cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2

Vulnerabilities

Page 144 of 292
CVE-2021-30582P4MEDIUMCVSS 6.5fixed in 92.0.4515.107≥ unspecified, < 92.0.4515.1072021-08-03
CVE-2021-30582 [MEDIUM] CVE-2021-30582: Inappropriate implementation in Animation in Google Chrome prior to 92.0.4515.107 allowed a remote a Inappropriate implementation in Animation in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2015-1209P4HIGHCVSS 7.5fixed in 40.0.2214.109fixed in 40.0.2214.1112015-02-06
CVE-2015-1209 [HIGH] CWE-416 CVE-2015-1209: Use-after-free vulnerability in the VisibleSelection::nonBoundaryShadowTreeRootNode function in core Use-after-free vulnerability in the VisibleSelection::nonBoundaryShadowTreeRootNode function in core/editing/VisibleSelection.cpp in the DOM implementation in Blink, as used in Google Chrome before 40.0.2214.111 on Windows, OS X, and Linux and before 40.0.2214.109 on Android, allows remote attackers to cause a denial of service or possibly have unspecif
nvd
CVE-2014-7933P3HIGHCVSS 7.5≤ 40.0.2214.852015-01-22
CVE-2014-7933 [HIGH] CVE-2014-7933: Use-after-free vulnerability in the matroska_read_seek function in libavformat/matroskadec.c in FFmp Use-after-free vulnerability in the matroska_read_seek function in libavformat/matroskadec.c in FFmpeg before 2.5.1, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted Matroska file that triggers improper maintenance of tracks data.
nvd
CVE-2011-0473P4CRITICALCVSS 10.0fixed in 8.0.552.2372011-01-14
CVE-2011-0473 [CRITICAL] CVE-2011-0473: Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly handle Cascading S Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly handle Cascading Style Sheets (CSS) token sequences in conjunction with CANVAS elements, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."
nvd
CVE-2010-2901P4CRITICALCVSS 10.0fixed in 5.0.375.1252010-07-28
CVE-2010-2901 [CRITICAL] CWE-119 CVE-2010-2901: The rendering implementation in Google Chrome before 5.0.375.125 allows remote attackers to cause a The rendering implementation in Google Chrome before 5.0.375.125 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2015-1221P4HIGHCVSS 7.5≤ 40.0.2214.1152015-03-09
CVE-2015-1221 [HIGH] CVE-2015-1221: Use-after-free vulnerability in Blink, as used in Google Chrome before 41.0.2272.76, allows remote a Use-after-free vulnerability in Blink, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging incorrect ordering of operations in the Web SQL Database thread relative to Blink's main thread, related to the shutdown function in web/WebKit.cpp.
nvd
CVE-2019-5881P4HIGHCVSS 8.1fixed in 77.0.3865.75≥ unspecified, < 77.0.3865.752019-11-25
CVE-2019-5881 [HIGH] CWE-125 CVE-2019-5881: Out of bounds read in SwiftShader in Google Chrome prior to 77.0.3865.75 allowed a remote attacker t Out of bounds read in SwiftShader in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
nvd
CVE-2013-2924P4HIGHCVSS 7.5≤ 30.0.1599.65v30.0.1599.0+57 more2013-10-02
CVE-2013-2924 [HIGH] CWE-399 CVE-2013-2924: Use-after-free vulnerability in International Components for Unicode (ICU), as used in Google Chrome Use-after-free vulnerability in International Components for Unicode (ICU), as used in Google Chrome before 30.0.1599.66 and other products, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2011-3095P4CRITICALCVSS 10.0≤ 19.0.1084.452012-05-16
CVE-2011-3095 [CRITICAL] CWE-20 CVE-2011-3095: The OGG container in Google Chrome before 19.0.1084.46 allows remote attackers to cause a denial of The OGG container in Google Chrome before 19.0.1084.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that trigger an out-of-bounds write.
nvd
CVE-2015-1258P4HIGHCVSS 7.5≤ 42.0.2311.1522015-05-20
CVE-2015-1258 [HIGH] CWE-189 CVE-2015-1258: Google Chrome before 43.0.2357.65 relies on libvpx code that was not built with an appropriate --siz Google Chrome before 43.0.2357.65 relies on libvpx code that was not built with an appropriate --size-limit value, which allows remote attackers to trigger a negative value for a size field, and consequently cause a denial of service or possibly have unspecified other impact, via a crafted frame size in VP9 video data.
