cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2

Vulnerabilities

Page 133 of 292
CVE-2015-6769P3HIGHCVSS 7.5≤ 46.0.2490.862015-12-06
CVE-2015-6769 [HIGH] CWE-264 CVE-2015-6769: The provisional-load commit implementation in WebKit/Source/bindings/core/v8/WindowProxy.cpp in Goog The provisional-load commit implementation in WebKit/Source/bindings/core/v8/WindowProxy.cpp in Google Chrome before 47.0.2526.73 allows remote attackers to bypass the Same Origin Policy by leveraging a delay in window proxy clearing.
nvd
CVE-2015-6770P3HIGHCVSS 7.5≤ 46.0.2490.862015-12-06
CVE-2015-6770 [HIGH] CVE-2015-6770: The DOM implementation in Google Chrome before 47.0.2526.73 allows remote attackers to bypass the Sa The DOM implementation in Google Chrome before 47.0.2526.73 allows remote attackers to bypass the Same Origin Policy via unspecified vectors, a different vulnerability than CVE-2015-6768.
nvd
CVE-2015-6768P3HIGHCVSS 7.5≤ 46.0.2490.862015-12-06
CVE-2015-6768 [HIGH] CWE-264 CVE-2015-6768: The DOM implementation in Google Chrome before 47.0.2526.73 allows remote attackers to bypass the Sa The DOM implementation in Google Chrome before 47.0.2526.73 allows remote attackers to bypass the Same Origin Policy via unspecified vectors, a different vulnerability than CVE-2015-6770.
nvd
CVE-2019-5815P3HIGHCVSS 7.5≥ unspecified, < 74.0.3729.1082019-12-11
CVE-2019-5815 [HIGH] CWE-787 CVE-2019-5815: Type confusion in xsltNumberFormatGetMultipleLevel prior to libxslt 1.1.33 could allow attackers to Type confusion in xsltNumberFormatGetMultipleLevel prior to libxslt 1.1.33 could allow attackers to potentially exploit heap corruption via crafted XML data.
nvd
CVE-2010-3257P3CRITICALCVSS 9.3fixed in 6.0.472.532010-09-07
CVE-2010-3257 [CRITICAL] CWE-416 CVE-2010-3257: Use-after-free vulnerability in WebKit, as used in Apple Safari before 4.1.3 and 5.0.x before 5.0.3, Use-after-free vulnerability in WebKit, as used in Apple Safari before 4.1.3 and 5.0.x before 5.0.3, Google Chrome before 6.0.472.53, and webkitgtk before 1.2.6, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving element focus.
nvd
CVE-2021-30577P3HIGHCVSS 7.8fixed in 92.0.4515.107≥ unspecified, < 92.0.4515.1072021-08-03
CVE-2021-30577 [HIGH] CWE-732 CVE-2021-30577: Insufficient policy enforcement in Installer in Google Chrome prior to 92.0.4515.107 allowed a remot Insufficient policy enforcement in Installer in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to perform local privilege escalation via a crafted file.
nvd
CVE-2010-4494P3HIGHCVSS 7.5fixed in 8.0.552.2152010-12-07
CVE-2010-4494 [HIGH] CWE-415 CVE-2010-4494: Double free vulnerability in libxml2 2.7.8 and other versions, as used in Google Chrome before 8.0.5 Double free vulnerability in libxml2 2.7.8 and other versions, as used in Google Chrome before 8.0.552.215 and other products, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XPath handling.
nvd
CVE-2013-0895P3HIGHCVSS 7.5fixed in 25.0.1364.97fixed in 25.0.1364.992013-02-23
CVE-2013-0895 [HIGH] CWE-22 CVE-2013-0895: Google Chrome before 25.0.1364.97 on Linux, and before 25.0.1364.99 on Mac OS X, does not properly h Google Chrome before 25.0.1364.97 on Linux, and before 25.0.1364.99 on Mac OS X, does not properly handle pathnames during copy operations, which might make it easier for remote attackers to execute arbitrary programs via unspecified vectors.
nvd
CVE-2015-1276P3CRITICALCVSS 9.8≤ 43.0.2357.1342015-07-23
CVE-2015-1276 [CRITICAL] CVE-2015-1276: Use-after-free vulnerability in content/browser/indexed_db/indexed_db_backing_store.cc in the Indexe Use-after-free vulnerability in content/browser/indexed_db/indexed_db_backing_store.cc in the IndexedDB implementation in Google Chrome before 44.0.2403.89 allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging an abort action before a certain write operation.
