Google Chrome vulnerabilities

4,008 known vulnerabilities affecting google/chrome.

Total CVEs
4,008
CISA KEV
74
actively exploited
Public exploits
63
Exploited in wild
65
Severity breakdown
CRITICAL298HIGH2025MEDIUM1626LOW17UNKNOWN42

Vulnerabilities

Page 133 of 201
CVE-2016-5212MEDIUMCVSS 6.5≤ 54.0.2840.992017-01-19
CVE-2016-5212 [MEDIUM] CWE-200 CVE-2016-5212: Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android insuffi Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android insufficiently sanitized DevTools URLs, which allowed a remote attacker to read local files via a crafted HTML page.
nvd
CVE-2016-5223MEDIUMCVSS 6.5≤ 54.0.2840.992017-01-19
CVE-2016-5223 [MEDIUM] CWE-190 CVE-2016-5223: Integer overflow in PDFium in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55 Integer overflow in PDFium in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to potentially exploit heap corruption or DoS via a crafted PDF file.
nvd
CVE-2016-5201MEDIUMCVSS 6.5≤ 54.0.2840.872017-01-19
CVE-2016-5201 [MEDIUM] CWE-200 CVE-2016-5201: A leak of privateClass in the extensions API in Google Chrome prior to 54.0.2840.100 for Linux, and A leak of privateClass in the extensions API in Google Chrome prior to 54.0.2840.100 for Linux, and 54.0.2840.99 for Windows, and 54.0.2840.98 for Mac allowed a remote attacker to access privileged JavaScript code via a crafted HTML page.
nvd
CVE-2016-5205MEDIUMCVSS 6.1≤ 54.0.2840.992017-01-19
CVE-2016-5205 [MEDIUM] CWE-79 CVE-2016-5205: Blink in Google Chrome prior to 55.0.2883.75 for Linux, Windows and Mac, incorrectly handles deferre Blink in Google Chrome prior to 55.0.2883.75 for Linux, Windows and Mac, incorrectly handles deferred page loads, which allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page.
nvd
CVE-2016-5185HIGHCVSS 8.8≤ 53.0.2785.1432016-12-18
CVE-2016-5185 [HIGH] CWE-416 CVE-2016-5185: Blink in Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android i Blink in Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android incorrectly allowed reentrance of FrameView::updateLifecyclePhasesInternal(), which allowed a remote attacker to perform an out of bounds memory read via crafted HTML pages.
nvd
CVE-2016-5184HIGHCVSS 8.8≤ 53.0.2785.1432016-12-18
CVE-2016-5184 [HIGH] CWE-416 CVE-2016-5184: PDFium in Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android PDFium in Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android incorrectly handled object lifecycles in CFFL_FormFillter::KillFocusForAnnot, which allowed a remote attacker to potentially exploit heap corruption via crafted PDF files.
nvd
CVE-2016-5183HIGHCVSS 8.8≤ 53.0.2785.1432016-12-18
CVE-2016-5183 [HIGH] CWE-416 CVE-2016-5183: A heap use after free in PDFium in Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; A heap use after free in PDFium in Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android allows a remote attacker to potentially exploit heap corruption via crafted PDF files.
nvd
CVE-2016-5182HIGHCVSS 8.8≤ 53.0.2785.1432016-12-18
CVE-2016-5182 [HIGH] CWE-119 CVE-2016-5182: Blink in Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android h Blink in Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android had insufficient validation in bitmap handling, which allowed a remote attacker to potentially exploit heap corruption via crafted HTML pages.
nvd
CVE-2016-5193MEDIUMCVSS 4.3≤ 53.0.2785.1432016-12-18
CVE-2016-5193 [MEDIUM] CWE-20 CVE-2016-5193: Google Chrome prior to 54.0 for iOS had insufficient validation of URLs for windows open by DOM, whi Google Chrome prior to 54.0 for iOS had insufficient validation of URLs for windows open by DOM, which allowed a remote attacker to bypass restrictions on navigation to certain URL schemes via crafted HTML pages.
nvd
CVE-2016-5191MEDIUMCVSS 6.1≤ 53.0.2785.1432016-12-18
CVE-2016-5191 [MEDIUM] CWE-79 CVE-2016-5191: Bookmark handling in Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 f Bookmark handling in Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android had insufficient validation of supplied data, which allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via crafted HTML pages, as demonstrated by an interpretation conflict between userinfo and scheme in an http://javascript:
