cbcvebase.

Debian Chromium vulnerabilities

2,134 known vulnerabilities affecting debian/chromium.

Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8

Vulnerabilities

Page 85 of 107
CVE-2019-5777P4MEDIUMCVSS 6.5fixed in chromium 72.0.3626.81-1 (bookworm)2019
CVE-2019-5777 [MEDIUM] CVE-2019-5777: chromium - Incorrect handling of a confusable character in Omnibox in Google Chrome prior t... Incorrect handling of a confusable character in Omnibox in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name. Scope: local bookworm: resolved (fixed in 72.0.3626.81-1) bullseye: resolved (fixed in 72.0.3626.81-1) forky: resolved (fixed in 72.0.3626.81-1) sid: resolved (fixed in 72.
debian
CVE-2019-5776P4MEDIUMCVSS 6.5fixed in chromium 72.0.3626.81-1 (bookworm)2019
CVE-2019-5776 [MEDIUM] CVE-2019-5776: chromium - Incorrect handling of a confusable character in Omnibox in Google Chrome prior t... Incorrect handling of a confusable character in Omnibox in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name. Scope: local bookworm: resolved (fixed in 72.0.3626.81-1) bullseye: resolved (fixed in 72.0.3626.81-1) forky: resolved (fixed in 72.0.3626.81-1) sid: resolved (fixed in 72.
debian
CVE-2019-5805P4MEDIUMCVSS 6.5fixed in chromium 74.0.3729.108-1 (bookworm)2019
CVE-2019-5805 [MEDIUM] CVE-2019-5805: chromium - Use-after-free in PDFium in Google Chrome prior to 74.0.3729.108 allowed a remot... Use-after-free in PDFium in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. Scope: local bookworm: resolved (fixed in 74.0.3729.108-1) bullseye: resolved (fixed in 74.0.3729.108-1) forky: resolved (fixed in 74.0.3729.108-1) sid: resolved (fixed in 74.0.3729.108-1) trixie: resolved (fixed
debian
CVE-2018-18346P4MEDIUMCVSS 6.5fixed in chromium 71.0.3578.80-1 (bookworm)2018
CVE-2018-18346 [MEDIUM] CVE-2018-18346: chromium - Incorrect handling of alert box display in Blink in Google Chrome prior to 71.0.... Incorrect handling of alert box display in Blink in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to present confusing browser UI via a crafted HTML page. Scope: local bookworm: resolved (fixed in 71.0.3578.80-1) bullseye: resolved (fixed in 71.0.3578.80-1) forky: resolved (fixed in 71.0.3578.80-1) sid: resolved (fixed in 71.0.3578.80-1) trixie: r
debian
CVE-2020-6480P4MEDIUMCVSS 6.5fixed in chromium 83.0.4103.83-1 (bookworm)2020
CVE-2020-6480 [MEDIUM] CVE-2020-6480: chromium - Insufficient policy enforcement in enterprise in Google Chrome prior to 83.0.410... Insufficient policy enforcement in enterprise in Google Chrome prior to 83.0.4103.61 allowed a local attacker to bypass navigation restrictions via UI actions. Scope: local bookworm: resolved (fixed in 83.0.4103.83-1) bullseye: resolved (fixed in 83.0.4103.83-1) forky: resolved (fixed in 83.0.4103.83-1) sid: resolved (fixed in 83.0.4103.83-1) trixie: resolved (fixe
debian
CVE-2019-13713P4MEDIUMCVSS 6.5fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-13713 [MEDIUM] CVE-2019-13713: chromium - Insufficient policy enforcement in JavaScript in Google Chrome prior to 78.0.390... Insufficient policy enforcement in JavaScript in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to leak cross-origin data via a crafted HTML page. Scope: local bookworm: resolved (fixed in 78.0.3904.87-1) bullseye: resolved (fixed in 78.0.3904.87-1) forky: resolved (fixed in 78.0.3904.87-1) sid: resolved (fixed in 78.0.3904.87-1) trixie: resolved (
debian
