cbcvebase.

Debian Chromium vulnerabilities

2,134 known vulnerabilities affecting debian/chromium.

Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8

Vulnerabilities

Page 98 of 107
CVE-2022-4184P4MEDIUMCVSS 4.3fixed in chromium 108.0.5359.71-1 (bookworm)2022
CVE-2022-4184 [MEDIUM] CVE-2022-4184: chromium - Insufficient policy enforcement in Autofill in Google Chrome prior to 108.0.5359... Insufficient policy enforcement in Autofill in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to bypass autofill restrictions via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 108.0.5359.71-1) bullseye: resolved (fixed in 108.0.5359.71-2~deb11u1) forky: resolved (fixed in 108.0.5359.71-1) sid: re
debian
CVE-2023-4908P4MEDIUMCVSS 4.3fixed in chromium 117.0.5938.62-1~deb12u1 (bookworm)2023
CVE-2023-4908 [MEDIUM] CVE-2023-4908: chromium - Inappropriate implementation in Picture in Picture in Google Chrome prior to 117... Inappropriate implementation in Picture in Picture in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Low) Scope: local bookworm: resolved (fixed in 117.0.5938.62-1~deb12u1) bullseye: resolved (fixed in 117.0.5938.62-1~deb11u1) forky: resolved (fixed in 117.0.5938.62-1) sid: r
debian
CVE-2023-4909P4MEDIUMCVSS 4.3fixed in chromium 117.0.5938.62-1~deb12u1 (bookworm)2023
CVE-2023-4909 [MEDIUM] CVE-2023-4909: chromium - Inappropriate implementation in Interstitials in Google Chrome prior to 117.0.59... Inappropriate implementation in Interstitials in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Low) Scope: local bookworm: resolved (fixed in 117.0.5938.62-1~deb12u1) bullseye: resolved (fixed in 117.0.5938.62-1~deb11u1) forky: resolved (fixed in 117.0.5938.62-1) sid: re
debian
CVE-2023-5853P4MEDIUMCVSS 4.3fixed in chromium 119.0.6045.105-1~deb12u1 (bookworm)2023
CVE-2023-5853 [MEDIUM] CVE-2023-5853: chromium - Incorrect security UI in Downloads in Google Chrome prior to 119.0.6045.105 allo... Incorrect security UI in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 119.0.6045.105-1~deb12u1) bullseye: resolved (fixed in 119.0.6045.105-1~deb11u1) forky: resolved (fixed in 119.0.6045.105-1) sid: resolv
debian
CVE-2023-5858P4MEDIUMCVSS 4.3fixed in chromium 119.0.6045.105-1~deb12u1 (bookworm)2023
CVE-2023-5858 [MEDIUM] CVE-2023-5858: chromium - Inappropriate implementation in WebApp Provider in Google Chrome prior to 119.0.... Inappropriate implementation in WebApp Provider in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Low) Scope: local bookworm: resolved (fixed in 119.0.6045.105-1~deb12u1) bullseye: resolved (fixed in 119.0.6045.105-1~deb11u1) forky: resolved (fixed in 119.0.6045.105-1) s
debian
CVE-2023-3734P4MEDIUMCVSS 4.3fixed in chromium 115.0.5790.98-1~deb12u1 (bookworm)2023
CVE-2023-3734 [MEDIUM] CVE-2023-3734: chromium - Inappropriate implementation in Picture In Picture in Google Chrome prior to 115... Inappropriate implementation in Picture In Picture in Google Chrome prior to 115.0.5790.98 allowed a remote attacker to potentially spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 115.0.5790.98-1~deb12u1) bullseye: resolved (fixed in 115.0.5790.98-1~deb11u1) forky: r
debian
CVE-2022-3317P4MEDIUMCVSS 4.3fixed in chromium 106.0.5249.61-1 (bookworm)2022
CVE-2022-3317 [MEDIUM] CVE-2022-3317: chromium - Insufficient validation of untrusted input in Intents in Google Chrome on Androi... Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 106.0.5249.62 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low) Scope: local bookworm: resolved (fixed in 106.0.5249.61-1) bullseye: resolved (fixed in 106.0.5249.61-1~deb11u1) forky: resolved (fixed in 106.
