Debian Chromium vulnerabilities
2,134 known vulnerabilities affecting debian/chromium.
Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8
Vulnerabilities
Page 93 of 107
CVE-2020-6442P4MEDIUMCVSS 4.3fixed in chromium 81.0.4044.92-1 (bookworm)2020
CVE-2020-6442 [MEDIUM] CVE-2020-6442: chromium - Inappropriate implementation in cache in Google Chrome prior to 81.0.4044.92 all...
Inappropriate implementation in cache in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 81.0.4044.92-1)
bullseye: resolved (fixed in 81.0.4044.92-1)
forky: resolved (fixed in 81.0.4044.92-1)
sid: resolved (fixed in 81.0.4044.92-1)
trixie: resolved (fixed in 8
debian
CVE-2020-6396P4MEDIUMCVSS 4.3fixed in chromium 80.0.3987.106-1 (bookworm)2020
CVE-2020-6396 [MEDIUM] CVE-2020-6396: chromium - Inappropriate implementation in Skia in Google Chrome prior to 80.0.3987.87 allo...
Inappropriate implementation in Skia in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 80.0.3987.106-1)
bullseye: resolved (fixed in 80.0.3987.106-1)
forky: resolved (fixed in 80.0.3987.106-1)
sid: resolved (fixed in 80.0.3987.106-1)
trix
debian
CVE-2021-30596P4MEDIUMCVSS 4.3fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30596 [MEDIUM] CVE-2021-30596: chromium - Incorrect security UI in Navigation in Google Chrome on Android prior to 92.0.45...
Incorrect security UI in Navigation in Google Chrome on Android prior to 92.0.4515.131 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 93.0.4577.82-1)
bullseye: resolved (fixed in 93.0.4577.82-1)
forky: resolved (fixed in 93.0.4577.82-1)
sid: resolved (fixed in 93.0.4577.8
debian
CVE-2021-30587P4MEDIUMCVSS 4.3fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30587 [MEDIUM] CVE-2021-30587: chromium - Inappropriate implementation in Compositing in Google Chrome prior to 92.0.4515....
Inappropriate implementation in Compositing in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 93.0.4577.82-1)
bullseye: resolved (fixed in 93.0.4577.82-1)
forky: resolved (fixed in 93.0.4577.82-1)
sid: resolved (fixed in 93
debian
CVE-2020-6432P4MEDIUMCVSS 4.3fixed in chromium 81.0.4044.92-1 (bookworm)2020
CVE-2020-6432 [MEDIUM] CVE-2020-6432: chromium - Insufficient policy enforcement in navigations in Google Chrome prior to 81.0.40...
Insufficient policy enforcement in navigations in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 81.0.4044.92-1)
bullseye: resolved (fixed in 81.0.4044.92-1)
forky: resolved (fixed in 81.0.4044.92-1)
sid: resolved (fixed in 81.0.4044.92-1)
trixie: res
debian
CVE-2020-6433P4MEDIUMCVSS 4.3fixed in chromium 81.0.4044.92-1 (bookworm)2020
CVE-2020-6433 [MEDIUM] CVE-2020-6433: chromium - Insufficient policy enforcement in extensions in Google Chrome prior to 81.0.404...
Insufficient policy enforcement in extensions in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 81.0.4044.92-1)
bullseye: resolved (fixed in 81.0.4044.92-1)
forky: resolved (fixed in 81.0.4044.92-1)
sid: resolved (fixed in 81.0.4044.92-1)
trixie: reso
debian
CVE-2020-6435P4MEDIUMCVSS 4.3fixed in chromium 81.0.4044.92-1 (bookworm)2020
CVE-2020-6435 [MEDIUM] CVE-2020-6435: chromium - Insufficient policy enforcement in extensions in Google Chrome prior to 81.0.404...
Insufficient policy enforcement in extensions in Google Chrome prior to 81.0.4044.92 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 81.0.4044.92-1)
bullseye: resolved (fixed in 81.0.4044.92-1)
forky: resolved (fixed in 81.0.4044.92-1)
sid: resolv
debian
CVE-2020-6403P4MEDIUMCVSS 4.3fixed in chromium 80.0.3987.106-1 (bookworm)2020
CVE-2020-6403 [MEDIUM] CVE-2020-6403: chromium - Incorrect implementation in Omnibox in Google Chrome on iOS prior to 80.0.3987.8...
Incorrect implementation in Omnibox in Google Chrome on iOS prior to 80.0.3987.87 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 80.0.3987.106-1)
bullseye: resolved (fixed in 80.0.3987.106-1)
forky: resolved (fixed in 80.0.3987.106-1)
sid: resolved (fixed in 80.0.3987.106-1
debian
CVE-2019-13754P4MEDIUMCVSS 4.3fixed in chromium 79.0.3945.79-1 (bookworm)2019
CVE-2019-13754 [MEDIUM] CVE-2019-13754: chromium - Insufficient policy enforcement in extensions in Google Chrome prior to 79.0.394...
Insufficient policy enforcement in extensions in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 79.0.3945.79-1)
bullseye: resolved (fixed in 79.0.3945.79-1)
forky: resolved (fixed in 79.0.3945.79-1)
sid: resolved (fixed in 79.0.3945.79-1)
trixie: re
debian
CVE-2020-6431P4MEDIUMCVSS 4.3fixed in chromium 81.0.4044.92-1 (bookworm)2020
CVE-2020-6431 [MEDIUM] CVE-2020-6431: chromium - Insufficient policy enforcement in full screen in Google Chrome prior to 81.0.40...
