Google Chrome vulnerabilities
4,008 known vulnerabilities affecting google/chrome.
Total CVEs
4,008
CISA KEV
74
actively exploited
Public exploits
64
Exploited in wild
65
Severity breakdown
CRITICAL298HIGH2025MEDIUM1626LOW17UNKNOWN42
Vulnerabilities
Page 146 of 201
CVE-2015-1260HIGHCVSS 7.5≤ 42.0.2311.1522015-05-20
CVE-2015-1260 [HIGH] CVE-2015-1260: Multiple use-after-free vulnerabilities in content/renderer/media/user_media_client_impl.cc in the W
Multiple use-after-free vulnerabilities in content/renderer/media/user_media_client_impl.cc in the WebRTC implementation in Google Chrome before 43.0.2357.65 allow remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that executes upon completion of a getUserMedia request.
nvd
CVE-2015-1259HIGHCVSS 7.5≤ 42.0.2311.1522015-05-20
CVE-2015-1259 [HIGH] CWE-17 CVE-2015-1259: PDFium, as used in Google Chrome before 43.0.2357.65, does not properly initialize memory, which all
PDFium, as used in Google Chrome before 43.0.2357.65, does not properly initialize memory, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2015-1253HIGHCVSS 7.5≤ 42.0.2311.1522015-05-20
CVE-2015-1253 [HIGH] CWE-284 CVE-2015-1253: core/html/parser/HTMLConstructionSite.cpp in the DOM implementation in Blink, as used in Google Chro
core/html/parser/HTMLConstructionSite.cpp in the DOM implementation in Blink, as used in Google Chrome before 43.0.2357.65, allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code that appends a child to a SCRIPT element, related to the insert and executeReparentTask functions.
nvd
CVE-2015-1256HIGHCVSS 7.5≤ 42.0.2311.1522015-05-20
CVE-2015-1256 [HIGH] CVE-2015-1256: Use-after-free vulnerability in the SVG implementation in Blink, as used in Google Chrome before 43.
Use-after-free vulnerability in the SVG implementation in Blink, as used in Google Chrome before 43.0.2357.65, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted document that leverages improper handling of a shadow tree for a use element.
nvd
CVE-2015-1262HIGHCVSS 7.5≤ 42.0.2311.1522015-05-20
CVE-2015-1262 [HIGH] CWE-17 CVE-2015-1262: platform/fonts/shaping/HarfBuzzShaper.cpp in Blink, as used in Google Chrome before 43.0.2357.65, do
platform/fonts/shaping/HarfBuzzShaper.cpp in Blink, as used in Google Chrome before 43.0.2357.65, does not initialize a certain width field, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted Unicode text.
nvd
CVE-2015-1257HIGHCVSS 7.5≤ 42.0.2311.1522015-05-20
CVE-2015-1257 [HIGH] CWE-119 CVE-2015-1257: platform/graphics/filters/FEColorMatrix.cpp in the SVG implementation in Blink, as used in Google Ch
platform/graphics/filters/FEColorMatrix.cpp in the SVG implementation in Blink, as used in Google Chrome before 43.0.2357.65, does not properly handle an insufficient number of values in an feColorMatrix filter, which allows remote attackers to cause a denial of service (container overflow) or possibly have unspecified other impact via a crafted documen
nvd
CVE-2015-1258HIGHCVSS 7.5≤ 42.0.2311.1522015-05-20
CVE-2015-1258 [HIGH] CWE-189 CVE-2015-1258: Google Chrome before 43.0.2357.65 relies on libvpx code that was not built with an appropriate --siz
Google Chrome before 43.0.2357.65 relies on libvpx code that was not built with an appropriate --size-limit value, which allows remote attackers to trigger a negative value for a size field, and consequently cause a denial of service or possibly have unspecified other impact, via a crafted frame size in VP9 video data.
nvd
CVE-2015-1265HIGHCVSS 7.5PoC≤ 42.0.2311.1522015-05-20
CVE-2015-1265 [HIGH] CVE-2015-1265: Multiple unspecified vulnerabilities in Google Chrome before 43.0.2357.65 allow attackers to cause a
Multiple unspecified vulnerabilities in Google Chrome before 43.0.2357.65 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2015-3910HIGHCVSS 7.5≤ 42.0.2311.1522015-05-20
CVE-2015-3910 [HIGH] CVE-2015-3910: Multiple unspecified vulnerabilities in Google V8 before 4.3.61.21, as used in Google Chrome before
Multiple unspecified vulnerabilities in Google V8 before 4.3.61.21, as used in Google Chrome before 43.0.2357.65, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2015-1255MEDIUMCVSS 6.8≤ 42.0.2311.1522015-05-20
CVE-2015-1255 [MEDIUM] CVE-2015-1255: Use-after-free vulnerability in content/renderer/media/webaudio_capturer_source.cc in the WebAudio i
Use-after-free vulnerability in content/renderer/media/webaudio_capturer_source.cc in the WebAudio implementation in Google Chrome before 43.0.2357.65 allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact by leveraging improper handling of a stop action for an audio track.
