cbcvebase.

Debian Chromium vulnerabilities

2,134 known vulnerabilities affecting debian/chromium.

Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8

Vulnerabilities

Page 87 of 107
CVE-2019-5872P4MEDIUMCVSS 6.5fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-5872 [MEDIUM] CVE-2019-5872: chromium - Use after free in Mojo in Google Chrome prior to 77.0.3865.75 allowed a remote a... Use after free in Mojo in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 78.0.3904.87-1) bullseye: resolved (fixed in 78.0.3904.87-1) forky: resolved (fixed in 78.0.3904.87-1) sid: resolved (fixed in 78.0.3904.87-1) trixie: resolved (fixed in 78.
debian
CVE-2019-13766P4MEDIUMCVSS 6.5fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-13766 [MEDIUM] CVE-2019-13766: chromium - Use-after-free in accessibility in Google Chrome prior to 77.0.3865.75 allowed a... Use-after-free in accessibility in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 78.0.3904.87-1) bullseye: resolved (fixed in 78.0.3904.87-1) forky: resolved (fixed in 78.0.3904.87-1) sid: resolved (fixed in 78.0.3904.87-1) trixie: resolved (f
debian
CVE-2020-6501P4MEDIUMCVSS 6.5fixed in chromium 80.0.3987.106-1 (bookworm)2020
CVE-2020-6501 [MEDIUM] CVE-2020-6501: chromium - Insufficient policy enforcement in CSP in Google Chrome prior to 80.0.3987.87 al... Insufficient policy enforcement in CSP in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass content security policy via a crafted HTML page. Scope: local bookworm: resolved (fixed in 80.0.3987.106-1) bullseye: resolved (fixed in 80.0.3987.106-1) forky: resolved (fixed in 80.0.3987.106-1) sid: resolved (fixed in 80.0.3987.106-1) trixie: resolve
debian
CVE-2020-6502P4MEDIUMCVSS 6.5fixed in chromium 80.0.3987.106-1 (bookworm)2020
CVE-2020-6502 [MEDIUM] CVE-2020-6502: chromium - Incorrect implementation in permissions in Google Chrome prior to 80.0.3987.87 a... Incorrect implementation in permissions in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to spoof security UI via a crafted HTML page. Scope: local bookworm: resolved (fixed in 80.0.3987.106-1) bullseye: resolved (fixed in 80.0.3987.106-1) forky: resolved (fixed in 80.0.3987.106-1) sid: resolved (fixed in 80.0.3987.106-1) trixie: resolved (fixed in
debian
CVE-2019-13672P4MEDIUMCVSS 6.5fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-13672 [MEDIUM] CVE-2019-13672: chromium - Incorrect security UI in Omnibox in Google Chrome prior to 77.0.3865.75 allowed ... Incorrect security UI in Omnibox in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially spoof the contents of the Omnibox (URL bar) via a crafted HTML page on iOS. Scope: local bookworm: resolved (fixed in 78.0.3904.87-1) bullseye: resolved (fixed in 78.0.3904.87-1) forky: resolved (fixed in 78.0.3904.87-1) sid: resolved (fixed in 78.0.39
debian
CVE-2022-0455P4MEDIUMCVSS 6.5fixed in chromium 98.0.4758.80-1 (bookworm)2022
CVE-2022-0455 [MEDIUM] CVE-2022-0455: chromium - Inappropriate implementation in Full Screen Mode in Google Chrome on Android pri... Inappropriate implementation in Full Screen Mode in Google Chrome on Android prior to 98.0.4758.80 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. Scope: local bookworm: resolved (fixed in 98.0.4758.80-1) bullseye: resolved (fixed in 98.0.4758.80-1~deb11u1) forky: resolved (fixed in 98.0.4758.80-1) sid: resolved (fi
debian
CVE-2022-0309P4MEDIUMCVSS 6.5fixed in chromium 97.0.4692.99-1 (bookworm)2022
CVE-2022-0309 [MEDIUM] CVE-2022-0309: chromium - Inappropriate implementation in Autofill in Google Chrome prior to 97.0.4692.99 ... Inappropriate implementation in Autofill in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. Scope: local bookworm: resolved (fixed in 97.0.4692.99-1) bullseye: resolved (fixed in 97.0.4692.99-1~deb11u2) forky: resolved (fixed in 97.0.4692.99-1) sid: resolved (fixed in 97.0.4692.99-1) trixie: r
