Debian Chromium vulnerabilities
2,134 known vulnerabilities affecting debian/chromium.
Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8
Vulnerabilities
Page 96 of 107
CVE-2019-13755P4MEDIUMCVSS 4.3fixed in chromium 79.0.3945.79-1 (bookworm)2019
CVE-2019-13755 [MEDIUM] CVE-2019-13755: chromium - Insufficient policy enforcement in extensions in Google Chrome prior to 79.0.394...
Insufficient policy enforcement in extensions in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to disable extensions via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 79.0.3945.79-1)
bullseye: resolved (fixed in 79.0.3945.79-1)
forky: resolved (fixed in 79.0.3945.79-1)
sid: resolved (fixed in 79.0.3945.79-1)
trixie: resolved (fixe
debian
CVE-2019-13719P4MEDIUMCVSS 4.3fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-13719 [MEDIUM] CVE-2019-13719: chromium - Incorrect security UI in full screen mode in Google Chrome prior to 78.0.3904.70...
Incorrect security UI in full screen mode in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to hide security UI via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 78.0.3904.87-1)
bullseye: resolved (fixed in 78.0.3904.87-1)
forky: resolved (fixed in 78.0.3904.87-1)
sid: resolved (fixed in 78.0.3904.87-1)
trixie: resolved (fixed in 7
debian
CVE-2021-37968P4MEDIUMCVSS 4.3fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-37968 [MEDIUM] CVE-2021-37968: chromium - Inappropriate implementation in Background Fetch API in Google Chrome prior to 9...
Inappropriate implementation in Background Fetch API in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 97.0.4692.71-0.1)
bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1)
forky: resolved (fixed in 97.0.4692.71-0.1)
sid: resolved (fixed in 97.0.4692.71-
debian
CVE-2021-37971P4MEDIUMCVSS 4.3fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-37971 [MEDIUM] CVE-2021-37971: chromium - Incorrect security UI in Web Browser UI in Google Chrome prior to 94.0.4606.54 a...
Incorrect security UI in Web Browser UI in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 97.0.4692.71-0.1)
bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1)
forky: resolved (fixed in 97.0.4692.71-0.1)
sid: resolved (fixed in 97.0.
debian
CVE-2022-0116P4MEDIUMCVSS 4.3fixed in chromium 97.0.4692.71-0.1 (bookworm)2022
CVE-2022-0116 [MEDIUM] CVE-2022-0116: chromium - Inappropriate implementation in Compositing in Google Chrome prior to 97.0.4692....
Inappropriate implementation in Compositing in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 97.0.4692.71-0.1)
bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1)
forky: resolved (fixed in 97.0.4692.71-0.1)
sid: resolved (fixed in 97.
debian
CVE-2023-1229P4MEDIUMCVSS 4.3fixed in chromium 111.0.5563.64-1 (bookworm)2023
CVE-2023-1229 [MEDIUM] CVE-2023-1229: chromium - Inappropriate implementation in Permission prompts in Google Chrome prior to 111...
Inappropriate implementation in Permission prompts in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 111.0.5563.64-1)
bullseye: resolved (fixed in 111.0.5563.64-1~deb11u1)
forky: resolved (fixed in 111.0.5563.64-1
debian
CVE-2018-18355P4MEDIUMCVSS 4.3fixed in chromium 71.0.3578.80-1 (bookworm)2018
CVE-2018-18355 [MEDIUM] CVE-2018-18355: chromium - Incorrect handling of confusable characters in URL Formatter in Google Chrome pr...
Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.
Scope: local
bookworm: resolved (fixed in 71.0.3578.80-1)
bullseye: resolved (fixed in 71.0.3578.80-1)
forky: resolved (fixed in 71.0.3578.80-1)
sid: resolved (fixed
debian
CVE-2018-18357P4MEDIUMCVSS 4.3fixed in chromium 71.0.3578.80-1 (bookworm)2018
CVE-2018-18357 [MEDIUM] CVE-2018-18357: chromium - Incorrect handling of confusable characters in URL Formatter in Google Chrome pr...
Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.
Scope: local
bookworm: resolved (fixed in 71.0.3578.80-1)
bullseye: resolved (fixed in 71.0.3578.80-1)
forky: resolved (fixed in 71.0.3578.80-1)
sid: resolved (fixed
debian
CVE-2021-30537P4MEDIUMCVSS 4.3fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30537 [MEDIUM] CVE-2021-30537: chromium - Insufficient policy enforcement in cookies in Google Chrome prior to 91.0.4472.7...
Insufficient policy enforcement in cookies in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass cookie policy via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 93.0.4577.82-1)
bullseye: resolved (fixed in 93.0.4577.82-1)
forky: resolved (fixed in 93.0.4577.82-1)
sid: resolved (fixed in 93.0.4577.82-1)
trixie: resolved (fixed
debian
CVE-2019-13761P4MEDIUMCVSS 4.3fixed in chromium 79.0.3945.79-1 (bookworm)2019
CVE-2019-13761 [MEDIUM] CVE-2019-13761: chromium - Incorrect security UI in Omnibox in Google Chrome prior to 79.0.3945.79 allowed ...
Incorrect security UI in Omnibox in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
Scope: local
bookworm: resolved (fixed in 79.0.3945.79-1)
bullseye: resolved (fixed in 79.0.3945.79-1)
forky: resolved (fixed in 79.0.3945.79-1)
sid: resolved (fixed in 79.0.3945.79-1)
trixie: r
debian
CVE-2021-21228P4MEDIUMCVSS 4.3fixed in chromium 90.0.4430.93-1 (bookworm)2021
CVE-2021-21228 [MEDIUM] CVE-2021-21228: chromium - Insufficient policy enforcement in extensions in Google Chrome prior to 90.0.443...
