cbcvebase.

Debian Chromium vulnerabilities

2,134 known vulnerabilities affecting debian/chromium.

Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8

Vulnerabilities

Page 96 of 107
CVE-2019-13755P4MEDIUMCVSS 4.3fixed in chromium 79.0.3945.79-1 (bookworm)2019
CVE-2019-13755 [MEDIUM] CVE-2019-13755: chromium - Insufficient policy enforcement in extensions in Google Chrome prior to 79.0.394... Insufficient policy enforcement in extensions in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to disable extensions via a crafted HTML page. Scope: local bookworm: resolved (fixed in 79.0.3945.79-1) bullseye: resolved (fixed in 79.0.3945.79-1) forky: resolved (fixed in 79.0.3945.79-1) sid: resolved (fixed in 79.0.3945.79-1) trixie: resolved (fixe
debian
CVE-2019-13719P4MEDIUMCVSS 4.3fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-13719 [MEDIUM] CVE-2019-13719: chromium - Incorrect security UI in full screen mode in Google Chrome prior to 78.0.3904.70... Incorrect security UI in full screen mode in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to hide security UI via a crafted HTML page. Scope: local bookworm: resolved (fixed in 78.0.3904.87-1) bullseye: resolved (fixed in 78.0.3904.87-1) forky: resolved (fixed in 78.0.3904.87-1) sid: resolved (fixed in 78.0.3904.87-1) trixie: resolved (fixed in 7
debian
CVE-2021-37968P4MEDIUMCVSS 4.3fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-37968 [MEDIUM] CVE-2021-37968: chromium - Inappropriate implementation in Background Fetch API in Google Chrome prior to 9... Inappropriate implementation in Background Fetch API in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to leak cross-origin data via a crafted HTML page. Scope: local bookworm: resolved (fixed in 97.0.4692.71-0.1) bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1) forky: resolved (fixed in 97.0.4692.71-0.1) sid: resolved (fixed in 97.0.4692.71-
debian
CVE-2021-37971P4MEDIUMCVSS 4.3fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-37971 [MEDIUM] CVE-2021-37971: chromium - Incorrect security UI in Web Browser UI in Google Chrome prior to 94.0.4606.54 a... Incorrect security UI in Web Browser UI in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. Scope: local bookworm: resolved (fixed in 97.0.4692.71-0.1) bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1) forky: resolved (fixed in 97.0.4692.71-0.1) sid: resolved (fixed in 97.0.
debian
CVE-2022-0116P4MEDIUMCVSS 4.3fixed in chromium 97.0.4692.71-0.1 (bookworm)2022
CVE-2022-0116 [MEDIUM] CVE-2022-0116: chromium - Inappropriate implementation in Compositing in Google Chrome prior to 97.0.4692.... Inappropriate implementation in Compositing in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. Scope: local bookworm: resolved (fixed in 97.0.4692.71-0.1) bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1) forky: resolved (fixed in 97.0.4692.71-0.1) sid: resolved (fixed in 97.
debian
CVE-2023-1229P4MEDIUMCVSS 4.3fixed in chromium 111.0.5563.64-1 (bookworm)2023
CVE-2023-1229 [MEDIUM] CVE-2023-1229: chromium - Inappropriate implementation in Permission prompts in Google Chrome prior to 111... Inappropriate implementation in Permission prompts in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 111.0.5563.64-1) bullseye: resolved (fixed in 111.0.5563.64-1~deb11u1) forky: resolved (fixed in 111.0.5563.64-1
debian
CVE-2018-18355P4MEDIUMCVSS 4.3fixed in chromium 71.0.3578.80-1 (bookworm)2018