debian
CVE-2022-3057P4MEDIUMCVSS 6.5fixed in chromium 105.0.5195.52-1 (bookworm)2022
CVE-2022-3057 [MEDIUM] CVE-2022-3057: chromium - Inappropriate implementation in iframe Sandbox in Google Chrome prior to 105.0.5... Inappropriate implementation in iframe Sandbox in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to leak cross-origin data via a crafted HTML page. Scope: local bookworm: resolved (fixed in 105.0.5195.52-1) bullseye: resolved (fixed in 105.0.5195.52-1~deb11u1) forky: resolved (fixed in 105.0.5195.52-1) sid: resolved (fixed in 105.0.5195.52-1) trixie
debian
CVE-2022-3310P4MEDIUMCVSS 6.5fixed in chromium 106.0.5249.61-1 (bookworm)2022
CVE-2022-3310 [MEDIUM] CVE-2022-3310: chromium - Insufficient policy enforcement in custom tabs in Google Chrome on Android prior... Insufficient policy enforcement in custom tabs in Google Chrome on Android prior to 106.0.5249.62 allowed an attacker who convinced the user to install an application to bypass same origin policy via a crafted application. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 106.0.5249.61-1) bullseye: resolved (fixed in 106.0.5249.61-1~deb
debian
CVE-2022-1497P4MEDIUMCVSS 6.5fixed in chromium 101.0.4951.41-1 (bookworm)2022
CVE-2022-1497 [MEDIUM] CVE-2022-1497: chromium - Inappropriate implementation in Input in Google Chrome prior to 101.0.4951.41 al... Inappropriate implementation in Input in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to spoof the contents of cross-origin websites via a crafted HTML page. Scope: local bookworm: resolved (fixed in 101.0.4951.41-1) bullseye: resolved (fixed in 101.0.4951.41-1~deb11u1) forky: resolved (fixed in 101.0.4951.41-1) sid: resolved (fixed in 101.0.4951.
debian
CVE-2019-13664P4MEDIUMCVSS 6.5fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-13664 [MEDIUM] CVE-2019-13664: chromium - Insufficient policy enforcement in Blink in Google Chrome prior to 77.0.3865.75 ... Insufficient policy enforcement in Blink in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to bypass content security policy via a crafted HTML page. Scope: local bookworm: resolved (fixed in 78.0.3904.87-1) bullseye: resolved (fixed in 78.0.3904.87-1) forky: resolved (fixed in 78.0.3904.87-1) sid: resolved (fixed in 78.0.3904.87-1) trixie: resolve
debian
CVE-2026-0903P4MEDIUMCVSS 5.4fixed in chromium 144.0.7559.59-1~deb12u1 (bookworm)2026
CVE-2026-0903 [MEDIUM] CVE-2026-0903: chromium - Inappropriate implementation in Downloads in Google Chrome on Windows prior to 1... Inappropriate implementation in Downloads in Google Chrome on Windows prior to 144.0.7559.59 allowed a remote attacker to bypass dangerous file type protections via a malicious file. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 144.0.7559.59-1~deb12u1) bullseye: open forky: resolved (fixed in 144.0.7559.59-1) sid: resolved (fixed i
debian
CVE-2026-3939P4MEDIUMCVSS 5.3fixed in chromium 146.0.7680.71-1~deb12u1 (bookworm)2026
CVE-2026-3939 [MEDIUM] CVE-2026-3939: chromium - Insufficient policy enforcement in PDF in Google Chrome prior to 146.0.7680.71 a... Insufficient policy enforcement in PDF in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to bypass navigation restrictions via a crafted PDF file. (Chromium security severity: Low) Scope: local bookworm: resolved (fixed in 146.0.7680.71-1~deb12u1) bullseye: open forky: resolved (fixed in 146.0.7680.71-1) sid: resolved (fixed in 146.0.7680.71-1) trix
debian
