cbcvebase.

Debian Chromium vulnerabilities

2,134 known vulnerabilities affecting debian/chromium.

Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8

Vulnerabilities

Page 83 of 107
CVE-2020-6460P4MEDIUMCVSS 6.5fixed in chromium 83.0.4103.83-1 (bookworm)2020
CVE-2020-6460 [MEDIUM] CVE-2020-6460: chromium - Insufficient data validation in URL formatting in Google Chrome prior to 81.0.40... Insufficient data validation in URL formatting in Google Chrome prior to 81.0.4044.122 allowed a remote attacker to perform domain spoofing via a crafted domain name. Scope: local bookworm: resolved (fixed in 83.0.4103.83-1) bullseye: resolved (fixed in 83.0.4103.83-1) forky: resolved (fixed in 83.0.4103.83-1) sid: resolved (fixed in 83.0.4103.83-1) trixie: resolve
debian
CVE-2022-0807P4MEDIUMCVSS 6.5fixed in chromium 99.0.4844.51-1 (bookworm)2022
CVE-2022-0807 [MEDIUM] CVE-2022-0807: chromium - Inappropriate implementation in Autofill in Google Chrome prior to 99.0.4844.51 ... Inappropriate implementation in Autofill in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. Scope: local bookworm: resolved (fixed in 99.0.4844.51-1) bullseye: resolved (fixed in 99.0.4844.51-1~deb11u1) forky: resolved (fixed in 99.0.4844.51-1) sid: resolved (fixed in 99.0.4844.51-1) trixie: r
debian
CVE-2022-3044P4MEDIUMCVSS 6.5fixed in chromium 105.0.5195.52-1 (bookworm)2022
CVE-2022-3044 [MEDIUM] CVE-2022-3044: chromium - Inappropriate implementation in Site Isolation in Google Chrome prior to 105.0.5... Inappropriate implementation in Site Isolation in Google Chrome prior to 105.0.5195.52 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. Scope: local bookworm: resolved (fixed in 105.0.5195.52-1) bullseye: resolved (fixed in 105.0.5195.52-1~deb11u1) forky: resolved (fixed in 105.0.5195.52-1) sid: re
debian
CVE-2022-2860P4MEDIUMCVSS 6.5fixed in chromium 104.0.5112.101-1 (bookworm)2022
CVE-2022-2860 [MEDIUM] CVE-2022-2860: chromium - Insufficient policy enforcement in Cookies in Google Chrome prior to 104.0.5112.... Insufficient policy enforcement in Cookies in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to bypass cookie prefix restrictions via a crafted HTML page. Scope: local bookworm: resolved (fixed in 104.0.5112.101-1) bullseye: resolved (fixed in 104.0.5112.101-1~deb11u1) forky: resolved (fixed in 104.0.5112.101-1) sid: resolved (fixed in 104.0.5112.1
debian
CVE-2022-1146P4MEDIUMCVSS 6.5fixed in chromium 100.0.4896.60-1 (bookworm)2022
CVE-2022-1146 [MEDIUM] CVE-2022-1146: chromium - Inappropriate implementation in Resource Timing in Google Chrome prior to 100.0.... Inappropriate implementation in Resource Timing in Google Chrome prior to 100.0.4896.60 allowed a remote attacker to leak cross-origin data via a crafted HTML page. Scope: local bookworm: resolved (fixed in 100.0.4896.60-1) bullseye: resolved (fixed in 100.0.4896.60-1~deb11u1) forky: resolved (fixed in 100.0.4896.60-1) sid: resolved (fixed in 100.0.4896.60-1) trixi
debian
CVE-2022-0113P4MEDIUMCVSS 6.5fixed in chromium 97.0.4692.71-0.1 (bookworm)2022
CVE-2022-0113 [MEDIUM] CVE-2022-0113: chromium - Inappropriate implementation in Blink in Google Chrome prior to 97.0.4692.71 all... Inappropriate implementation in Blink in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to leak cross-origin data via a crafted HTML page. Scope: local bookworm: resolved (fixed in 97.0.4692.71-0.1) bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1) forky: resolved (fixed in 97.0.4692.71-0.1) sid: resolved (fixed in 97.0.4692.71-0.1) trixie: reso
debian
