Debian Chromium vulnerabilities

2,176 known vulnerabilities affecting debian/chromium.

Total CVEs
2,176
CISA KEV
65
actively exploited
Public exploits
14
Exploited in wild
56
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW56UNKNOWN8

Vulnerabilities

Page 89 of 109
CVE-2020-16023HIGHCVSS 8.8fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-16023 [HIGH] CVE-2020-16023: chromium - Use after free in WebCodecs in Google Chrome prior to 87.0.4280.66 allowed a rem... Use after free in WebCodecs in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 87.0.4280.88-0.1) bullseye: resolved (fixed in 87.0.4280.88-0.1) forky: resolved (fixed in 87.0.4280.88-0.1) sid: resolved (fixed in 87.0.4280.88-0.1) trixie: resolved
debian
CVE-2020-6554HIGHCVSS 8.6fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-6554 [HIGH] CVE-2020-6554: chromium - Use after free in extensions in Google Chrome prior to 84.0.4147.125 allowed a r... Use after free in extensions in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially perform a sandbox escape via a crafted Chrome Extension. Scope: local bookworm: resolved (fixed in 87.0.4280.88-0.1) bullseye: resolved (fixed in 87.0.4280.88-0.1) forky: resolved (fixed in 87.0.4280.88-0.1) sid: resolved (fixed in 87.0.4280.88-0.1) trixie: r
debian
CVE-2020-16005HIGHCVSS 8.8fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-16005 [HIGH] CVE-2020-16005: chromium - Insufficient policy enforcement in ANGLE in Google Chrome prior to 86.0.4240.183... Insufficient policy enforcement in ANGLE in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 87.0.4280.88-0.1) bullseye: resolved (fixed in 87.0.4280.88-0.1) forky: resolved (fixed in 87.0.4280.88-0.1) sid: resolved (fixed in 87.0.4280.88-0.1) tri
debian
CVE-2020-6532HIGHCVSS 8.8fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-6532 [HIGH] CVE-2020-6532: chromium - Use after free in SCTP in Google Chrome prior to 84.0.4147.105 allowed a remote ... Use after free in SCTP in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 87.0.4280.88-0.1) bullseye: resolved (fixed in 87.0.4280.88-0.1) forky: resolved (fixed in 87.0.4280.88-0.1) sid: resolved (fixed in 87.0.4280.88-0.1) trixie: resolved (fixed
debian
CVE-2020-15980HIGHCVSS 7.8fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-15980 [HIGH] CVE-2020-15980: chromium - Insufficient policy enforcement in Intents in Google Chrome on Android prior to ... Insufficient policy enforcement in Intents in Google Chrome on Android prior to 86.0.4240.75 allowed a local attacker to bypass navigation restrictions via crafted Intents. Scope: local bookworm: resolved (fixed in 87.0.4280.88-0.1) bullseye: resolved (fixed in 87.0.4280.88-0.1) forky: resolved (fixed in 87.0.4280.88-0.1) sid: resolved (fixed in 87.0.4280.88-0.1) t
debian
CVE-2020-6455HIGHCVSS 8.8fixed in chromium 81.0.4044.92-1 (bookworm)2020
CVE-2020-6455 [HIGH] CVE-2020-6455: chromium - Out of bounds read in WebSQL in Google Chrome prior to 81.0.4044.92 allowed a re... Out of bounds read in WebSQL in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 81.0.4044.92-1) bullseye: resolved (fixed in 81.0.4044.92-1) forky: resolved (fixed in 81.0.4044.92-1) sid: resolved (fixed in 81.0.4044.92-1) trixie: resolved (fixed in
debian
