolved (fixed in 79.0.3945.79-1)
forky: resolved (fixed in 79.0.3945.79-1)
sid: resolved (fix
debian
CVE-2018-18350P4MEDIUMCVSS 6.5fixed in chromium 71.0.3578.80-1 (bookworm)2018
CVE-2018-18350 [MEDIUM] CVE-2018-18350: chromium - Incorrect handling of CSP enforcement during navigations in Blink in Google Chro...
Incorrect handling of CSP enforcement during navigations in Blink in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to bypass content security policy via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 71.0.3578.80-1)
bullseye: resolved (fixed in 71.0.3578.80-1)
forky: resolved (fixed in 71.0.3578.80-1)
sid: resolved (fixed in 71.0.3
debian
CVE-2019-13746P4MEDIUMCVSS 6.5fixed in chromium 79.0.3945.79-1 (bookworm)2019
CVE-2019-13746 [MEDIUM] CVE-2019-13746: chromium - Insufficient policy enforcement in Omnibox in Google Chrome prior to 79.0.3945.7...
Insufficient policy enforcement in Omnibox in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 79.0.3945.79-1)
bullseye: resolved (fixed in 79.0.3945.79-1)
forky: resolved (fixed in 79.0.3945.79-1)
sid: resolved (fixed in 79.0.3945.79-1)
debian