CVE-2021-38022P4MEDIUMCVSS 6.5fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-38022 [MEDIUM] CVE-2021-38022: chromium - Inappropriate implementation in WebAuthentication in Google Chrome prior to 96.0... Inappropriate implementation in WebAuthentication in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to leak cross-origin data via a crafted HTML page. Scope: local bookworm: resolved (fixed in 97.0.4692.71-0.1) bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1) forky: resolved (fixed in 97.0.4692.71-0.1) sid: resolved (fixed in 97.0.4692.71-0.1
debian
CVE-2022-1501P4MEDIUMCVSS 6.5fixed in chromium 101.0.4951.41-1 (bookworm)2022
CVE-2022-1501 [MEDIUM] CVE-2022-1501: chromium - Inappropriate implementation in iframe in Google Chrome prior to 101.0.4951.41 a... Inappropriate implementation in iframe in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to leak cross-origin data via a crafted HTML page. Scope: local bookworm: resolved (fixed in 101.0.4951.41-1) bullseye: resolved (fixed in 101.0.4951.41-1~deb11u1) forky: resolved (fixed in 101.0.4951.41-1) sid: resolved (fixed in 101.0.4951.41-1) trixie: resolv
debian
CVE-2022-0803P4MEDIUMCVSS 6.5fixed in chromium 99.0.4844.51-1 (bookworm)2022
CVE-2022-0803 [MEDIUM] CVE-2022-0803: chromium - Inappropriate implementation in Permissions in Google Chrome prior to 99.0.4844.... Inappropriate implementation in Permissions in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to tamper with the contents of the Omnibox (URL bar) via a crafted HTML page. Scope: local bookworm: resolved (fixed in 99.0.4844.51-1) bullseye: resolved (fixed in 99.0.4844.51-1~deb11u1) forky: resolved (fixed in 99.0.4844.51-1) sid: resolved (fixed in 99.
debian
CVE-2022-0462P4MEDIUMCVSS 6.5fixed in chromium 98.0.4758.80-1 (bookworm)2022
CVE-2022-0462 [MEDIUM] CVE-2022-0462: chromium - Inappropriate implementation in Scroll in Google Chrome prior to 98.0.4758.80 al... Inappropriate implementation in Scroll in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to leak cross-origin data via a crafted HTML page. Scope: local bookworm: resolved (fixed in 98.0.4758.80-1) bullseye: resolved (fixed in 98.0.4758.80-1~deb11u1) forky: resolved (fixed in 98.0.4758.80-1) sid: resolved (fixed in 98.0.4758.80-1) trixie: resolved (f
debian
CVE-2021-38009P4MEDIUMCVSS 6.5fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-38009 [MEDIUM] CVE-2021-38009: chromium - Inappropriate implementation in cache in Google Chrome prior to 96.0.4664.45 all... Inappropriate implementation in cache in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to leak cross-origin data via a crafted HTML page. Scope: local bookworm: resolved (fixed in 97.0.4692.71-0.1) bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1) forky: resolved (fixed in 97.0.4692.71-0.1) sid: resolved (fixed in 97.0.4692.71-0.1) trixie: re
debian
CVE-2021-38019P4MEDIUMCVSS 6.5fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-38019 [MEDIUM] CVE-2021-38019: chromium - Insufficient policy enforcement in CORS in Google Chrome prior to 96.0.4664.45 a... Insufficient policy enforcement in CORS in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to leak cross-origin data via a crafted HTML page. Scope: local bookworm: resolved (fixed in 97.0.4692.71-0.1) bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1) forky: resolved (fixed in 97.0.4692.71-0.1) sid: resolved (fixed in 97.0.4692.71-0.1) trixie:
debian
CVE-2020-16027P4MEDIUMCVSS 6.5fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-16027 [MEDIUM] CVE-2020-16027: chromium - Insufficient policy enforcement in developer tools in Google Chrome prior to 87.... Insufficient policy enforcement in developer tools in Google Chrome prior to 87.0.4280.66 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from the user's disk via a crafted Chrome Extension. Scope: local bookworm: resolved (fixed in 87.0.4280.88-0.1) bullseye: resolved (fixed in 87.0.4280.88-0.
debian
