cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL496HIGH2798MEDIUM2448LOW79UNKNOWN10

Vulnerabilities

Page 109 of 292
CVE-2022-1312P3CRITICALCVSS 9.6fixed in 100.0.4896.88≥ unspecified, < 100.0.4896.882022-07-25
CVE-2022-1312 [CRITICAL] CWE-416 CVE-2022-1312: Use after free in storage in Google Chrome prior to 100.0.4896.88 allowed an attacker who convinced Use after free in storage in Google Chrome prior to 100.0.4896.88 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.
nvd
CVE-2017-5055P3HIGHCVSS 8.8fixed in 57.0.2987.1332017-10-27
CVE-2017-5055 [HIGH] CWE-125 CVE-2017-5055: A use after free in printing in Google Chrome prior to 57.0.2987.133 for Linux and Windows allowed a A use after free in printing in Google Chrome prior to 57.0.2987.133 for Linux and Windows allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
nvd
CVE-2020-6381P3HIGHCVSS 8.8fixed in 80.0.3987.87≥ unspecified, < 80.0.3987.872020-02-11
CVE-2020-6381 [HIGH] CWE-190 CVE-2020-6381: Integer overflow in JavaScript in Google Chrome on ChromeOS and Android prior to 80.0.3987.87 allowe Integer overflow in JavaScript in Google Chrome on ChromeOS and Android prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2017-5029P3HIGHCVSS 8.8≤ 57.0.2987.75≤ 57.0.2987.1002017-04-24
CVE-2017-5029 [HIGH] CWE-787 CVE-2017-5029: The xsltAddTextString function in transform.c in libxslt 1.1.29, as used in Blink in Google Chrome p The xsltAddTextString function in transform.c in libxslt 1.1.29, as used in Blink in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android, lacked a check for integer overflow during a size calculation, which allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page.
nvd
CVE-2015-1283P3MEDIUMCVSS 6.8≤ 43.0.2357.1342015-07-23
CVE-2015-1283 [MEDIUM] CWE-190 CVE-2015-1283: Multiple integer overflows in the XML_GetBuffer function in Expat through 2.1.0, as used in Google C Multiple integer overflows in the XML_GetBuffer function in Expat through 2.1.0, as used in Google Chrome before 44.0.2403.89 and other products, allow remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted XML data, a related issue to CVE-2015-2716.
nvd
CVE-2020-6455P3HIGHCVSS 8.8fixed in 81.0.4044.92≥ unspecified, < 81.0.4044.922020-04-13
CVE-2020-6455 [HIGH] CWE-125 CVE-2020-6455: Out of bounds read in WebSQL in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to pot Out of bounds read in WebSQL in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2017-5012P3HIGHCVSS 8.8≤ 55.0.2883.872017-02-17
CVE-2017-5012 [HIGH] CWE-119 CVE-2017-5012: A heap buffer overflow in V8 in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and A heap buffer overflow in V8 in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2019-5772P3HIGHCVSS 8.8fixed in 72.0.3626.81≥ unspecified, < 72.0.3626.812019-02-19
CVE-2019-5772 [HIGH] CWE-416 CVE-2019-5772: Sharing of objects over calls into JavaScript runtime in PDFium in Google Chrome prior to 72.0.3626. Sharing of objects over calls into JavaScript runtime in PDFium in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
nvd
CVE-2018-6141P3HIGHCVSS 8.8fixed in 67.0.3396.62≥ unspecified, < 67.0.3396.622019-01-09
CVE-2018-6141 [HIGH] CWE-125 CVE-2018-6141: Insufficient validation of an image filter in Skia in Google Chrome prior to 67.0.3396.62 allowed a Insufficient validation of an image filter in Skia in Google Chrome prior to 67.0.3396.62 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory read via a crafted HTML page.