CVE-2020-6547P4MEDIUMCVSS 6.5fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-6547 [MEDIUM] CVE-2020-6547: chromium - Incorrect security UI in media in Google Chrome prior to 84.0.4147.125 allowed a... Incorrect security UI in media in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially obtain sensitive information via a crafted HTML page. Scope: local bookworm: resolved (fixed in 87.0.4280.88-0.1) bullseye: resolved (fixed in 87.0.4280.88-0.1) forky: resolved (fixed in 87.0.4280.88-0.1) sid: resolved (fixed in 87.0.4280.88-0.1) trixie:
debian
CVE-2020-6495P4MEDIUMCVSS 6.5fixed in chromium 83.0.4103.106-1 (bookworm)2020
CVE-2020-6495 [MEDIUM] CVE-2020-6495: chromium - Insufficient policy enforcement in developer tools in Google Chrome prior to 83.... Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.97 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension. Scope: local bookworm: resolved (fixed in 83.0.4103.106-1) bullseye: resolved (fixed in 83.0.4103.106-1) forky: resolved (fixed in
debian
CVE-2019-5826P4MEDIUMCVSS 6.5fixed in chromium 75.0.3770.80-1 (bookworm)2019
CVE-2019-5826 [MEDIUM] CVE-2019-5826: chromium - Use after free in IndexedDB in Google Chrome prior to 73.0.3683.86 allowed a rem... Use after free in IndexedDB in Google Chrome prior to 73.0.3683.86 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 75.0.3770.80-1) bullseye: resolved (fixed in 75.0.3770.80-1) forky: resolved (fixed in 75.0.3770.80-1) sid: resolved (fixed in
debian
CVE-2021-21211P4MEDIUMCVSS 6.5fixed in chromium 90.0.4430.72-1 (bookworm)2021
CVE-2021-21211 [MEDIUM] CVE-2021-21211: chromium - Inappropriate implementation in Navigation in Google Chrome on iOS prior to 90.0... Inappropriate implementation in Navigation in Google Chrome on iOS prior to 90.0.4430.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. Scope: local bookworm: resolved (fixed in 90.0.4430.72-1) bullseye: resolved (fixed in 90.0.4430.72-1) forky: resolved (fixed in 90.0.4430.72-1) sid: resolved (fixed in 90.0.4430.72-1) trixie: resolv
debian
CVE-2020-6538P4MEDIUMCVSS 6.5fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-6538 [MEDIUM] CVE-2020-6538: chromium - Inappropriate implementation in WebView in Google Chrome on Android prior to 84.... Inappropriate implementation in WebView in Google Chrome on Android prior to 84.0.4147.105 allowed a remote attacker to leak cross-origin data via a crafted HTML page. Scope: local bookworm: resolved (fixed in 87.0.4280.88-0.1) bullseye: resolved (fixed in 87.0.4280.88-0.1) forky: resolved (fixed in 87.0.4280.88-0.1) sid: resolved (fixed in 87.0.4280.88-0.1) trixie
debian
CVE-2019-5793P4MEDIUMCVSS 6.5fixed in chromium 73.0.3683.75-1 (bookworm)2019
CVE-2019-5793 [MEDIUM] CVE-2019-5793: chromium - Insufficient policy enforcement in extensions in Google Chrome prior to 73.0.368... Insufficient policy enforcement in extensions in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to initiate the extensions installation user interface via a crafted HTML page. Scope: local bookworm: resolved (fixed in 73.0.3683.75-1) bullseye: resolved (fixed in 73.0.3683.75-1) forky: resolved (fixed in 73.0.3683.75-1) sid: resolved (fixed in 73.0.36
debian
CVE-2019-13709P4MEDIUMCVSS 6.5fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-13709 [MEDIUM] CVE-2019-13709: chromium - Insufficient policy enforcement in downloads in Google Chrome prior to 78.0.3904... Insufficient policy enforcement in downloads in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to bypass download restrictions via a crafted HTML page. Scope: local bookworm: resolved (fixed in 78.0.3904.87-1) bullseye: resolved (fixed in 78.0.3904.87-1) forky: resolved (fixed in 78.0.3904.87-1) sid: resolved (fixed in 78.0.3904.87-1) trixie: resol
debian
