Debian Chromium vulnerabilities
2,176 known vulnerabilities affecting debian/chromium.
Total CVEs
2,176
CISA KEV
65
actively exploited
Public exploits
14
Exploited in wild
56
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW56UNKNOWN8
Vulnerabilities
Page 90 of 109
CVE-2020-6495MEDIUMCVSS 6.5fixed in chromium 83.0.4103.106-1 (bookworm)2020
CVE-2020-6495 [MEDIUM] CVE-2020-6495: chromium - Insufficient policy enforcement in developer tools in Google Chrome prior to 83....
Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.97 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.
Scope: local
bookworm: resolved (fixed in 83.0.4103.106-1)
bullseye: resolved (fixed in 83.0.4103.106-1)
forky: resolved (fixed in
debian
CVE-2020-6405MEDIUMCVSS 6.5fixed in chromium 80.0.3987.106-1 (bookworm)2020
CVE-2020-6405 [MEDIUM] CVE-2020-6405: chromium - Out of bounds read in SQLite in Google Chrome prior to 80.0.3987.87 allowed a re...
Out of bounds read in SQLite in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 80.0.3987.106-1)
bullseye: resolved (fixed in 80.0.3987.106-1)
forky: resolved (fixed in 80.0.3987.106-1)
sid: resolved (fixed in 80.0.3987.10
debian
CVE-2020-6401MEDIUMCVSS 6.5fixed in chromium 80.0.3987.106-1 (bookworm)2020
CVE-2020-6401 [MEDIUM] CVE-2020-6401: chromium - Insufficient validation of untrusted input in Omnibox in Google Chrome prior to ...
Insufficient validation of untrusted input in Omnibox in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
Scope: local
bookworm: resolved (fixed in 80.0.3987.106-1)
bullseye: resolved (fixed in 80.0.3987.106-1)
forky: resolved (fixed in 80.0.3987.106-1)
sid: resolved (fixed in 80.
debian
CVE-2020-16036MEDIUMCVSS 6.5fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-16036 [MEDIUM] CVE-2020-16036: chromium - Inappropriate implementation in cookies in Google Chrome prior to 87.0.4280.66 a...
Inappropriate implementation in cookies in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to bypass cookie restrictions via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (fixed in 87.0.4280.88-0.1)
trixie: reso
debian
CVE-2020-6485MEDIUMCVSS 6.5fixed in chromium 83.0.4103.83-1 (bookworm)2020
CVE-2020-6485 [MEDIUM] CVE-2020-6485: chromium - Insufficient data validation in media router in Google Chrome prior to 83.0.4103...
Insufficient data validation in media router in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 83.0.4103.83-1)
bullseye: resolved (fixed in 83.0.4103.83-1)
forky: resolved (fixed in 83.0.4103.83-1)
sid: resolve
debian
CVE-2020-6431MEDIUMCVSS 4.3fixed in chromium 81.0.4044.92-1 (bookworm)2020
CVE-2020-6431 [MEDIUM] CVE-2020-6431: chromium - Insufficient policy enforcement in full screen in Google Chrome prior to 81.0.40...
Insufficient policy enforcement in full screen in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to spoof security UI via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 81.0.4044.92-1)
bullseye: resolved (fixed in 81.0.4044.92-1)
forky: resolved (fixed in 81.0.4044.92-1)
sid: resolved (fixed in 81.0.4044.92-1)
trixie: resolved (fixed
debian
CVE-2020-6486MEDIUMCVSS 6.5fixed in chromium 83.0.4103.83-1 (bookworm)2020
CVE-2020-6486 [MEDIUM] CVE-2020-6486: chromium - Insufficient policy enforcement in navigations in Google Chrome prior to 83.0.41...
Insufficient policy enforcement in navigations in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 83.0.4103.83-1)
bullseye: resolved (fixed in 83.0.4103.83-1)
forky: resolved (fixed in 83.0.4103.83-1)
sid: resolved (fixed in 83.0.4103.83-1)
trixie: res
debian
CVE-2020-6560MEDIUMCVSS 6.5fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-6560 [MEDIUM] CVE-2020-6560: chromium - Insufficient policy enforcement in autofill in Google Chrome prior to 85.0.4183....
Insufficient policy enforcement in autofill in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (fixed in 87.0.4280.88-0.1)
trixie: resolv
debian
CVE-2020-6426MEDIUMCVSS 6.5fixed in chromium 80.0.3987.149-1 (bookworm)2020
CVE-2020-6426 [MEDIUM] CVE-2020-6426: chromium - Inappropriate implementation in V8 in Google Chrome prior to 80.0.3987.149 allow...
Inappropriate implementation in V8 in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 80.0.3987.149-1)
bullseye: resolved (fixed in 80.0.3987.149-1)
forky: resolved (fixed in 80.0.3987.149-1)
sid: resolved (fixed in 80.0.3987.149-1)
trixie: resol
debian
CVE-2020-6482MEDIUMCVSS 6.5fixed in chromium 83.0.4103.83-1 (bookworm)2020
CVE-2020-6482 [MEDIUM] CVE-2020-6482: chromium - Insufficient policy enforcement in developer tools in Google Chrome prior to 83....
Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension.
