cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2

Vulnerabilities

Page 140 of 292
CVE-2021-30511P4HIGHCVSS 8.1fixed in 90.0.4430.212≥ unspecified, < 90.0.4430.2122021-06-04
CVE-2021-30511 [HIGH] CWE-125 CVE-2021-30511: Out of bounds read in Tab Groups in Google Chrome prior to 90.0.4430.212 allowed an attacker who con Out of bounds read in Tab Groups in Google Chrome prior to 90.0.4430.212 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory read via a crafted HTML page.
nvd
CVE-2021-21139P4MEDIUMCVSS 6.5fixed in 88.0.4324.96≥ unspecified, < 88.0.4324.962021-02-09
CVE-2021-21139 [MEDIUM] CWE-1021 CVE-2021-21139: Inappropriate implementation in iframe sandbox in Google Chrome prior to 88.0.4324.96 allowed a remo Inappropriate implementation in iframe sandbox in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
nvd
CVE-2017-5040P4MEDIUMCVSS 4.3≤ 57.0.2987.75≤ 57.0.2987.1002017-04-24
CVE-2017-5040 [MEDIUM] CVE-2017-5040: V8 in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android V8 in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android was missing a neutering check, which allowed a remote attacker to read values in memory via a crafted HTML page.
nvd
CVE-2012-5140P4CRITICALCVSS 10.0≤ 23.0.1271.96v23.0.1271.0+66 more2012-12-12
CVE-2012-5140 [CRITICAL] CWE-416 CVE-2012-5140: Use-after-free vulnerability in Google Chrome before 23.0.1271.97 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 23.0.1271.97 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the URL loader.
nvd
CVE-2012-5139P4CRITICALCVSS 10.0≤ 23.0.1271.96v23.0.1271.0+66 more2012-12-12
CVE-2012-5139 [CRITICAL] CWE-416 CVE-2012-5139: Use-after-free vulnerability in Google Chrome before 23.0.1271.97 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 23.0.1271.97 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to visibility events.
nvd
CVE-2017-5039P4HIGHCVSS 7.8≤ 57.0.2987.75≤ 57.0.2987.1002017-04-24
CVE-2017-5039 [HIGH] CWE-416 CVE-2017-5039: A use after free in PDFium in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57 A use after free in PDFium in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
nvd
CVE-2010-1230P4CRITICALCVSS 10.0fixed in 4.1.249.10362010-04-01
CVE-2010-1230 [CRITICAL] CWE-200 CVE-2010-1230: Google Chrome before 4.1.249.1036 does not have the expected behavior for attempts to delete Web SQL Google Chrome before 4.1.249.1036 does not have the expected behavior for attempts to delete Web SQL Databases and clear the Strict Transport Security (STS) state, which has unspecified impact and attack vectors.
nvd
CVE-2015-1253P4HIGHCVSS 7.5≤ 42.0.2311.1522015-05-20
CVE-2015-1253 [HIGH] CWE-284 CVE-2015-1253: core/html/parser/HTMLConstructionSite.cpp in the DOM implementation in Blink, as used in Google Chro core/html/parser/HTMLConstructionSite.cpp in the DOM implementation in Blink, as used in Google Chrome before 43.0.2357.65, allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code that appends a child to a SCRIPT element, related to the insert and executeReparentTask functions.
nvd
CVE-2015-6772P4HIGHCVSS 7.5≤ 46.0.2490.862015-12-06
CVE-2015-6772 [HIGH] CWE-264 CVE-2015-6772: The DOM implementation in Blink, as used in Google Chrome before 47.0.2526.73, does not prevent java The DOM implementation in Blink, as used in Google Chrome before 47.0.2526.73, does not prevent javascript: URL navigation while a document is being detached, which allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code that improperly interacts with a plugin.
nvd
CVE-2019-13706P4HIGHCVSS 7.8fixed in 78.0.3904.70≥ unspecified, < 78.0.3904.702019-11-25
CVE-2019-13706 [HIGH] CWE-787 CVE-2019-13706: Out of bounds memory access in PDFium in Google Chrome prior to 78.0.3904.70 allowed a remote attack Out of bounds memory access in PDFium in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
nvd
CVE-2015-1227P4HIGHCVSS 7.5≤ 40.0.2214.1152015-03-09
CVE-2015-1227 [HIGH] CWE-399 CVE-2015-1227: The DragImage::create function in platform/DragImage.cpp in Blink, as used in Google Chrome before 4 The DragImage::create function in platform/DragImage.cpp in Blink, as used in Google Chrome before 41.0.2272.76, does not initialize memory for image drawing, which allows remote attackers to have an unspecified impact by triggering a failed image decoding, as demonstrated by an image for which the default orientation cannot be used.