CVE-2020-16021HIGHCVSS 7.5fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-16021 [HIGH] CVE-2020-16021: chromium - Race in image burner in Google Chrome on ChromeOS prior to 87.0.4280.66 allowed ... Race in image burner in Google Chrome on ChromeOS prior to 87.0.4280.66 allowed a remote attacker who had compromised the browser process to perform OS-level privilege escalation via a malicious file. Scope: local bookworm: resolved (fixed in 87.0.4280.88-0.1) bullseye: resolved (fixed in 87.0.4280.88-0.1) forky: resolved (fixed in 87.0.4280.88-0.1) sid: resolved (
debian
CVE-2020-6429HIGHCVSS 8.8fixed in chromium 80.0.3987.149-1 (bookworm)2020
CVE-2020-6429 [HIGH] CVE-2020-6429: chromium - Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote... Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 80.0.3987.149-1) bullseye: resolved (fixed in 80.0.3987.149-1) forky: resolved (fixed in 80.0.3987.149-1) sid: resolved (fixed in 80.0.3987.149-1) trixie: resolved (fixed in
debian
CVE-2020-6379HIGHCVSS 8.8fixed in chromium 79.0.3945.130-1 (bookworm)2020
CVE-2020-6379 [HIGH] CVE-2020-6379: chromium - Use after free in V8 in Google Chrome prior to 79.0.3945.130 allowed a remote at... Use after free in V8 in Google Chrome prior to 79.0.3945.130 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 79.0.3945.130-1) bullseye: resolved (fixed in 79.0.3945.130-1) forky: resolved (fixed in 79.0.3945.130-1) sid: resolved (fixed in 79.0.3945.130-1) trixie: resolved (fixed in 79
debian
CVE-2020-15969HIGHCVSS 8.8fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-15969 [HIGH] CVE-2020-15969: chromium - Use after free in WebRTC in Google Chrome prior to 86.0.4240.75 allowed a remote... Use after free in WebRTC in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 87.0.4280.88-0.1) bullseye: resolved (fixed in 87.0.4280.88-0.1) forky: resolved (fixed in 87.0.4280.88-0.1) sid: resolved (fixed in 87.0.4280.88-0.1) trixie: resolved (fi
debian
CVE-2020-15974HIGHCVSS 8.8fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-15974 [HIGH] CVE-2020-15974: chromium - Integer overflow in Blink in Google Chrome prior to 86.0.4240.75 allowed a remot... Integer overflow in Blink in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to bypass site isolation via a crafted HTML page. Scope: local bookworm: resolved (fixed in 87.0.4280.88-0.1) bullseye: resolved (fixed in 87.0.4280.88-0.1) forky: resolved (fixed in 87.0.4280.88-0.1) sid: resolved (fixed in 87.0.4280.88-0.1) trixie: resolved (fixed in 87.0.4
debian
CVE-2020-6390HIGHCVSS 8.8fixed in chromium 80.0.3987.106-1 (bookworm)2020
CVE-2020-6390 [HIGH] CVE-2020-6390: chromium - Out of bounds memory access in streams in Google Chrome prior to 80.0.3987.87 al... Out of bounds memory access in streams in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 80.0.3987.106-1) bullseye: resolved (fixed in 80.0.3987.106-1) forky: resolved (fixed in 80.0.3987.106-1) sid: resolved (fixed in 80.0.3987.106-1) trixie: reso
debian
CVE-2020-6389HIGHCVSS 8.8fixed in chromium 80.0.3987.106-1 (bookworm)2020
CVE-2020-6389 [HIGH] CVE-2020-6389: chromium - Out of bounds write in WebRTC in Google Chrome prior to 80.0.3987.87 allowed a r... Out of bounds write in WebRTC in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted video stream. Scope: local bookworm: resolved (fixed in 80.0.3987.106-1) bullseye: resolved (fixed in 80.0.3987.106-1) forky: resolved (fixed in 80.0.3987.106-1) sid: resolved (fixed in 80.0.3987.106-1) trixie: resolved (
debian