debian
CVE-2023-5859P4MEDIUMCVSS 4.3fixed in chromium 119.0.6045.105-1~deb12u1 (bookworm)2023
CVE-2023-5859 [MEDIUM] CVE-2023-5859: chromium - Incorrect security UI in Picture In Picture in Google Chrome prior to 119.0.6045... Incorrect security UI in Picture In Picture in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to perform domain spoofing via a crafted local HTML page. (Chromium security severity: Low) Scope: local bookworm: resolved (fixed in 119.0.6045.105-1~deb12u1) bullseye: resolved (fixed in 119.0.6045.105-1~deb11u1) forky: resolved (fixed in 119.0.6045.105-
debian
CVE-2024-3843P4MEDIUMCVSS 4.3fixed in chromium 124.0.6367.60-1~deb12u1 (bookworm)2024
CVE-2024-3843 [MEDIUM] CVE-2024-3843: chromium - Insufficient data validation in Downloads in Google Chrome prior to 124.0.6367.6... Insufficient data validation in Downloads in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 124.0.6367.60-1~deb12u1) bullseye: open forky: resolved (fixed in 124.0.6367.60-1) sid: resolved (fixed in 124.0.6367.60-1) trixie:
debian
CVE-2023-3735P4MEDIUMCVSS 4.3fixed in chromium 115.0.5790.98-1~deb12u1 (bookworm)2023
CVE-2023-3735 [MEDIUM] CVE-2023-3735: chromium - Inappropriate implementation in Web API Permission Prompts in Google Chrome prio... Inappropriate implementation in Web API Permission Prompts in Google Chrome prior to 115.0.5790.98 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 115.0.5790.98-1~deb12u1) bullseye: resolved (fixed in 115.0.5790.98-1~deb11u1) forky: resolved (fixed in 115.0.57
debian
CVE-2023-3733P4MEDIUMCVSS 4.3fixed in chromium 115.0.5790.98-1~deb12u1 (bookworm)2023
CVE-2023-3733 [MEDIUM] CVE-2023-3733: chromium - Inappropriate implementation in WebApp Installs in Google Chrome prior to 115.0.... Inappropriate implementation in WebApp Installs in Google Chrome prior to 115.0.5790.98 allowed a remote attacker to potentially spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 115.0.5790.98-1~deb12u1) bullseye: resolved (fixed in 115.0.5790.98-1~deb11u1) forky: reso
debian
CVE-2022-1488P4MEDIUMCVSS 4.3fixed in chromium 101.0.4951.41-1 (bookworm)2022
CVE-2022-1488 [MEDIUM] CVE-2022-1488: chromium - Inappropriate implementation in Extensions API in Google Chrome prior to 101.0.4... Inappropriate implementation in Extensions API in Google Chrome prior to 101.0.4951.41 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension. Scope: local bookworm: resolved (fixed in 101.0.4951.41-1) bullseye: resolved (fixed in 101.0.4951.41-1~deb11u1) forky: resolved (fixed in 101.0.495
debian
CVE-2022-4188P4MEDIUMCVSS 4.3fixed in chromium 108.0.5359.71-1 (bookworm)2022
CVE-2022-4188 [MEDIUM] CVE-2022-4188: chromium - Insufficient validation of untrusted input in CORS in Google Chrome on Android p... Insufficient validation of untrusted input in CORS in Google Chrome on Android prior to 108.0.5359.71 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 108.0.5359.71-1) bullseye: resolved (fixed in 108.0.5359.71-2~deb11u1) forky: resolved (fixed in 108.0.535
debian
CVE-2022-1871P4MEDIUMCVSS 4.3fixed in chromium 102.0.5005.61-1 (bookworm)2022