nvd
CVE-2019-5816P3HIGHCVSS 8.8fixed in 74.0.3729.108≥ unspecified, < 74.0.3729.1082019-06-27
CVE-2019-5816 [HIGH] CWE-664 CVE-2019-5816: Process lifetime issue in Chrome in Google Chrome on Android prior to 74.0.3729.108 allowed a remote Process lifetime issue in Chrome in Google Chrome on Android prior to 74.0.3729.108 allowed a remote attacker to potentially persist an exploited process via a crafted HTML page.
nvd
CVE-2017-5127P3HIGHCVSS 8.8fixed in 62.0.3202.622018-02-07
CVE-2017-5127 [HIGH] CWE-416 CVE-2017-5127: Use after free in PDFium in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to potenti Use after free in PDFium in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
nvd
CVE-2018-6162P3HIGHCVSS 8.8fixed in 68.0.3440.75≥ unspecified, < 68.0.3440.752019-01-09
CVE-2018-6162 [HIGH] CWE-502 CVE-2018-6162: Improper deserialization in WebGL in Google Chrome on Mac prior to 68.0.3440.75 allowed a remote att Improper deserialization in WebGL in Google Chrome on Mac prior to 68.0.3440.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2017-15409P3HIGHCVSS 8.8fixed in 63.0.3239.842018-08-28
CVE-2017-15409 [HIGH] CWE-119 CVE-2017-15409: Heap buffer overflow in Skia in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to pot Heap buffer overflow in Skia in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2019-5769P3HIGHCVSS 8.8fixed in 72.0.3626.81≥ unspecified, < 72.0.3626.812019-02-19
CVE-2019-5769 [HIGH] CWE-20 CVE-2019-5769: Incorrect handling of invalid end character position when front rendering in Blink in Google Chrome Incorrect handling of invalid end character position when front rendering in Blink in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2018-17481P3HIGHCVSS 8.8fixed in 71.0.3578.98≥ unspecified, < 71.0.3578.982018-12-11
CVE-2018-17481 [HIGH] CWE-416 CVE-2018-17481: Incorrect object lifecycle handling in PDFium in Google Chrome prior to 71.0.3578.98 allowed a remot Incorrect object lifecycle handling in PDFium in Google Chrome prior to 71.0.3578.98 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
nvd
CVE-2018-6153P3HIGHCVSS 8.8fixed in 68.0.3440.75≥ unspecified, < 68.0.3440.752019-01-09
CVE-2018-6153 [HIGH] CWE-787 CVE-2018-6153: A precision error in Skia in Google Chrome prior to 68.0.3440.75 allowed a remote attacker who had c A precision error in Skia in Google Chrome prior to 68.0.3440.75 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory write via a crafted HTML page.
nvd
CVE-2017-15410P3HIGHCVSS 8.8fixed in 63.0.3239.842018-08-28
CVE-2017-15410 [HIGH] CWE-416 CVE-2017-15410: Use after free in PDFium in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to potenti Use after free in PDFium in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
nvd
CVE-2017-15411P3HIGHCVSS 8.8fixed in 63.0.3239.842018-08-28
CVE-2017-15411 [HIGH] CWE-416 CVE-2017-15411: Use after free in PDFium in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to potenti Use after free in PDFium in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
nvd
CVE-2016-5200P3HIGHCVSS 8.8≤ 54.0.2840.872017-01-19
CVE-2016-5200 [HIGH] CWE-119 CVE-2016-5200: V8 in Google Chrome prior to 54.0.2840.98 for Mac, and 54.0.2840.99 for Windows, and 54.0.2840.100 f V8 in Google Chrome prior to 54.0.2840.98 for Mac, and 54.0.2840.99 for Windows, and 54.0.2840.100 for Linux, and 55.0.2883.84 for Android incorrectly applied type rules, which allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2018-17465P3HIGHCVSS 8.8fixed in 70.0.3538.67≥ unspecified, < 70.0.3538.672018-11-14
CVE-2018-17465 [HIGH] CWE-416 CVE-2018-17465: Incorrect implementation of object trimming in V8 in Google Chrome prior to 70.0.3538.67 allowed a r Incorrect implementation of object trimming in V8 in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page.
nvd
Google Chrome vulnerabilities | cvebase