nvd
CVE-2016-5188MEDIUMCVSS 4.3≤ 53.0.2785.1432016-12-18
CVE-2016-5188 [MEDIUM] CWE-20 CVE-2016-5188: Multiple issues in Blink in Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux allow a Multiple issues in Blink in Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux allow a remote attacker to spoof various parts of browser UI via crafted HTML pages.
nvd
CVE-2016-5192MEDIUMCVSS 6.5≤ 53.0.2785.1432016-12-18
CVE-2016-5192 [MEDIUM] CWE-284 CVE-2016-5192: Blink in Google Chrome prior to 54.0.2840.59 for Windows missed a CORS check on redirect in TextTrac Blink in Google Chrome prior to 54.0.2840.59 for Windows missed a CORS check on redirect in TextTrackLoader, which allowed a remote attacker to bypass cross-origin restrictions via crafted HTML pages.
nvd
CVE-2016-5187MEDIUMCVSS 6.5≤ 53.0.2785.1432016-12-18
CVE-2016-5187 [MEDIUM] CWE-20 CVE-2016-5187: Google Chrome prior to 54.0.2840.85 for Android incorrectly handled rapid transition into and out of Google Chrome prior to 54.0.2840.85 for Android incorrectly handled rapid transition into and out of full screen mode, which allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via crafted HTML pages.
nvd
CVE-2016-5189MEDIUMCVSS 6.5≤ 53.0.2785.1432016-12-18
CVE-2016-5189 [MEDIUM] CWE-284 CVE-2016-5189: Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android permitted Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android permitted navigation to blob URLs with non-canonical origins, which allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via crafted HTML pages.
nvd
CVE-2016-5186MEDIUMCVSS 5.3≤ 53.0.2785.1432016-12-18
CVE-2016-5186 [MEDIUM] CWE-125 CVE-2016-5186: Devtools in Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Androi Devtools in Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android incorrectly handled objects after a tab crash, which allowed a remote attacker to perform an out of bounds memory read via crafted PDF files.
nvd
CVE-2016-5190MEDIUMCVSS 6.3≤ 53.0.2785.1432016-12-18
CVE-2016-5190 [MEDIUM] CWE-416 CVE-2016-5190: Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android incorrectl Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android incorrectly handled object lifecycles during shutdown, which allowed a remote attacker to perform an out of bounds memory read via crafted HTML pages.
nvd
CVE-2016-5181MEDIUMCVSS 6.1≤ 53.0.2785.1432016-12-18
CVE-2016-5181 [MEDIUM] CWE-79 CVE-2016-5181: Blink in Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android p Blink in Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android permitted execution of v8 microtasks while the DOM was in an inconsistent state, which allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via crafted HTML pages.
nvd
CVE-2005-4900MEDIUMCVSS 5.9≤ 47.0.2526.1112016-10-14
CVE-2005-4900 [MEDIUM] CWE-326 CVE-2005-4900: SHA-1 is not collision resistant, which makes it easier for context-dependent attackers to conduct s SHA-1 is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attacks, as demonstrated by attacks on the use of SHA-1 in TLS 1.2. NOTE: this CVE exists to provide a common identifier for referencing this SHA-1 issue; the existence of an identifier is not, by itself, a technology recommendation.
nvd
CVE-2016-5176MEDIUMCVSS 6.5≤ 53.0.2785.1012016-09-29
CVE-2016-5176 [MEDIUM] CWE-284 CVE-2016-5176: Google Chrome before 53.0.2785.113 allows remote attackers to bypass the SafeBrowsing protection mec Google Chrome before 53.0.2785.113 allows remote attackers to bypass the SafeBrowsing protection mechanism via unspecified vectors.
nvd
CVE-2016-5175HIGHCVSS 8.8≤ 53.0.2785.1012016-09-25
CVE-2016-5175 [HIGH] CVE-2016-5175: Multiple unspecified vulnerabilities in Google Chrome before 53.0.2785.113 allow attackers to cause Multiple unspecified vulnerabilities in Google Chrome before 53.0.2785.113 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
Google Chrome vulnerabilities | cvebase