Debian Chromium vulnerabilities
2,134 known vulnerabilities affecting debian/chromium.
Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8
Vulnerabilities
Page 86 of 107
CVE-2022-0804P4MEDIUMCVSS 6.5fixed in chromium 99.0.4844.51-1 (bookworm)2022
CVE-2022-0804 [MEDIUM] CVE-2022-0804: chromium - Inappropriate implementation in Full screen mode in Google Chrome on Android pri...
Inappropriate implementation in Full screen mode in Google Chrome on Android prior to 99.0.4844.51 allowed a remote attacker to hide the contents of the Omnibox (URL bar) via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 99.0.4844.51-1)
bullseye: resolved (fixed in 99.0.4844.51-1~deb11u1)
forky: resolved (fixed in 99.0.4844.51-1)
sid: resolved (fix
debian
CVE-2021-21229P4MEDIUMCVSS 6.5fixed in chromium 90.0.4430.93-1 (bookworm)2021
CVE-2021-21229 [MEDIUM] CVE-2021-21229: chromium - Incorrect security UI in downloads in Google Chrome on Android prior to 90.0.443...
Incorrect security UI in downloads in Google Chrome on Android prior to 90.0.4430.93 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 90.0.4430.93-1)
bullseye: resolved (fixed in 90.0.4430.93-1)
forky: resolved (fixed in 90.0.4430.93-1)
sid: resolved (fixed in 90.0.4430.93-1)
trixie: resolved
debian
CVE-2019-5847P4MEDIUMCVSS 6.5fixed in chromium 76.0.3809.87-1 (bookworm)2019
CVE-2019-5847 [MEDIUM] CVE-2019-5847: chromium - Inappropriate implementation in JavaScript in Google Chrome prior to 75.0.3770.1...
Inappropriate implementation in JavaScript in Google Chrome prior to 75.0.3770.142 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 76.0.3809.87-1)
bullseye: resolved (fixed in 76.0.3809.87-1)
forky: resolved (fixed in 76.0.3809.87-1)
sid: resolved (fixed in 76.0.3809.87-1)
trixie: r
debian
CVE-2019-13740P4MEDIUMCVSS 6.5fixed in chromium 79.0.3945.79-1 (bookworm)2019
CVE-2019-13740 [MEDIUM] CVE-2019-13740: chromium - Incorrect security UI in sharing in Google Chrome prior to 79.0.3945.79 allowed ...
Incorrect security UI in sharing in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 79.0.3945.79-1)
bullseye: resolved (fixed in 79.0.3945.79-1)
forky: resolved (fixed in 79.0.3945.79-1)
sid: resolved (fixed in 79.0.3945.79-1)
trixie: resolved (fixed in 79.
debian
CVE-2019-13677P4MEDIUMCVSS 6.5fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-13677 [MEDIUM] CVE-2019-13677: chromium - Insufficient policy enforcement in site isolation in Google Chrome prior to 77.0...
Insufficient policy enforcement in site isolation in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to bypass site isolation via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 78.0.3904.87-1)
bullseye: resolved (fixed in 78.0.3904.87-1)
forky: resolved (fixed in 78.0.3904.87-1)
sid: resolved (fixed in 78.0.3904.87-1)
trixie: resolve
debian
CVE-2020-6497P4MEDIUMCVSS 6.5fixed in chromium 83.0.4103.106-1 (bookworm)2020
CVE-2020-6497 [MEDIUM] CVE-2020-6497: chromium - Insufficient policy enforcement in Omnibox in Google Chrome on iOS prior to 83.0...
Insufficient policy enforcement in Omnibox in Google Chrome on iOS prior to 83.0.4103.88 allowed a remote attacker to perform domain spoofing via a crafted URI.
Scope: local
bookworm: resolved (fixed in 83.0.4103.106-1)
bullseye: resolved (fixed in 83.0.4103.106-1)
forky: resolved (fixed in 83.0.4103.106-1)
sid: resolved (fixed in 83.0.4103.106-1)
trixie: resolved
debian
CVE-2022-1129P4MEDIUMCVSS 6.5fixed in chromium 100.0.4896.60-1 (bookworm)2022
CVE-2022-1129 [MEDIUM] CVE-2022-1129: chromium - Inappropriate implementation in Full Screen Mode in Google Chrome on Android pri...
Inappropriate implementation in Full Screen Mode in Google Chrome on Android prior to 100.0.4896.60 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 100.0.4896.60-1)
bullseye: resolved (fixed in 100.0.4896.60-1~deb11u1)
forky: resolved (fixed in 100.0.4896.60-1)
sid: resolved
debian
CVE-2021-38021P4MEDIUMCVSS 6.5fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-38021 [MEDIUM] CVE-2021-38021: chromium - Inappropriate implementation in referrer in Google Chrome prior to 96.0.4664.45 ...
Inappropriate implementation in referrer in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 97.0.4692.71-0.1)
bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1)
forky: resolved (fixed in 97.0.4692.71-0.1)
sid: resolved (fixed in 97.0.4692.71-0.1)
debian
CVE-2021-37995P4MEDIUMCVSS 6.5fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-37995 [MEDIUM] CVE-2021-37995: chromium - Inappropriate implementation in WebApp Installer in Google Chrome prior to 95.0....
Inappropriate implementation in WebApp Installer in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to potentially overlay and spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 97.0.4692.71-0.1)
bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1)
forky: resolved (fixed in 97.0.4692.71-0
debian
CVE-2021-38018P4MEDIUMCVSS 6.5fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-38018 [MEDIUM] CVE-2021-38018: chromium - Inappropriate implementation in navigation in Google Chrome prior to 96.0.4664.4...