nvd
CVE-2015-1254MEDIUMCVSS 5.0≤ 42.0.2311.1522015-05-20
CVE-2015-1254 [MEDIUM] CWE-264 CVE-2015-1254: core/dom/Document.cpp in Blink, as used in Google Chrome before 43.0.2357.65, enables the inheritanc
core/dom/Document.cpp in Blink, as used in Google Chrome before 43.0.2357.65, enables the inheritance of the designMode attribute, which allows remote attackers to bypass the Same Origin Policy by leveraging the availability of editing.
nvd
CVE-2015-1264MEDIUMCVSS 4.3≤ 42.0.2311.1522015-05-20
CVE-2015-1264 [MEDIUM] CWE-79 CVE-2015-1264: Cross-site scripting (XSS) vulnerability in Google Chrome before 43.0.2357.65 allows user-assisted r
Cross-site scripting (XSS) vulnerability in Google Chrome before 43.0.2357.65 allows user-assisted remote attackers to inject arbitrary web script or HTML via crafted data that is improperly handled by the Bookmarks feature.
nvd
CVE-2015-1263MEDIUMCVSS 4.3≤ 42.0.2311.1522015-05-20
CVE-2015-1263 [MEDIUM] CWE-17 CVE-2015-1263: The Spellcheck API implementation in Google Chrome before 43.0.2357.65 does not use an HTTPS session
The Spellcheck API implementation in Google Chrome before 43.0.2357.65 does not use an HTTPS session for downloading a Hunspell dictionary, which allows man-in-the-middle attackers to deliver incorrect spelling suggestions or possibly have unspecified other impact via a crafted file.
nvd
CVE-2015-1261MEDIUMCVSS 5.0≤ 42.0.2311.1072015-05-20
CVE-2015-1261 [MEDIUM] CWE-20 CVE-2015-1261: android/java/src/org/chromium/chrome/browser/WebsiteSettingsPopup.java in Google Chrome before 43.0.
android/java/src/org/chromium/chrome/browser/WebsiteSettingsPopup.java in Google Chrome before 43.0.2357.65 on Android does not properly restrict use of a URL's fragment identifier during construction of a page-info popup, which allows remote attackers to spoof the URL bar or deliver misleading popup content via crafted text.
nvd
CVE-2015-1251MEDIUMCVSS 6.8≤ 42.0.2311.1522015-05-20
CVE-2015-1251 [MEDIUM] CVE-2015-1251: Use-after-free vulnerability in the SpeechRecognitionClient implementation in the Speech subsystem i
Use-after-free vulnerability in the SpeechRecognitionClient implementation in the Speech subsystem in Google Chrome before 43.0.2357.65 allows remote attackers to execute arbitrary code via a crafted document.
nvd
CVE-2015-1250HIGHCVSS 7.5≤ 42.0.2311.872015-05-01
CVE-2015-1250 [HIGH] CVE-2015-1250: Multiple unspecified vulnerabilities in Google Chrome before 42.0.2311.135 allow attackers to cause
Multiple unspecified vulnerabilities in Google Chrome before 42.0.2311.135 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2015-1243HIGHCVSS 7.5≤ 42.0.2311.872015-05-01
CVE-2015-1243 [HIGH] CVE-2015-1243: Use-after-free vulnerability in the MutationObserver::disconnect function in core/dom/MutationObserv
Use-after-free vulnerability in the MutationObserver::disconnect function in core/dom/MutationObserver.cpp in the DOM implementation in Blink, as used in Google Chrome before 42.0.2311.135, allows remote attackers to cause a denial of service or possibly have unspecified other impact by triggering an attempt to unregister a MutationObserver object that is not c
nvd
CVE-2015-1238HIGHCVSS 7.5≤ 42.0.2311.602015-04-19
CVE-2015-1238 [HIGH] CWE-119 CVE-2015-1238: Skia, as used in Google Chrome before 42.0.2311.90, allows remote attackers to cause a denial of ser
Skia, as used in Google Chrome before 42.0.2311.90, allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2015-1237HIGHCVSS 7.5≤ 42.0.2311.602015-04-19
CVE-2015-1237 [HIGH] CVE-2015-1237: Use-after-free vulnerability in the RenderFrameImpl::OnMessageReceived function in content/renderer/
Use-after-free vulnerability in the RenderFrameImpl::OnMessageReceived function in content/renderer/render_frame_impl.cc in Google Chrome before 42.0.2311.90 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger renderer IPC messages during a detach operation.
nvd
CVE-2015-1242HIGHCVSS 7.5≤ 42.0.2311.602015-04-19
CVE-2015-1242 [HIGH] CVE-2015-1242: The ReduceTransitionElementsKind function in hydrogen-check-elimination.cc in Google V8 before 4.2.7
The ReduceTransitionElementsKind function in hydrogen-check-elimination.cc in Google V8 before 4.2.77.8, as used in Google Chrome before 42.0.2311.90, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that leverages "type confusion" in the check-elimination optimization.
nvd