Scope: local
bookworm: resolved (fixed in 83.0.4103.83-1)
bullseye: resolved (fixed in 83.0.4103.83-1)
forky: resolved (fixed in 83.0.410
debian
CVE-2020-6498MEDIUMCVSS 6.5fixed in chromium 83.0.4103.106-1 (bookworm)2020
CVE-2020-6498 [MEDIUM] CVE-2020-6498: chromium - Incorrect implementation in user interface in Google Chrome on iOS prior to 83.0...
Incorrect implementation in user interface in Google Chrome on iOS prior to 83.0.4103.88 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 83.0.4103.106-1)
bullseye: resolved (fixed in 83.0.4103.106-1)
forky: resolved (fixed in 83.0.4103.106-1)
sid: resolved (fixed in 83.0.4103.106-1)
trixie: res
debian
CVE-2020-16034MEDIUMCVSS 4.3fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-16034 [MEDIUM] CVE-2020-16034: chromium - Inappropriate implementation in WebRTC in Google Chrome prior to 87.0.4280.66 al...
Inappropriate implementation in WebRTC in Google Chrome prior to 87.0.4280.66 allowed a local attacker to bypass policy restrictions via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (fixed in 87.0.4280.88-0.1)
trixie: resolv
debian
CVE-2020-6488MEDIUMCVSS 4.3fixed in chromium 83.0.4103.83-1 (bookworm)2020
CVE-2020-6488 [MEDIUM] CVE-2020-6488: chromium - Insufficient policy enforcement in downloads in Google Chrome prior to 83.0.4103...
Insufficient policy enforcement in downloads in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 83.0.4103.83-1)
bullseye: resolved (fixed in 83.0.4103.83-1)
forky: resolved (fixed in 83.0.4103.83-1)
sid: resolved (fixed in 83.0.4103.83-1)
trixie: resol
debian
CVE-2020-6394MEDIUMCVSS 5.4fixed in chromium 80.0.3987.106-1 (bookworm)2020
CVE-2020-6394 [MEDIUM] CVE-2020-6394: chromium - Insufficient policy enforcement in Blink in Google Chrome prior to 80.0.3987.87 ...
Insufficient policy enforcement in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass content security policy via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 80.0.3987.106-1)
bullseye: resolved (fixed in 80.0.3987.106-1)
forky: resolved (fixed in 80.0.3987.106-1)
sid: resolved (fixed in 80.0.3987.106-1)
trixie: resol
debian
CVE-2020-6479MEDIUMCVSS 6.5fixed in chromium 83.0.4103.83-1 (bookworm)2020
CVE-2020-6479 [MEDIUM] CVE-2020-6479: chromium - Inappropriate implementation in sharing in Google Chrome prior to 83.0.4103.61 a...
Inappropriate implementation in sharing in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to spoof security UI via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 83.0.4103.83-1)
bullseye: resolved (fixed in 83.0.4103.83-1)
forky: resolved (fixed in 83.0.4103.83-1)
sid: resolved (fixed in 83.0.4103.83-1)
trixie: resolved (fixed in 83.0
debian
CVE-2020-6503MEDIUMCVSS 6.5fixed in chromium 74.0.3729.108-1 (bookworm)2020
CVE-2020-6503 [MEDIUM] CVE-2020-6503: chromium - Inappropriate implementation in accessibility in Google Chrome prior to 74.0.372...
Inappropriate implementation in accessibility in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 74.0.3729.108-1)
bullseye: resolved (fixed in 74.0.3729.108-1)
forky: resolved (fixed in 74.0.3729.108-1)
sid: resolved (fix
debian
CVE-2020-6483MEDIUMCVSS 6.5fixed in chromium 83.0.4103.83-1 (bookworm)2020
CVE-2020-6483 [MEDIUM] CVE-2020-6483: chromium - Insufficient policy enforcement in payments in Google Chrome prior to 83.0.4103....
Insufficient policy enforcement in payments in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 83.0.4103.83-1)
bullseye: resolved (fixed in 83.0.4103.83-1)
forky: resolved (fixed in 83.0.4103.83-1)
sid: resolved (fixed in 83.0.4103.83-1)
trixie: resolv
debian
CVE-2020-6395MEDIUMCVSS 6.5fixed in chromium 80.0.3987.106-1 (bookworm)2020
CVE-2020-6395 [MEDIUM] CVE-2020-6395: chromium - Out of bounds read in JavaScript in Google Chrome prior to 80.0.3987.87 allowed ...
Out of bounds read in JavaScript in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 80.0.3987.106-1)
bullseye: resolved (fixed in 80.0.3987.106-1)
forky: resolved (fixed in 80.0.3987.106-1)
sid: resolved (fixed in 80.0.398
debian
CVE-2020-6562MEDIUMCVSS 6.5fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-6562 [MEDIUM] CVE-2020-6562: chromium - Insufficient policy enforcement in Blink in Google Chrome prior to 85.0.4183.83 ...
Insufficient policy enforcement in Blink in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (fixed in 87.0.4280.88-0.1)
trixie: resolved
debian
CVE-2020-16031MEDIUMCVSS 4.3fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-16031 [MEDIUM] CVE-2020-16031: chromium - Insufficient data validation in UI in Google Chrome prior to 87.0.4280.66 allowe...
Insufficient data validation in UI in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (fixed in 87.0.4280.88-0.1)
debian