Inappropriate implementation in navigation in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 97.0.4692.71-0.1)
bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1)
forky: resolved (fixed in 97.0.4692.71-0.1)
sid: resolved (fixed in 97.0.4692.71-0.1)
trix
debian
CVE-2019-13697P4MEDIUMCVSS 6.5fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-13697 [MEDIUM] CVE-2019-13697: chromium - Insufficient policy enforcement in performance APIs in Google Chrome prior to 77...
Insufficient policy enforcement in performance APIs in Google Chrome prior to 77.0.3865.120 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 78.0.3904.87-1)
bullseye: resolved (fixed in 78.0.3904.87-1)
forky: resolved (fixed in 78.0.3904.87-1)
sid: resolved (fixed in 78.0.3904.87-1)
trixie: res
debian
CVE-2019-5869P4MEDIUMCVSS 6.5fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-5869 [MEDIUM] CVE-2019-5869: chromium - Use after free in Blink in Google Chrome prior to 76.0.3809.132 allowed a remote...
Use after free in Blink in Google Chrome prior to 76.0.3809.132 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 78.0.3904.87-1)
bullseye: resolved (fixed in 78.0.3904.87-1)
forky: resolved (fixed in 78.0.3904.87-1)
sid: resolved (fixed in 78.0.3904.87-1)
trixie: resolved (fixed in 7
debian
CVE-2020-16036P4MEDIUMCVSS 6.5fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-16036 [MEDIUM] CVE-2020-16036: chromium - Inappropriate implementation in cookies in Google Chrome prior to 87.0.4280.66 a...
Inappropriate implementation in cookies in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to bypass cookie restrictions via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (fixed in 87.0.4280.88-0.1)
trixie: reso
debian
CVE-2019-5842P4MEDIUMCVSS 6.5fixed in chromium 75.0.3770.90-1 (bookworm)2019
CVE-2019-5842 [MEDIUM] CVE-2019-5842: chromium - Use after free in Blink in Google Chrome prior to 75.0.3770.90 allowed a remote ...
Use after free in Blink in Google Chrome prior to 75.0.3770.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 75.0.3770.90-1)
bullseye: resolved (fixed in 75.0.3770.90-1)
forky: resolved (fixed in 75.0.3770.90-1)
sid: resolved (fixed in 75.0.3770.90-1)
trixie: resolved (fixed in 75
debian
CVE-2019-5862P4MEDIUMCVSS 6.5fixed in chromium 76.0.3809.87-1 (bookworm)2019
CVE-2019-5862 [MEDIUM] CVE-2019-5862: chromium - Insufficient data validation in AppCache in Google Chrome prior to 76.0.3809.87 ...
Insufficient data validation in AppCache in Google Chrome prior to 76.0.3809.87 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 76.0.3809.87-1)
bullseye: resolved (fixed in 76.0.3809.87-1)
forky: resolved (fixed in 76.0.3809.87-1)
sid: resolved (fixed in 7
debian
CVE-2019-5865P4MEDIUMCVSS 6.5fixed in chromium 76.0.3809.87-1 (bookworm)2019
CVE-2019-5865 [MEDIUM] CVE-2019-5865: chromium - Insufficient policy enforcement in navigations in Google Chrome prior to 76.0.38...
Insufficient policy enforcement in navigations in Google Chrome prior to 76.0.3809.87 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 76.0.3809.87-1)
bullseye: resolved (fixed in 76.0.3809.87-1)
forky: resolved (fixed in 76.0.3809.87-1)
sid: resolved (fixe
debian
CVE-2019-13765P4MEDIUMCVSS 6.5fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-13765 [MEDIUM] CVE-2019-13765: chromium - Use-after-free in content delivery manager in Google Chrome prior to 78.0.3904.7...
Use-after-free in content delivery manager in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 78.0.3904.87-1)
bullseye: resolved (fixed in 78.0.3904.87-1)
forky: resolved (fixed in 78.0.3904.87-1)
sid: resolved (fixed in 78.0.3904.87-1)
trixie:
debian
CVE-2019-13665P4MEDIUMCVSS 6.5fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-13665 [MEDIUM] CVE-2019-13665: chromium - Insufficient filtering in Blink in Google Chrome prior to 77.0.3865.75 allowed a...
Insufficient filtering in Blink in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to bypass multiple file download protection via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 78.0.3904.87-1)
bullseye: resolved (fixed in 78.0.3904.87-1)
forky: resolved (fixed in 78.0.3904.87-1)
sid: resolved (fixed in 78.0.3904.87-1)
trixie: resolv
debian
CVE-2020-6499P4MEDIUMCVSS 6.5fixed in chromium 80.0.3987.106-1 (bookworm)2020
CVE-2020-6499 [MEDIUM] CVE-2020-6499: chromium - Inappropriate implementation in AppCache in Google Chrome prior to 80.0.3987.87 ...
Inappropriate implementation in AppCache in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass AppCache security restrictions via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 80.0.3987.106-1)
bullseye: resolved (fixed in 80.0.3987.106-1)
forky: resolved (fixed in 80.0.3987.106-1)
sid: resolved (fixed in 80.0.3987.106-1)
trixie
debian
CVE-2020-6500P4MEDIUMCVSS 6.5fixed in chromium 80.0.3987.106-1 (bookworm)2020
CVE-2020-6500 [MEDIUM] CVE-2020-6500: chromium - Inappropriate implementation in interstitials in Google Chrome prior to 80.0.398...
Inappropriate implementation in interstitials in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 80.0.3987.106-1)
bullseye: resolved (fixed in 80.0.3987.106-1)
forky: resolved (fixed in 80.0.3987.106-1)
sid: resolved (fixed in 80.0.3987.10
debian