CVE-2020-16029HIGHCVSS 8.8fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-16029 [HIGH] CVE-2020-16029: chromium - Inappropriate implementation in PDFium in Google Chrome prior to 87.0.4280.66 al... Inappropriate implementation in PDFium in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to bypass navigation restrictions via a crafted PDF file. Scope: local bookworm: resolved (fixed in 87.0.4280.88-0.1) bullseye: resolved (fixed in 87.0.4280.88-0.1) forky: resolved (fixed in 87.0.4280.88-0.1) sid: resolved (fixed in 87.0.4280.88-0.1) trixie: reso
debian
CVE-2020-6542HIGHCVSS 8.8fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-6542 [HIGH] CVE-2020-6542: chromium - Use after free in ANGLE in Google Chrome prior to 84.0.4147.125 allowed a remote... Use after free in ANGLE in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 87.0.4280.88-0.1) bullseye: resolved (fixed in 87.0.4280.88-0.1) forky: resolved (fixed in 87.0.4280.88-0.1) sid: resolved (fixed in 87.0.4280.88-0.1) trixie: resolved (fixe
debian
CVE-2020-6534HIGHCVSS 8.8fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-6534 [HIGH] CVE-2020-6534: chromium - Heap buffer overflow in WebRTC in Google Chrome prior to 84.0.4147.89 allowed a ... Heap buffer overflow in WebRTC in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 87.0.4280.88-0.1) bullseye: resolved (fixed in 87.0.4280.88-0.1) forky: resolved (fixed in 87.0.4280.88-0.1) sid: resolved (fixed in 87.0.4280.88-0.1) trixie: resolved
debian
CVE-2020-15971HIGHCVSS 8.8fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-15971 [HIGH] CVE-2020-15971: chromium - Use after free in printing in Google Chrome prior to 86.0.4240.75 allowed a remo... Use after free in printing in Google Chrome prior to 86.0.4240.75 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. Scope: local bookworm: resolved (fixed in 87.0.4280.88-0.1) bullseye: resolved (fixed in 87.0.4280.88-0.1) forky: resolved (fixed in 87.0.4280.88-0.1) sid: resolved (fix
debian
CVE-2020-6450HIGHCVSS 8.8fixed in chromium 80.0.3987.162-1 (bookworm)2020
CVE-2020-6450 [HIGH] CVE-2020-6450: chromium - Use after free in WebAudio in Google Chrome prior to 80.0.3987.162 allowed a rem... Use after free in WebAudio in Google Chrome prior to 80.0.3987.162 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 80.0.3987.162-1) bullseye: resolved (fixed in 80.0.3987.162-1) forky: resolved (fixed in 80.0.3987.162-1) sid: resolved (fixed in 80.0.3987.162-1) trixie: resolved (fixed
debian
CVE-2020-6410HIGHCVSS 8.8fixed in chromium 80.0.3987.106-1 (bookworm)2020
CVE-2020-6410 [HIGH] CVE-2020-6410: chromium - Insufficient policy enforcement in navigation in Google Chrome prior to 80.0.398... Insufficient policy enforcement in navigation in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to confuse the user via a crafted domain name. Scope: local bookworm: resolved (fixed in 80.0.3987.106-1) bullseye: resolved (fixed in 80.0.3987.106-1) forky: resolved (fixed in 80.0.3987.106-1) sid: resolved (fixed in 80.0.3987.106-1) trixie: resolved (fixe
debian
CVE-2020-6456MEDIUMCVSS 6.5fixed in chromium 81.0.4044.92-1 (bookworm)2020
CVE-2020-6456 [MEDIUM] CVE-2020-6456: chromium - Insufficient validation of untrusted input in clipboard in Google Chrome prior t... Insufficient validation of untrusted input in clipboard in Google Chrome prior to 81.0.4044.92 allowed a local attacker to bypass site isolation via crafted clipboard contents. Scope: local bookworm: resolved (fixed in 81.0.4044.92-1) bullseye: resolved (fixed in 81.0.4044.92-1) forky: resolved (fixed in 81.0.4044.92-1) sid: resolved (fixed in 81.0.4044.92-1) trixi
debian