nvd
CVE-2018-6061P3HIGHCVSS 7.5fixed in 65.0.3325.146≥ unspecified, < 65.0.3325.1462018-11-14
CVE-2018-6061 [HIGH] CWE-362 CVE-2018-6061: A race in the handling of SharedArrayBuffers in WebAssembly in Google Chrome prior to 65.0.3325.146 A race in the handling of SharedArrayBuffers in WebAssembly in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2018-6158P3HIGHCVSS 7.5fixed in 68.0.3440.75≥ unspecified, < 68.0.3440.752019-01-09
CVE-2018-6158 [HIGH] CWE-362 CVE-2018-6158: A race condition in Oilpan in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to poten A race condition in Oilpan in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2023-2939P3HIGHCVSS 7.8fixed in 114.0.5735.90≥ 114.0.5735.90, < 114.0.5735.902023-05-30
CVE-2023-2939 [HIGH] CWE-59 CVE-2023-2939: Insufficient data validation in Installer in Google Chrome on Windows prior to 114.0.5735.90 allowed Insufficient data validation in Installer in Google Chrome on Windows prior to 114.0.5735.90 allowed a local attacker to perform privilege escalation via crafted symbolic link. (Chromium security severity: Medium)
nvd
CVE-2011-2826P3HIGHCVSS 7.5fixed in 13.0.782.2152011-08-29
CVE-2011-2826 [HIGH] CVE-2011-2826: Google Chrome before 13.0.782.215 allows remote attackers to bypass the Same Origin Policy via vecto Google Chrome before 13.0.782.215 allows remote attackers to bypass the Same Origin Policy via vectors related to empty origins.
nvd
CVE-2024-9956P3HIGHCVSS 7.8fixed in 130.0.6723.58≥ 130.0.6723.58, < 130.0.6723.582024-10-15
CVE-2024-9956 [HIGH] CVE-2024-9956: Inappropriate implementation in WebAuthentication in Google Chrome on Android prior to 130.0.6723.58 Inappropriate implementation in WebAuthentication in Google Chrome on Android prior to 130.0.6723.58 allowed a local attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2020-6574P3HIGHCVSS 7.8fixed in 85.0.4183.102≥ unspecified, < 85.0.4183.1022020-09-21
CVE-2020-6574 [HIGH] CVE-2020-6574: Insufficient policy enforcement in installer in Google Chrome on OS X prior to 85.0.4183.102 allowed Insufficient policy enforcement in installer in Google Chrome on OS X prior to 85.0.4183.102 allowed a local attacker to potentially achieve privilege escalation via a crafted binary.
nvd
CVE-2022-1487P3HIGHCVSS 7.5fixed in 101.0.4951.41≥ unspecified, < 101.0.4951.412022-07-26
CVE-2022-1487 [HIGH] CWE-416 CVE-2022-1487: Use after free in Ozone in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potenti Use after free in Ozone in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via running a Wayland test.
nvd
CVE-2024-7977P3HIGHCVSS 7.8fixed in 128.0.6613.84≥ 128.0.6613.84, < 128.0.6613.842024-08-21
CVE-2024-7977 [HIGH] CWE-20 CVE-2024-7977: Insufficient data validation in Installer in Google Chrome on Windows prior to 128.0.6613.84 allowed Insufficient data validation in Installer in Google Chrome on Windows prior to 128.0.6613.84 allowed a local attacker to perform privilege escalation via a malicious file. (Chromium security severity: Medium)
nvd
CVE-2020-6417P3HIGHCVSS 7.8fixed in 80.0.3987.87≥ unspecified, < 80.0.3987.872020-02-11
CVE-2020-6417 [HIGH] CVE-2020-6417: Inappropriate implementation in installer in Google Chrome prior to 80.0.3987.87 allowed a local att Inappropriate implementation in installer in Google Chrome prior to 80.0.3987.87 allowed a local attacker to execute arbitrary code via a crafted registry entry.
nvd
CVE-2020-16007P3HIGHCVSS 7.8fixed in 86.0.4240.183≥ unspecified, < 86.0.4240.1832020-11-03
CVE-2020-16007 [HIGH] CWE-59 CVE-2020-16007: Insufficient data validation in installer in Google Chrome prior to 86.0.4240.183 allowed a local at Insufficient data validation in installer in Google Chrome prior to 86.0.4240.183 allowed a local attacker to potentially elevate privilege via a crafted filesystem.
nvd
CVE-2024-7980P3HIGHCVSS 7.8fixed in 128.0.6613.84≥ 128.0.6613.84, < 128.0.6613.842024-08-21
CVE-2024-7980 [HIGH] CWE-345 CVE-2024-7980: Insufficient data validation in Installer in Google Chrome on Windows prior to 128.0.6613.84 allowed Insufficient data validation in Installer in Google Chrome on Windows prior to 128.0.6613.84 allowed a local attacker to perform privilege escalation via a crafted symbolic link. (Chromium security severity: Medium)
nvd
Google Chrome vulnerabilities | cvebase