cbcvebase.

Debian Chromium vulnerabilities

2,134 known vulnerabilities affecting debian/chromium.

Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8

Vulnerabilities

Page 99 of 107
CVE-2022-4195P4MEDIUMCVSS 4.3fixed in chromium 108.0.5359.71-1 (bookworm)2022
CVE-2022-4195 [MEDIUM] CVE-2022-4195: chromium - Insufficient policy enforcement in Safe Browsing in Google Chrome prior to 108.0... Insufficient policy enforcement in Safe Browsing in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to bypass Safe Browsing warnings via a malicious file. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 108.0.5359.71-1) bullseye: resolved (fixed in 108.0.5359.71-2~deb11u1) forky: resolved (fixed in 108.0.5359.71-1) sid:
debian
CVE-2024-7003P4MEDIUMCVSS 4.3fixed in chromium 127.0.6533.88-1~deb12u1 (bookworm)2024
CVE-2024-7003 [MEDIUM] CVE-2024-7003: chromium - Inappropriate implementation in FedCM in Google Chrome prior to 127.0.6533.72 al... Inappropriate implementation in FedCM in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low) Scope: local bookworm: resolved (fixed in 127.0.6533.88-1~deb12u1) bullseye: open forky: resolved (fixed in 127.0.6533.88-1) s
debian
CVE-2019-5864P4MEDIUMCVSS 4.3fixed in chromium 76.0.3809.87-1 (bookworm)2019
CVE-2019-5864 [MEDIUM] CVE-2019-5864: chromium - Insufficient data validation in CORS in Google Chrome prior to 76.0.3809.87 allo... Insufficient data validation in CORS in Google Chrome prior to 76.0.3809.87 allowed an attacker who convinced a user to install a malicious extension to bypass content security policy via a crafted Chrome Extension. Scope: local bookworm: resolved (fixed in 76.0.3809.87-1) bullseye: resolved (fixed in 76.0.3809.87-1) forky: resolved (fixed in 76.0.3809.87-1) sid: r
debian
CVE-2022-3318P4MEDIUMCVSS 4.3fixed in chromium 106.0.5249.61-1 (bookworm)2022
CVE-2022-3318 [MEDIUM] CVE-2022-3318: chromium - Use after free in ChromeOS Notifications in Google Chrome on ChromeOS prior to 1... Use after free in ChromeOS Notifications in Google Chrome on ChromeOS prior to 106.0.5249.62 allowed a remote attacker who convinced a user to reboot Chrome OS to potentially exploit heap corruption via UI interaction. (Chromium security severity: Low) Scope: local bookworm: resolved (fixed in 106.0.5249.61-1) bullseye: resolved (fixed in 106.0.5249.61-1~deb11u1) f
debian
CVE-2024-7976P4MEDIUMCVSS 4.3fixed in chromium 128.0.6613.84-1~deb12u1 (bookworm)2024
CVE-2024-7976 [MEDIUM] CVE-2024-7976: chromium - Inappropriate implementation in FedCM in Google Chrome prior to 128.0.6613.84 al... Inappropriate implementation in FedCM in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 128.0.6613.84-1~deb12u1) bullseye: open forky: resolved (fixed in 128.0.6613.84-1) sid: resolved (fixed in 128.0.6613.84-1) trixie: reso
debian
CVE-2023-1224P4MEDIUMCVSS 4.3fixed in chromium 111.0.5563.64-1 (bookworm)2023
CVE-2023-1224 [MEDIUM] CVE-2023-1224: chromium - Insufficient policy enforcement in Web Payments API in Google Chrome prior to 11... Insufficient policy enforcement in Web Payments API in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 111.0.5563.64-1) bullseye: resolved (fixed in 111.0.5563.64-1~deb11u1) forky: resolved (fixed in 111.0.5563.64-
debian
CVE-2024-7001P4MEDIUMCVSS 4.3fixed in chromium 127.0.6533.88-1~deb12u1 (bookworm)2024
CVE-2024-7001 [MEDIUM] CVE-2024-7001: chromium - Inappropriate implementation in HTML in Google Chrome prior to 127.0.6533.72 all... Inappropriate implementation in HTML in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 127.0.6533.88-1~deb12u1) bullseye: open forky: resolved (fixed in 127.0.6533.88-1)
debian
CVE-2024-6999P4MEDIUMCVSS 4.3fixed in chromium 127.0.6533.88-1~deb12u1 (bookworm)2024
CVE-2024-6999 [MEDIUM] CVE-2024-6999: chromium - Inappropriate implementation in FedCM in Google Chrome prior to 127.0.6533.72 al... Inappropriate implementation in FedCM in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 127.0.6533.88-1~deb12u1) bullseye: open forky: resolved (fixed in 127.0.6533.88-1
debian
CVE-2024-8906P4MEDIUMCVSS 4.3fixed in chromium 129.0.6668.58-1~deb12u1 (bookworm)2024
CVE-2024-8906 [MEDIUM] CVE-2024-8906: chromium - Incorrect security UI in Downloads in Google Chrome prior to 129.0.6668.58 allow... Incorrect security UI in Downloads in Google Chrome prior to 129.0.6668.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 129.0.6668.58-1~deb12u1) bullseye: open forky: resolved (fixed in 129.0.6668.58-1) s
debian
CVE-2024-8034P4MEDIUMCVSS 4.3fixed in chromium 128.0.6613.84-1~deb12u1 (bookworm)2024
CVE-2024-8034 [MEDIUM] CVE-2024-8034: chromium - Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to... Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to 128.0.6613.84 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low) Scope: local bookworm: resolved (fixed in 128.0.6613.84-1~deb12u1) bullseye: open forky: resolved (fixed in 128.0.6613.84-1) sid: resolved (fixed in 128.0.6613.84-1