CVE-2018-18355 [MEDIUM] CVE-2018-18355: chromium - Incorrect handling of confusable characters in URL Formatter in Google Chrome pr... Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name. Scope: local bookworm: resolved (fixed in 71.0.3578.80-1) bullseye: resolved (fixed in 71.0.3578.80-1) forky: resolved (fixed in 71.0.3578.80-1) sid: resolved (fixed
debian
CVE-2018-18357P4MEDIUMCVSS 4.3fixed in chromium 71.0.3578.80-1 (bookworm)2018
CVE-2018-18357 [MEDIUM] CVE-2018-18357: chromium - Incorrect handling of confusable characters in URL Formatter in Google Chrome pr... Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name. Scope: local bookworm: resolved (fixed in 71.0.3578.80-1) bullseye: resolved (fixed in 71.0.3578.80-1) forky: resolved (fixed in 71.0.3578.80-1) sid: resolved (fixed
debian
CVE-2021-30537P4MEDIUMCVSS 4.3fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30537 [MEDIUM] CVE-2021-30537: chromium - Insufficient policy enforcement in cookies in Google Chrome prior to 91.0.4472.7... Insufficient policy enforcement in cookies in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass cookie policy via a crafted HTML page. Scope: local bookworm: resolved (fixed in 93.0.4577.82-1) bullseye: resolved (fixed in 93.0.4577.82-1) forky: resolved (fixed in 93.0.4577.82-1) sid: resolved (fixed in 93.0.4577.82-1) trixie: resolved (fixed
debian
CVE-2019-13761P4MEDIUMCVSS 4.3fixed in chromium 79.0.3945.79-1 (bookworm)2019
CVE-2019-13761 [MEDIUM] CVE-2019-13761: chromium - Incorrect security UI in Omnibox in Google Chrome prior to 79.0.3945.79 allowed ... Incorrect security UI in Omnibox in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name. Scope: local bookworm: resolved (fixed in 79.0.3945.79-1) bullseye: resolved (fixed in 79.0.3945.79-1) forky: resolved (fixed in 79.0.3945.79-1) sid: resolved (fixed in 79.0.3945.79-1) trixie: r
debian
CVE-2021-21228P4MEDIUMCVSS 4.3fixed in chromium 90.0.4430.93-1 (bookworm)2021
CVE-2021-21228 [MEDIUM] CVE-2021-21228: chromium - Insufficient policy enforcement in extensions in Google Chrome prior to 90.0.443... Insufficient policy enforcement in extensions in Google Chrome prior to 90.0.4430.93 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension. Scope: local bookworm: resolved (fixed in 90.0.4430.93-1) bullseye: resolved (fixed in 90.0.4430.93-1) forky: resolved (fixed in 90.0.4430.9
debian
CVE-2019-13710P4MEDIUMCVSS 4.3fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-13710 [MEDIUM] CVE-2019-13710: chromium - Insufficient validation of untrusted input in downloads in Google Chrome prior t... Insufficient validation of untrusted input in downloads in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to bypass download restrictions via a crafted HTML page. Scope: local bookworm: resolved (fixed in 78.0.3904.87-1) bullseye: resolved (fixed in 78.0.3904.87-1) forky: resolved (fixed in 78.0.3904.87-1) sid: resolved (fixed in 78.0.3904.87-1) tr
debian
CVE-2019-13704P4MEDIUMCVSS 4.3fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-13704 [MEDIUM] CVE-2019-13704: chromium - Insufficient policy enforcement in navigation in Google Chrome prior to 78.0.390... Insufficient policy enforcement in navigation in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to bypass content security policy via a crafted HTML page. Scope: local bookworm: resolved (fixed in 78.0.3904.87-1) bullseye: resolved (fixed in 78.0.3904.87-1) forky: resolved (fixed in 78.0.3904.87-1) sid: resolved (fixed in 78.0.3904.87-1) trixie: re
debian
CVE-2023-2937P4MEDIUMCVSS 4.3fixed in chromium 114.0.5735.90-2~deb12u1 (bookworm)2023