Insufficient policy enforcement in extensions in Google Chrome prior to 90.0.4430.93 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension.
Scope: local
bookworm: resolved (fixed in 90.0.4430.93-1)
bullseye: resolved (fixed in 90.0.4430.93-1)
forky: resolved (fixed in 90.0.4430.9
debian
CVE-2019-13710P4MEDIUMCVSS 4.3fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-13710 [MEDIUM] CVE-2019-13710: chromium - Insufficient validation of untrusted input in downloads in Google Chrome prior t...
Insufficient validation of untrusted input in downloads in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to bypass download restrictions via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 78.0.3904.87-1)
bullseye: resolved (fixed in 78.0.3904.87-1)
forky: resolved (fixed in 78.0.3904.87-1)
sid: resolved (fixed in 78.0.3904.87-1)
tr
debian
CVE-2019-13704P4MEDIUMCVSS 4.3fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-13704 [MEDIUM] CVE-2019-13704: chromium - Insufficient policy enforcement in navigation in Google Chrome prior to 78.0.390...
Insufficient policy enforcement in navigation in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to bypass content security policy via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 78.0.3904.87-1)
bullseye: resolved (fixed in 78.0.3904.87-1)
forky: resolved (fixed in 78.0.3904.87-1)
sid: resolved (fixed in 78.0.3904.87-1)
trixie: re
debian
CVE-2023-2937P4MEDIUMCVSS 4.3fixed in chromium 114.0.5735.90-2~deb12u1 (bookworm)2023
CVE-2023-2937 [MEDIUM] CVE-2023-2937: chromium - Inappropriate implementation in Picture In Picture in Google Chrome prior to 114...
Inappropriate implementation in Picture In Picture in Google Chrome prior to 114.0.5735.90 allowed a remote attacker who had compromised the renderer process to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 114.0.5735.90-2~deb12u1)
bullseye: resolved (fixed in 114.
debian
CVE-2023-2938P4MEDIUMCVSS 4.3fixed in chromium 114.0.5735.90-2~deb12u1 (bookworm)2023
CVE-2023-2938 [MEDIUM] CVE-2023-2938: chromium - Inappropriate implementation in Picture In Picture in Google Chrome prior to 114...
Inappropriate implementation in Picture In Picture in Google Chrome prior to 114.0.5735.90 allowed a remote attacker who had compromised the renderer process to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 114.0.5735.90-2~deb12u1)
bullseye: resolved (fixed in 114.
debian
CVE-2023-5851P4MEDIUMCVSS 4.3fixed in chromium 119.0.6045.105-1~deb12u1 (bookworm)2023
CVE-2023-5851 [MEDIUM] CVE-2023-5851: chromium - Inappropriate implementation in Downloads in Google Chrome prior to 119.0.6045.1...
Inappropriate implementation in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 119.0.6045.105-1~deb12u1)
bullseye: resolved (fixed in 119.0.6045.105-1~deb11u1)
forky: resolved (fixed in 119.0.6045.105-1)
sid:
debian
CVE-2023-6511P4MEDIUMCVSS 4.3fixed in chromium 120.0.6099.71-1~deb12u1 (bookworm)2023
CVE-2023-6511 [MEDIUM] CVE-2023-6511: chromium - Inappropriate implementation in Autofill in Google Chrome prior to 120.0.6099.62...
Inappropriate implementation in Autofill in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to bypass Autofill restrictions via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 120.0.6099.71-1~deb12u1)
bullseye: resolved (fixed in 120.0.6099.71-1~deb11u1)
forky: resolved (fixed in 120.0.6099.71-1)
sid:
debian
CVE-2019-13715P4MEDIUMCVSS 4.3fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-13715 [MEDIUM] CVE-2019-13715: chromium - Insufficient validation of untrusted input in Omnibox in Google Chrome prior to ...
Insufficient validation of untrusted input in Omnibox in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
Scope: local
bookworm: resolved (fixed in 78.0.3904.87-1)
bullseye: resolved (fixed in 78.0.3904.87-1)
forky: resolved (fixed in 78.0.3904.87-1)
sid: resolved (fixed in 78.0
debian
CVE-2022-2165P4MEDIUMCVSS 4.3fixed in chromium 103.0.5060.53-1 (bookworm)2022
CVE-2022-2165 [MEDIUM] CVE-2022-2165: chromium - Insufficient data validation in URL formatting in Google Chrome prior to 103.0.5...
Insufficient data validation in URL formatting in Google Chrome prior to 103.0.5060.53 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
Scope: local
bookworm: resolved (fixed in 103.0.5060.53-1)
bullseye: resolved (fixed in 103.0.5060.53-1~deb11u1)
forky: resolved (fixed in 103.0.5060.53-1)
sid: resolved (fixed in 1
debian
CVE-2023-2466P4MEDIUMCVSS 4.3fixed in chromium 113.0.5672.63-1 (bookworm)2023
CVE-2023-2466 [MEDIUM] CVE-2023-2466: chromium - Inappropriate implementation in Prompts in Google Chrome prior to 113.0.5672.63 ...
Inappropriate implementation in Prompts in Google Chrome prior to 113.0.5672.63 allowed a remote attacker to spoof the contents of the security UI via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 113.0.5672.63-1)
bullseye: resolved (fixed in 113.0.5672.63-1~deb11u1)
forky: resolved (fixed in 113.0.5672.63-1)
sid:
debian