CVE-2021-37989P4MEDIUMCVSS 6.5fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-37989 [MEDIUM] CVE-2021-37989: chromium - Inappropriate implementation in Blink in Google Chrome prior to 95.0.4638.54 all... Inappropriate implementation in Blink in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to abuse content security policy via a crafted HTML page. Scope: local bookworm: resolved (fixed in 97.0.4692.71-0.1) bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1) forky: resolved (fixed in 97.0.4692.71-0.1) sid: resolved (fixed in 97.0.4692.71-0.1) tri
debian
CVE-2022-0111P4MEDIUMCVSS 6.5fixed in chromium 97.0.4692.71-0.1 (bookworm)2022
CVE-2022-0111 [MEDIUM] CVE-2022-0111: chromium - Inappropriate implementation in Navigation in Google Chrome prior to 97.0.4692.7... Inappropriate implementation in Navigation in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to incorrectly set origin via a crafted HTML page. Scope: local bookworm: resolved (fixed in 97.0.4692.71-0.1) bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1) forky: resolved (fixed in 97.0.4692.71-0.1) sid: resolved (fixed in 97.0.4692.71-0.1) trixie:
debian
CVE-2021-37994P4MEDIUMCVSS 6.5fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-37994 [MEDIUM] CVE-2021-37994: chromium - Inappropriate implementation in iFrame Sandbox in Google Chrome prior to 95.0.46... Inappropriate implementation in iFrame Sandbox in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. Scope: local bookworm: resolved (fixed in 97.0.4692.71-0.1) bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1) forky: resolved (fixed in 97.0.4692.71-0.1) sid: resolved (fixed in 97.0.4692.7
debian
CVE-2022-1858P4MEDIUMCVSS 6.5fixed in chromium 102.0.5005.61-1 (bookworm)2022
CVE-2022-1858 [MEDIUM] CVE-2022-1858: chromium - Out of bounds read in DevTools in Google Chrome prior to 102.0.5005.61 allowed a... Out of bounds read in DevTools in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to perform an out of bounds memory read via specific user interaction. Scope: local bookworm: resolved (fixed in 102.0.5005.61-1) bullseye: resolved (fixed in 102.0.5005.61-1~deb11u1) forky: resolved (fixed in 102.0.5005.61-1) sid: resolved (fixed in 102.0.5005.61-1) tr
debian
CVE-2022-0294P4MEDIUMCVSS 6.5fixed in chromium 97.0.4692.99-1 (bookworm)2022
CVE-2022-0294 [MEDIUM] CVE-2022-0294: chromium - Inappropriate implementation in Push messaging in Google Chrome prior to 97.0.46... Inappropriate implementation in Push messaging in Google Chrome prior to 97.0.4692.99 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. Scope: local bookworm: resolved (fixed in 97.0.4692.99-1) bullseye: resolved (fixed in 97.0.4692.99-1~deb11u2) forky: resolved (fixed in 97.0.4692.99-1) sid: resolv
debian
CVE-2019-13662P4MEDIUMCVSS 6.5fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-13662 [MEDIUM] CVE-2019-13662: chromium - Insufficient policy enforcement in navigations in Google Chrome prior to 77.0.38... Insufficient policy enforcement in navigations in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to bypass content security policy via a crafted HTML page. Scope: local bookworm: resolved (fixed in 78.0.3904.87-1) bullseye: resolved (fixed in 78.0.3904.87-1) forky: resolved (fixed in 78.0.3904.87-1) sid: resolved (fixed in 78.0.3904.87-1) trixie: r
debian
CVE-2022-2610P4MEDIUMCVSS 6.5fixed in chromium 104.0.5112.79-1 (bookworm)2022
CVE-2022-2610 [MEDIUM] CVE-2022-2610: chromium - Insufficient policy enforcement in Background Fetch in Google Chrome prior to 10... Insufficient policy enforcement in Background Fetch in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to leak cross-origin data via a crafted HTML page. Scope: local bookworm: resolved (fixed in 104.0.5112.79-1) bullseye: resolved (fixed in 104.0.5112.79-1~deb11u1) forky: resolved (fixed in 104.0.5112.79-1) sid: resolved (fixed in 104.0.5112.79-1) t
debian
Debian Chromium vulnerabilities | cvebase