CVE-2022-1871 [MEDIUM] CVE-2022-1871: chromium - Insufficient policy enforcement in File System API in Google Chrome prior to 102... Insufficient policy enforcement in File System API in Google Chrome prior to 102.0.5005.61 allowed an attacker who convinced a user to install a malicious extension to bypass file system policy via a crafted HTML page. Scope: local bookworm: resolved (fixed in 102.0.5005.61-1) bullseye: resolved (fixed in 102.0.5005.61-1~deb11u1) forky: resolved (fixed in 102.0.500
debian
CVE-2022-1872P4MEDIUMCVSS 4.3fixed in chromium 102.0.5005.61-1 (bookworm)2022
CVE-2022-1872 [MEDIUM] CVE-2022-1872: chromium - Insufficient policy enforcement in Extensions API in Google Chrome prior to 102.... Insufficient policy enforcement in Extensions API in Google Chrome prior to 102.0.5005.61 allowed an attacker who convinced a user to install a malicious extension to bypass downloads policy via a crafted HTML page. Scope: local bookworm: resolved (fixed in 102.0.5005.61-1) bullseye: resolved (fixed in 102.0.5005.61-1~deb11u1) forky: resolved (fixed in 102.0.5005.6
debian
CVE-2022-4183P4MEDIUMCVSS 4.3fixed in chromium 108.0.5359.71-1 (bookworm)2022
CVE-2022-4183 [MEDIUM] CVE-2022-4183: chromium - Insufficient policy enforcement in Popup Blocker in Google Chrome prior to 108.0... Insufficient policy enforcement in Popup Blocker in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 108.0.5359.71-1) bullseye: resolved (fixed in 108.0.5359.71-2~deb11u1) forky: resolved (fixed in 108.0.5359.71-1)
debian
CVE-2021-4321P4MEDIUMCVSS 4.3fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-4321 [MEDIUM] CVE-2021-4321: chromium - Policy bypass in Blink in Google Chrome prior to 91.0.4472.77 allowed a remote a... Policy bypass in Blink in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low) Scope: local bookworm: resolved (fixed in 97.0.4692.71-0.1) bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1) forky: resolved (fixed in 97.0.4692.71-0.1) sid: resolved (fixed in 97.
debian
CVE-2022-3316P4MEDIUMCVSS 4.3fixed in chromium 106.0.5249.61-1 (bookworm)2022
CVE-2022-3316 [MEDIUM] CVE-2022-3316: chromium - Insufficient validation of untrusted input in Safe Browsing in Google Chrome pri... Insufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to bypass security feature via a crafted HTML page. (Chromium security severity: Low) Scope: local bookworm: resolved (fixed in 106.0.5249.61-1) bullseye: resolved (fixed in 106.0.5249.61-1~deb11u1) forky: resolved (fixed in 106.0.5249.61-1)
debian
CVE-2023-3738P4MEDIUMCVSS 4.3fixed in chromium 115.0.5790.98-1~deb12u1 (bookworm)2023
CVE-2023-3738 [MEDIUM] CVE-2023-3738: chromium - Inappropriate implementation in Autofill in Google Chrome prior to 115.0.5790.98... Inappropriate implementation in Autofill in Google Chrome prior to 115.0.5790.98 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 115.0.5790.98-1~deb12u1) bullseye: resolved (fixed in 115.0.5790.98-1~deb11u1) forky: resolved (fixed in 115.0.5790.98-1) sid: reso
debian
CVE-2022-3661P4MEDIUMCVSS 4.3fixed in chromium 107.0.5304.68-1 (bookworm)2022
CVE-2022-3661 [MEDIUM] CVE-2022-3661: chromium - Insufficient data validation in Extensions in Google Chrome prior to 107.0.5304.... Insufficient data validation in Extensions in Google Chrome prior to 107.0.5304.62 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted Chrome extension. (Chromium security severity: Low) Scope: local bookworm: resolved (fixed in 107.0.5304.68-1) bullseye: resolved (fixed in 107.0.5304.68-1~deb11u1) forky: resol
debian
Debian Chromium vulnerabilities | cvebase