nvd
CVE-2011-0778P3HIGHCVSS 7.5≤ 9.0.597.832011-02-04
CVE-2011-0778 [HIGH] CWE-264 CVE-2011-0778: Google Chrome before 9.0.597.84 does not properly restrict drag and drop operations, which might all Google Chrome before 9.0.597.84 does not properly restrict drag and drop operations, which might allow remote attackers to bypass the Same Origin Policy via unspecified vectors.
nvd
CVE-2013-0910P4HIGHCVSS 7.5≤ 25.0.1364.126v25.0.1364.0+104 more2013-03-05
CVE-2013-0910 [HIGH] CWE-287 CVE-2013-0910: Google Chrome before 25.0.1364.152 does not properly manage the interaction between the browser proc Google Chrome before 25.0.1364.152 does not properly manage the interaction between the browser process and renderer processes during authorization of the loading of a plug-in, which makes it easier for remote attackers to bypass intended access restrictions via vectors involving a blocked plug-in.
nvd
CVE-2019-13702P4HIGHCVSS 7.8fixed in 78.0.3904.70≥ unspecified, < 78.0.3904.702019-11-25
CVE-2019-13702 [HIGH] CWE-269 CVE-2019-13702: Inappropriate implementation in installer in Google Chrome on Windows prior to 78.0.3904.70 allowed Inappropriate implementation in installer in Google Chrome on Windows prior to 78.0.3904.70 allowed a local attacker to perform privilege escalation via a crafted executable.
nvd
CVE-2013-0911P4HIGHCVSS 7.5≤ 25.0.1364.126v25.0.1364.0+104 more2013-03-05
CVE-2013-0911 [HIGH] CWE-22 CVE-2013-0911: Directory traversal vulnerability in Google Chrome before 25.0.1364.152 allows remote attackers to h Directory traversal vulnerability in Google Chrome before 25.0.1364.152 allows remote attackers to have an unspecified impact via vectors related to databases.
nvd
CVE-2019-5819P4HIGHCVSS 7.8fixed in 74.0.3729.108≥ unspecified, < 74.0.3729.1082019-06-27
CVE-2019-5819 [HIGH] CWE-20 CVE-2019-5819: Insufficient data validation in developer tools in Google Chrome on OS X prior to 74.0.3729.108 allo Insufficient data validation in developer tools in Google Chrome on OS X prior to 74.0.3729.108 allowed a local attacker to execute arbitrary code via a crafted string copied to clipboard.
nvd
CVE-2013-2859P3HIGHCVSS 7.5≤ 27.0.1453.109v27.0.1453.0+79 more2013-06-05
CVE-2013-2859 [HIGH] CVE-2013-2859: Google Chrome before 27.0.1453.110 allows remote attackers to bypass the Same Origin Policy and trig Google Chrome before 27.0.1453.110 allows remote attackers to bypass the Same Origin Policy and trigger namespace pollution via unspecified vectors.
nvd
CVE-2017-5068P4HIGHCVSS 7.5fixed in 58.0.3029.962017-10-27
CVE-2017-5068 [HIGH] CWE-362 CVE-2017-5068: Incorrect handling of picture ID in WebRTC in Google Chrome prior to 58.0.3029.96 for Mac, Windows, Incorrect handling of picture ID in WebRTC in Google Chrome prior to 58.0.3029.96 for Mac, Windows, and Linux allowed a remote attacker to trigger a race condition via a crafted HTML page.
nvd
CVE-2011-2878P4HIGHCVSS 7.5fixed in 14.0.835.2022011-10-04
CVE-2011-2878 [HIGH] CVE-2011-2878: Google Chrome before 14.0.835.202 does not properly restrict access to the window prototype, which a Google Chrome before 14.0.835.202 does not properly restrict access to the window prototype, which allows remote attackers to bypass the Same Origin Policy via unspecified vectors.
nvd
CVE-2011-2856P4HIGHCVSS 7.5fixed in 14.0.835.1632011-09-19
CVE-2011-2856 [HIGH] CWE-346 CVE-2011-2856: Google V8, as used in Google Chrome before 14.0.835.163, allows remote attackers to bypass the Same Google V8, as used in Google Chrome before 14.0.835.163, allows remote attackers to bypass the Same Origin Policy via unspecified vectors.
nvd
Google Chrome vulnerabilities | cvebase