debian
CVE-2024-0809P4MEDIUMCVSS 4.3fixed in chromium 121.0.6167.85-1~deb12u1 (bookworm)2024
CVE-2024-0809 [MEDIUM] CVE-2024-0809: chromium - Inappropriate implementation in Autofill in Google Chrome prior to 121.0.6167.85... Inappropriate implementation in Autofill in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to bypass Autofill restrictions via a crafted HTML page. (Chromium security severity: Low) Scope: local bookworm: resolved (fixed in 121.0.6167.85-1~deb12u1) bullseye: open forky: resolved (fixed in 121.0.6167.85-1) sid: resolved (fixed in 121.0.6167.85-1) tri
debian
CVE-2024-7022P4MEDIUMCVSS 4.3fixed in chromium 123.0.6312.86-1~deb12u1 (bookworm)2024
CVE-2024-7022 [MEDIUM] CVE-2024-7022: chromium - Uninitialized Use in V8 in Google Chrome prior to 123.0.6312.58 allowed a remote... Uninitialized Use in V8 in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 123.0.6312.86-1~deb12u1) bullseye: open forky: resolved (fixed in 123.0.6312.58-1) sid: resolved (fixed in 123.0.6312.58-1) trixie: re
debian
CVE-2024-11111P4MEDIUMCVSS 4.3fixed in chromium 131.0.6778.85-1~deb12u1 (bookworm)2024
CVE-2024-11111 [MEDIUM] CVE-2024-11111: chromium - Inappropriate implementation in Autofill in Google Chrome prior to 131.0.6778.69... Inappropriate implementation in Autofill in Google Chrome prior to 131.0.6778.69 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 131.0.6778.85-1~deb12u1) bullseye: open forky: resolved (fixed in 131.0.6778
debian
CVE-2024-8035P4MEDIUMCVSS 4.3fixed in chromium 128.0.6613.84-1~deb12u1 (bookworm)2024
CVE-2024-8035 [MEDIUM] CVE-2024-8035: chromium - Inappropriate implementation in Extensions in Google Chrome on Windows prior to ... Inappropriate implementation in Extensions in Google Chrome on Windows prior to 128.0.6613.84 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low) Scope: local bookworm: resolved (fixed in 128.0.6613.84-1~deb12u1) bullseye: open forky: resolved (fixed in 128.0.6613.84-1) sid: resolved (fixed in 128.0.6613.84-1)
debian
CVE-2024-11116P4MEDIUMCVSS 4.3fixed in chromium 131.0.6778.85-1~deb12u1 (bookworm)2024
CVE-2024-11116 [MEDIUM] CVE-2024-11116: chromium - Inappropriate implementation in Blink in Google Chrome prior to 131.0.6778.69 al... Inappropriate implementation in Blink in Google Chrome prior to 131.0.6778.69 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 131.0.6778.85-1~deb12u1) bullseye: open forky: resolved (fixed in 131.0.6778.85
debian
CVE-2025-1922P4MEDIUMCVSS 4.3fixed in chromium 134.0.6998.35-1~deb12u1 (bookworm)2025
CVE-2025-1922 [MEDIUM] CVE-2025-1922: chromium - Inappropriate implementation in Selection in Google Chrome on Android prior to 1... Inappropriate implementation in Selection in Google Chrome on Android prior to 134.0.6998.35 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low) Scope: local bookworm: resolved (fixed in 134.0.6998.35-1~deb12u1) bullseye: open forky: resolved (fixed in 134
debian
CVE-2025-0446P4MEDIUMCVSS 4.3fixed in chromium 132.0.6834.83-1~deb12u1 (bookworm)2025
CVE-2025-0446 [MEDIUM] CVE-2025-0446: chromium - Inappropriate implementation in Extensions in Google Chrome prior to 132.0.6834.... Inappropriate implementation in Extensions in Google Chrome prior to 132.0.6834.83 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Low) Scope: local bookworm: resolved (fixed in 132.0.6834.83-1~deb12u1) bullseye: open forky: resolved (fixed in 132.0.
debian
CVE-2024-9958P4MEDIUMCVSS 4.3fixed in chromium 130.0.6723.58-1~deb12u1 (bookworm)2024
CVE-2024-9958 [MEDIUM] CVE-2024-9958: chromium - Inappropriate implementation in PictureInPicture in Google Chrome prior to 130.0... Inappropriate implementation in PictureInPicture in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 130.0.6723.58-1~deb12u1) bullseye: open forky: resolved (fixed in 130.0.6723.58-1) sid: resolved (fixed in 130.0.6723.58-1) t
debian
CVE-2024-9962P4MEDIUMCVSS 4.3fixed in chromium 130.0.6723.58-1~deb12u1 (bookworm)2024
CVE-2024-9962 [MEDIUM] CVE-2024-9962: chromium - Inappropriate implementation in Permissions in Google Chrome prior to 130.0.6723... Inappropriate implementation in Permissions in Google Chrome prior to 130.0.6723.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 130.0.6723.58-1~deb12u1) bullseye: open forky: resolved (fixed in 130.0.672
debian
CVE-2024-7019P4MEDIUMCVSS 4.3fixed in chromium 124.0.6367.60-1~deb12u1 (bookworm)2024
CVE-2024-7019 [MEDIUM] CVE-2024-7019: chromium - Inappropriate implementation in UI in Google Chrome prior to 124.0.6367.60 allow... Inappropriate implementation in UI in Google Chrome prior to 124.0.6367.60 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 124.0.6367.60-1~deb12u1) bullseye: open forky: resolved (fixed in 124.0.6367.60-1) s
debian
Debian Chromium vulnerabilities | cvebase