Insufficient policy enforcement in full screen in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to spoof security UI via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 81.0.4044.92-1)
bullseye: resolved (fixed in 81.0.4044.92-1)
forky: resolved (fixed in 81.0.4044.92-1)
sid: resolved (fixed in 81.0.4044.92-1)
trixie: resolved (fixed
debian
CVE-2020-6488P4MEDIUMCVSS 4.3fixed in chromium 83.0.4103.83-1 (bookworm)2020
CVE-2020-6488 [MEDIUM] CVE-2020-6488: chromium - Insufficient policy enforcement in downloads in Google Chrome prior to 83.0.4103...
Insufficient policy enforcement in downloads in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 83.0.4103.83-1)
bullseye: resolved (fixed in 83.0.4103.83-1)
forky: resolved (fixed in 83.0.4103.83-1)
sid: resolved (fixed in 83.0.4103.83-1)
trixie: resol
debian
CVE-2020-6528P4MEDIUMCVSS 4.3fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-6528 [MEDIUM] CVE-2020-6528: chromium - Incorrect security UI in basic auth in Google Chrome on iOS prior to 84.0.4147.8...
Incorrect security UI in basic auth in Google Chrome on iOS prior to 84.0.4147.89 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (fixed in 87.0.4280.88
debian
CVE-2020-6392P4MEDIUMCVSS 4.3fixed in chromium 80.0.3987.106-1 (bookworm)2020
CVE-2020-6392 [MEDIUM] CVE-2020-6392: chromium - Insufficient policy enforcement in extensions in Google Chrome prior to 80.0.398...
Insufficient policy enforcement in extensions in Google Chrome prior to 80.0.3987.87 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension.
Scope: local
bookworm: resolved (fixed in 80.0.3987.106-1)
bullseye: resolved (fixed in 80.0.3987.106-1)
forky: resolved (fixed in 80.0.3987.1
debian
CVE-2021-21189P4MEDIUMCVSS 4.3fixed in chromium 89.0.4389.82-1 (bookworm)2021
CVE-2021-21189 [MEDIUM] CVE-2021-21189: chromium - Insufficient policy enforcement in payments in Google Chrome prior to 89.0.4389....
Insufficient policy enforcement in payments in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 89.0.4389.82-1)
bullseye: resolved (fixed in 89.0.4389.82-1)
forky: resolved (fixed in 89.0.4389.82-1)
sid: resolved (fixed in 89.0.4389.82-1)
trixie: reso
debian
CVE-2020-6490P4MEDIUMCVSS 4.3fixed in chromium 83.0.4103.83-1 (bookworm)2020
CVE-2020-6490 [MEDIUM] CVE-2020-6490: chromium - Insufficient data validation in loader in Google Chrome prior to 83.0.4103.61 al...
Insufficient data validation in loader in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had been able to write to disk to leak cross-origin data via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 83.0.4103.83-1)
bullseye: resolved (fixed in 83.0.4103.83-1)
forky: resolved (fixed in 83.0.4103.83-1)
sid: resolved (fixed in 83.0.410
debian
CVE-2021-21187P4MEDIUMCVSS 4.3fixed in chromium 89.0.4389.82-1 (bookworm)2021
CVE-2021-21187 [MEDIUM] CVE-2021-21187: chromium - Insufficient data validation in URL formatting in Google Chrome prior to 89.0.43...
Insufficient data validation in URL formatting in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
Scope: local
bookworm: resolved (fixed in 89.0.4389.82-1)
bullseye: resolved (fixed in 89.0.4389.82-1)
forky: resolved (fixed in 89.0.4389.82-1)
sid: resolved (fixed in 89.0.4389.8
debian
CVE-2020-6536P4MEDIUMCVSS 4.3fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-6536 [MEDIUM] CVE-2020-6536: chromium - Incorrect security UI in PWAs in Google Chrome prior to 84.0.4147.89 allowed a r...
Incorrect security UI in PWAs in Google Chrome prior to 84.0.4147.89 allowed a remote attacker who had persuaded the user to install a PWA to spoof the contents of the Omnibox (URL bar) via a crafted PWA.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolv
debian
CVE-2021-30532P4MEDIUMCVSS 4.3fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30532 [MEDIUM] CVE-2021-30532: chromium - Insufficient policy enforcement in Content Security Policy in Google Chrome prio...
Insufficient policy enforcement in Content Security Policy in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass content security policy via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 93.0.4577.82-1)
bullseye: resolved (fixed in 93.0.4577.82-1)
forky: resolved (fixed in 93.0.4577.82-1)
sid: resolved (fixed in 93.0.4577.82-
debian
CVE-2019-13757P4MEDIUMCVSS 4.3fixed in chromium 79.0.3945.79-1 (bookworm)2019
CVE-2019-13757 [MEDIUM] CVE-2019-13757: chromium - Incorrect security UI in Omnibox in Google Chrome prior to 79.0.3945.79 allowed ...
Incorrect security UI in Omnibox in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
Scope: local
bookworm: resolved (fixed in 79.0.3945.79-1)
bullseye: resolved (fixed in 79.0.3945.79-1)
forky: resolved (fixed in 79.0.3945.79-1)
sid: resolved (fixed in 79.0.3945.79-1)
trixie: r
debian
CVE-2021-21186P4MEDIUMCVSS 4.3fixed in chromium 89.0.4389.82-1 (bookworm)2021
CVE-2021-21186 [MEDIUM] CVE-2021-21186: chromium - Insufficient policy enforcement in QR scanning in Google Chrome on iOS prior to ...
Insufficient policy enforcement in QR scanning in Google Chrome on iOS prior to 89.0.4389.72 allowed an attacker who convinced the user to scan a QR code to bypass navigation restrictions via a crafted QR code.
Scope: local
bookworm: resolved (fixed in 89.0.4389.82-1)
bullseye: resolved (fixed in 89.0.4389.82-1)
forky: resolved (fixed in 89.0.4389.82-1)
sid: reso
debian