CVE-2023-2937 [MEDIUM] CVE-2023-2937: chromium - Inappropriate implementation in Picture In Picture in Google Chrome prior to 114... Inappropriate implementation in Picture In Picture in Google Chrome prior to 114.0.5735.90 allowed a remote attacker who had compromised the renderer process to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 114.0.5735.90-2~deb12u1) bullseye: resolved (fixed in 114.
debian
CVE-2023-2938P4MEDIUMCVSS 4.3fixed in chromium 114.0.5735.90-2~deb12u1 (bookworm)2023
CVE-2023-2938 [MEDIUM] CVE-2023-2938: chromium - Inappropriate implementation in Picture In Picture in Google Chrome prior to 114... Inappropriate implementation in Picture In Picture in Google Chrome prior to 114.0.5735.90 allowed a remote attacker who had compromised the renderer process to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 114.0.5735.90-2~deb12u1) bullseye: resolved (fixed in 114.
debian
CVE-2023-5851P4MEDIUMCVSS 4.3fixed in chromium 119.0.6045.105-1~deb12u1 (bookworm)2023
CVE-2023-5851 [MEDIUM] CVE-2023-5851: chromium - Inappropriate implementation in Downloads in Google Chrome prior to 119.0.6045.1... Inappropriate implementation in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 119.0.6045.105-1~deb12u1) bullseye: resolved (fixed in 119.0.6045.105-1~deb11u1) forky: resolved (fixed in 119.0.6045.105-1) sid:
debian
CVE-2023-6511P4MEDIUMCVSS 4.3fixed in chromium 120.0.6099.71-1~deb12u1 (bookworm)2023
CVE-2023-6511 [MEDIUM] CVE-2023-6511: chromium - Inappropriate implementation in Autofill in Google Chrome prior to 120.0.6099.62... Inappropriate implementation in Autofill in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to bypass Autofill restrictions via a crafted HTML page. (Chromium security severity: Low) Scope: local bookworm: resolved (fixed in 120.0.6099.71-1~deb12u1) bullseye: resolved (fixed in 120.0.6099.71-1~deb11u1) forky: resolved (fixed in 120.0.6099.71-1) sid:
debian
CVE-2019-13715P4MEDIUMCVSS 4.3fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-13715 [MEDIUM] CVE-2019-13715: chromium - Insufficient validation of untrusted input in Omnibox in Google Chrome prior to ... Insufficient validation of untrusted input in Omnibox in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name. Scope: local bookworm: resolved (fixed in 78.0.3904.87-1) bullseye: resolved (fixed in 78.0.3904.87-1) forky: resolved (fixed in 78.0.3904.87-1) sid: resolved (fixed in 78.0
debian
CVE-2022-2165P4MEDIUMCVSS 4.3fixed in chromium 103.0.5060.53-1 (bookworm)2022
CVE-2022-2165 [MEDIUM] CVE-2022-2165: chromium - Insufficient data validation in URL formatting in Google Chrome prior to 103.0.5... Insufficient data validation in URL formatting in Google Chrome prior to 103.0.5060.53 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name. Scope: local bookworm: resolved (fixed in 103.0.5060.53-1) bullseye: resolved (fixed in 103.0.5060.53-1~deb11u1) forky: resolved (fixed in 103.0.5060.53-1) sid: resolved (fixed in 1
debian
CVE-2023-2466P4MEDIUMCVSS 4.3fixed in chromium 113.0.5672.63-1 (bookworm)2023
CVE-2023-2466 [MEDIUM] CVE-2023-2466: chromium - Inappropriate implementation in Prompts in Google Chrome prior to 113.0.5672.63 ... Inappropriate implementation in Prompts in Google Chrome prior to 113.0.5672.63 allowed a remote attacker to spoof the contents of the security UI via a crafted HTML page. (Chromium security severity: Low) Scope: local bookworm: resolved (fixed in 113.0.5672.63-1) bullseye: resolved (fixed in 113.0.5672.63-1~deb11u1) forky: resolved (fixed in 113.0.5672.63-1) sid:
debian
Debian Chromium vulnerabilities | cvebase