CVE-2019-13670P4MEDIUMCVSS 6.5fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-13670 [MEDIUM] CVE-2019-13670: chromium - Insufficient data validation in JavaScript in Google Chrome prior to 77.0.3865.7... Insufficient data validation in JavaScript in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 78.0.3904.87-1) bullseye: resolved (fixed in 78.0.3904.87-1) forky: resolved (fixed in 78.0.3904.87-1) sid: resolved (fixed in 78.0.3904.87-1) trixie:
debian
CVE-2019-5814P4MEDIUMCVSS 6.5fixed in chromium 74.0.3729.108-1 (bookworm)2019
CVE-2019-5814 [MEDIUM] CVE-2019-5814: chromium - Insufficient policy enforcement in Blink in Google Chrome prior to 74.0.3729.108... Insufficient policy enforcement in Blink in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to leak cross-origin data via a crafted HTML page. Scope: local bookworm: resolved (fixed in 74.0.3729.108-1) bullseye: resolved (fixed in 74.0.3729.108-1) forky: resolved (fixed in 74.0.3729.108-1) sid: resolved (fixed in 74.0.3729.108-1) trixie: resolved (fi
debian
CVE-2021-38010P4MEDIUMCVSS 6.5fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-38010 [MEDIUM] CVE-2021-38010: chromium - Inappropriate implementation in service workers in Google Chrome prior to 96.0.4... Inappropriate implementation in service workers in Google Chrome prior to 96.0.4664.45 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. Scope: local bookworm: resolved (fixed in 97.0.4692.71-0.1) bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1) forky: resolved (fixed in 97.0.4692.71-0.1) si
debian
CVE-2020-16042P4MEDIUMCVSS 6.5fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-16042 [MEDIUM] CVE-2020-16042: chromium - Uninitialized Use in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote ... Uninitialized Use in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. Scope: local bookworm: resolved (fixed in 87.0.4280.88-0.1) bullseye: resolved (fixed in 87.0.4280.88-0.1) forky: resolved (fixed in 87.0.4280.88-0.1) sid: resolved (fixed in 87.0.4280.88
debian
CVE-2020-6498P4MEDIUMCVSS 6.5fixed in chromium 83.0.4103.106-1 (bookworm)2020
CVE-2020-6498 [MEDIUM] CVE-2020-6498: chromium - Incorrect implementation in user interface in Google Chrome on iOS prior to 83.0... Incorrect implementation in user interface in Google Chrome on iOS prior to 83.0.4103.88 allowed a remote attacker to perform domain spoofing via a crafted HTML page. Scope: local bookworm: resolved (fixed in 83.0.4103.106-1) bullseye: resolved (fixed in 83.0.4103.106-1) forky: resolved (fixed in 83.0.4103.106-1) sid: resolved (fixed in 83.0.4103.106-1) trixie: res
debian
CVE-2019-13683P4MEDIUMCVSS 6.5fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-13683 [MEDIUM] CVE-2019-13683: chromium - Insufficient policy enforcement in developer tools in Google Chrome prior to 77.... Insufficient policy enforcement in developer tools in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to leak cross-origin data via a crafted HTML page. Scope: local bookworm: resolved (fixed in 78.0.3904.87-1) bullseye: resolved (fixed in 78.0.3904.87-1) forky: resolved (fixed in 78.0.3904.87-1) sid: resolved (fixed in 78.0.3904.87-1) trixie: resol
debian
CVE-2022-0802P4MEDIUMCVSS 6.5fixed in chromium 99.0.4844.51-1 (bookworm)2022
CVE-2022-0802 [MEDIUM] CVE-2022-0802: chromium - Inappropriate implementation in Full screen mode in Google Chrome on Android pri... Inappropriate implementation in Full screen mode in Google Chrome on Android prior to 99.0.4844.51 allowed a remote attacker to hide the contents of the Omnibox (URL bar) via a crafted HTML page. Scope: local bookworm: resolved (fixed in 99.0.4844.51-1) bullseye: resolved (fixed in 99.0.4844.51-1~deb11u1) forky: resolved (fixed in 99.0.4844.51-1) sid: resolved (fix
debian
Debian Chromium vulnerabilities | cvebase