CVE-2021-30594P4MEDIUMCVSS 6.8fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30594 [MEDIUM] CVE-2021-30594: chromium - Use after free in Page Info UI in Google Chrome prior to 92.0.4515.131 allowed a... Use after free in Page Info UI in Google Chrome prior to 92.0.4515.131 allowed a remote attacker to potentially exploit heap corruption via physical access to the device. Scope: local bookworm: resolved (fixed in 93.0.4577.82-1) bullseye: resolved (fixed in 93.0.4577.82-1) forky: resolved (fixed in 93.0.4577.82-1) sid: resolved (fixed in 93.0.4577.82-1) trixie: r
debian
CVE-2019-5794P4MEDIUMCVSS 6.5fixed in chromium 73.0.3683.75-1 (bookworm)2019
CVE-2019-5794 [MEDIUM] CVE-2019-5794: chromium - Incorrect handling of cancelled requests in Navigation in Google Chrome prior to... Incorrect handling of cancelled requests in Navigation in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to perform domain spoofing via a crafted HTML page. Scope: local bookworm: resolved (fixed in 73.0.3683.75-1) bullseye: resolved (fixed in 73.0.3683.75-1) forky: resolved (fixed in 73.0.3683.75-1) sid: resolved (fixed in 73.0.3683.75-1) trixie: re
debian
CVE-2019-5810P4MEDIUMCVSS 6.5fixed in chromium 74.0.3729.108-1 (bookworm)2019
CVE-2019-5810 [MEDIUM] CVE-2019-5810: chromium - Information leak in autofill in Google Chrome prior to 74.0.3729.108 allowed a r... Information leak in autofill in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. Scope: local bookworm: resolved (fixed in 74.0.3729.108-1) bullseye: resolved (fixed in 74.0.3729.108-1) forky: resolved (fixed in 74.0.3729.108-1) sid: resolved (fixed in 74.0.3729.1
debian
CVE-2019-5852P4MEDIUMCVSS 6.5fixed in chromium 76.0.3809.87-1 (bookworm)2019
CVE-2019-5852 [MEDIUM] CVE-2019-5852: chromium - Inappropriate implementation in JavaScript in Google Chrome prior to 76.0.3809.8... Inappropriate implementation in JavaScript in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. Scope: local bookworm: resolved (fixed in 76.0.3809.87-1) bullseye: resolved (fixed in 76.0.3809.87-1) forky: resolved (fixed in 76.0.3809.87-1) sid: resolved (fixed in 7
debian
CVE-2019-13748P4MEDIUMCVSS 6.5fixed in chromium 79.0.3945.79-1 (bookworm)2019
CVE-2019-13748 [MEDIUM] CVE-2019-13748: chromium - Insufficient policy enforcement in developer tools in Google Chrome prior to 79.... Insufficient policy enforcement in developer tools in Google Chrome prior to 79.0.3945.79 allowed a local attacker to obtain potentially sensitive information from process memory via a crafted HTML page. Scope: local bookworm: resolved (fixed in 79.0.3945.79-1) bullseye: resolved (fixed in 79.0.3945.79-1) forky: resolved (fixed in 79.0.3945.79-1) sid: resolved (f
debian
CVE-2019-5802P4MEDIUMCVSS 6.5fixed in chromium 73.0.3683.75-1 (bookworm)2019
CVE-2019-5802 [MEDIUM] CVE-2019-5802: chromium - Incorrect handling of download origins in Navigation in Google Chrome prior to 7... Incorrect handling of download origins in Navigation in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to perform domain spoofing via a crafted HTML page. Scope: local bookworm: resolved (fixed in 73.0.3683.75-1) bullseye: resolved (fixed in 73.0.3683.75-1) forky: resolved (fixed in 73.0.3683.75-1) sid: resolved (fixed in 73.0.3683.75-1) trixie: reso
debian
CVE-2020-6503P4MEDIUMCVSS 6.5fixed in chromium 74.0.3729.108-1 (bookworm)2020
CVE-2020-6503 [MEDIUM] CVE-2020-6503: chromium - Inappropriate implementation in accessibility in Google Chrome prior to 74.0.372... Inappropriate implementation in accessibility in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. Scope: local bookworm: resolved (fixed in 74.0.3729.108-1) bullseye: resolved (fixed in 74.0.3729.108-1) forky: resolved (fixed in 74.0.3729.108-1) sid: resolved (fix
debian
Debian Chromium vulnerabilities | cvebase