nvd
CVE-2015-1243P4HIGHCVSS 7.5≤ 42.0.2311.872015-05-01
CVE-2015-1243 [HIGH] CVE-2015-1243: Use-after-free vulnerability in the MutationObserver::disconnect function in core/dom/MutationObserv Use-after-free vulnerability in the MutationObserver::disconnect function in core/dom/MutationObserver.cpp in the DOM implementation in Blink, as used in Google Chrome before 42.0.2311.135, allows remote attackers to cause a denial of service or possibly have unspecified other impact by triggering an attempt to unregister a MutationObserver object that is not c
nvd
CVE-2017-5035P4HIGHCVSS 8.1≤ 57.0.2987.752017-04-24
CVE-2017-5035 [HIGH] CWE-362 CVE-2017-5035: Google Chrome prior to 57.0.2987.98 for Windows and Mac had a race condition, which could cause Chro Google Chrome prior to 57.0.2987.98 for Windows and Mac had a race condition, which could cause Chrome to display incorrect certificate information for a site.
nvd
CVE-2017-5074P4HIGHCVSS 8.0fixed in 59.0.3071.862017-10-27
CVE-2017-5074 [HIGH] CWE-416 CVE-2017-5074: A use after free in Chrome Apps in Google Chrome prior to 59.0.3071.86 for Windows allowed a remote A use after free in Chrome Apps in Google Chrome prior to 59.0.3071.86 for Windows allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page, related to Bluetooth.
nvd
CVE-2011-3895P4HIGHCVSS 7.5fixed in 15.0.874.1202011-11-11
CVE-2011-3895 [HIGH] CWE-787 CVE-2011-3895: Heap-based buffer overflow in the Vorbis decoder in Google Chrome before 15.0.874.120 allows remote Heap-based buffer overflow in the Vorbis decoder in Google Chrome before 15.0.874.120 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted stream.
nvd
CVE-2012-5143P4CRITICALCVSS 10.0≤ 23.0.1271.96v23.0.1271.0+66 more2012-12-12
CVE-2012-5143 [CRITICAL] CWE-190 CVE-2012-5143: Integer overflow in Google Chrome before 23.0.1271.97 allows remote attackers to cause a denial of s Integer overflow in Google Chrome before 23.0.1271.97 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to PPAPI image buffers.
nvd
CVE-2015-6791P4CRITICALCVSS 10.0≤ 47.0.2526.732015-12-14
CVE-2015-6791 [CRITICAL] CVE-2015-6791: Multiple unspecified vulnerabilities in Google Chrome before 47.0.2526.80 allow attackers to cause a Multiple unspecified vulnerabilities in Google Chrome before 47.0.2526.80 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2016-1684P4HIGHCVSS 7.5≤ 50.0.2661.1022016-06-05
CVE-2016-1684 [HIGH] CVE-2016-1684: numbers.c in libxslt before 1.1.29, as used in Google Chrome before 51.0.2704.63, mishandles the i f numbers.c in libxslt before 1.1.29, as used in Google Chrome before 51.0.2704.63, mishandles the i format token for xsl:number data, which allows remote attackers to cause a denial of service (integer overflow or resource consumption) or possibly have unspecified other impact via a crafted document.
nvd
CVE-2014-7937P4HIGHCVSS 7.5≤ 40.0.2214.852015-01-22
CVE-2014-7937 [HIGH] CWE-119 CVE-2014-7937: Multiple off-by-one errors in libavcodec/vorbisdec.c in FFmpeg before 2.4.2, as used in Google Chrom Multiple off-by-one errors in libavcodec/vorbisdec.c in FFmpeg before 2.4.2, as used in Google Chrome before 40.0.2214.91, allow remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted Vorbis I data.
nvd
CVE-2017-5036P4HIGHCVSS 7.8≤ 57.0.2987.75≤ 57.0.2987.1002017-04-24
CVE-2017-5036 [HIGH] CWE-416 CVE-2017-5036: A use after free in PDFium in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57 A use after free in PDFium in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed a remote attacker to have an unspecified impact via a crafted PDF file.
nvd
CVE-2015-1303P4HIGHCVSS 7.5≤ 45.0.2454.932015-10-12
CVE-2015-1303 [HIGH] CWE-20 CVE-2015-1303: bindings/core/v8/V8DOMWrapper.h in Blink, as used in Google Chrome before 45.0.2454.101, does not pe bindings/core/v8/V8DOMWrapper.h in Blink, as used in Google Chrome before 45.0.2454.101, does not perform a rethrow action to propagate information about a cross-context exception, which allows remote attackers to bypass the Same Origin Policy via a crafted HTML document containing an IFRAME element.
nvd
Google Chrome vulnerabilities | cvebase