Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2
Vulnerabilities
Page 152 of 292
CVE-2014-3152P4HIGHCVSS 7.5≤ 35.0.1916.113v35.0.1916.0+78 more2014-05-21
CVE-2014-3152 [HIGH] CWE-189 CVE-2014-3152: Integer underflow in the LCodeGen::PrepareKeyedOperand function in arm/lithium-codegen-arm.cc in Goo
Integer underflow in the LCodeGen::PrepareKeyedOperand function in arm/lithium-codegen-arm.cc in Google V8 before 3.25.28.16, as used in Google Chrome before 35.0.1916.114, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger a negative key value.
nvd
CVE-2014-7906P4HIGHCVSS 7.5≤ 39.0.2171.452014-11-19
CVE-2014-7906 [HIGH] CWE-399 CVE-2014-7906: Use-after-free vulnerability in the Pepper plugins in Google Chrome before 39.0.2171.65 allows remot
Use-after-free vulnerability in the Pepper plugins in Google Chrome before 39.0.2171.65 allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted Flash content that triggers an attempted PepperMediaDeviceManager access outside of the object's lifetime.
nvd
CVE-2014-1735P4HIGHCVSS 7.5fixed in 34.0.1847.131fixed in 34.0.1847.1322014-04-26
CVE-2014-1735 [HIGH] CVE-2014-1735: Multiple unspecified vulnerabilities in Google V8 before 3.24.35.33, as used in Google Chrome before
Multiple unspecified vulnerabilities in Google V8 before 3.24.35.33, as used in Google Chrome before 34.0.1847.131 on Windows and OS X and before 34.0.1847.132 on Linux, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2013-6638P4HIGHCVSS 7.5≤ 31.0.1650.62v31.0.1650.0+56 more2013-12-07
CVE-2013-6638 [HIGH] CWE-119 CVE-2013-6638: Multiple buffer overflows in runtime.cc in Google V8 before 3.22.24.7, as used in Google Chrome befo
Multiple buffer overflows in runtime.cc in Google V8 before 3.22.24.7, as used in Google Chrome before 31.0.1650.63, allow remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger a large typed array, related to the (1) Runtime_TypedArrayInitialize and (2) Runtime_TypedArrayInitializeFromArrayLike
nvd
CVE-2014-1716P4HIGHCVSS 7.5≤ 34.0.1847.1152014-04-09
CVE-2014-1716 [HIGH] CWE-94 CVE-2014-1716: Cross-site scripting (XSS) vulnerability in the Runtime_SetPrototype function in runtime.cc in Googl
Cross-site scripting (XSS) vulnerability in the Runtime_SetPrototype function in runtime.cc in Google V8, as used in Google Chrome before 34.0.1847.116, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Universal XSS (UXSS)."
nvd
CVE-2015-6766P4HIGHCVSS 7.5≤ 46.0.2490.862015-12-06
CVE-2015-6766 [HIGH] CVE-2015-6766: Use-after-free vulnerability in the AppCache implementation in Google Chrome before 47.0.2526.73 all
Use-after-free vulnerability in the AppCache implementation in Google Chrome before 47.0.2526.73 allows remote attackers with renderer access to cause a denial of service or possibly have unspecified other impact by leveraging incorrect AppCacheUpdateJob behavior associated with duplicate cache selection.
nvd
CVE-2015-1223P4HIGHCVSS 7.5≤ 40.0.2214.1152015-03-09
CVE-2015-1223 [HIGH] CVE-2015-1223: Multiple use-after-free vulnerabilities in core/html/HTMLInputElement.cpp in the DOM implementation
Multiple use-after-free vulnerabilities in core/html/HTMLInputElement.cpp in the DOM implementation in Blink, as used in Google Chrome before 41.0.2272.76, allow remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger extraneous change events, as demonstrated by events for invalid input or input to read-on
nvd
CVE-2011-3105P4HIGHCVSS 7.5≤ 19.0.1084.51v19.0.1028.0+130 more2012-05-24
CVE-2011-3105 [HIGH] CWE-399 CVE-2011-3105: Use-after-free vulnerability in the Cascading Style Sheets (CSS) implementation in Google Chrome bef
Use-after-free vulnerability in the Cascading Style Sheets (CSS) implementation in Google Chrome before 19.0.1084.52 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the :first-letter pseudo-element.
nvd
CVE-2013-6644P4HIGHCVSS 7.5fixed in 32.0.1700.77fixed in 32.0.1700.762014-01-16
CVE-2013-6644 [HIGH] CWE-416 CVE-2013-6644: Multiple unspecified vulnerabilities in Google Chrome before 32.0.1700.76 on Windows and before 32.0
Multiple unspecified vulnerabilities in Google Chrome before 32.0.1700.76 on Windows and before 32.0.1700.77 on Mac OS X and Linux allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2010-4574P4HIGHCVSS 7.5fixed in 8.0.552.2242010-12-22
CVE-2010-4574 [HIGH] CWE-502 CVE-2010-4574: The Pickle::Pickle function in base/pickle.cc in Google Chrome before 8.0.552.224 and Chrome OS befo
The Pickle::Pickle function in base/pickle.cc in Google Chrome before 8.0.552.224 and Chrome OS before 8.0.552.343 on 64-bit Linux platforms does not properly perform pointer arithmetic, which allows remote attackers to bypass message deserialization validation, and cause a denial of service or possibly have unspecified other impact, via invalid pickle
nvd
CVE-2013-2871P4HIGHCVSS 7.5≤ 28.0.1500.70v28.0.1500.0+61 more2013-07-10
CVE-2013-2871 [HIGH] CWE-20 CVE-2013-2871: Use-after-free vulnerability in Google Chrome before 28.0.1500.71 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 28.0.1500.71 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of input.
nvd
CVE-2013-6663P4HIGHCVSS 7.5≤ 33.0.1750.144v33.0.1750.0+104 more2014-03-05
CVE-2013-6663 [HIGH] CWE-399 CVE-2013-6663: Use-after-free vulnerability in the SVGImage::setContainerSize function in core/svg/graphics/SVGImag
Use-after-free vulnerability in the SVGImage::setContainerSize function in core/svg/graphics/SVGImage.cpp in the SVG implementation in Blink, as used in Google Chrome before 33.0.1750.146, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the resizing of a view.
nvd
CVE-2010-2902P4CRITICALCVSS 10.0fixed in 5.0.375.1252010-07-28
CVE-2010-2902 [CRITICAL] CWE-119 CVE-2010-2902: The SVG implementation in Google Chrome before 5.0.375.125 allows remote attackers to cause a denial
The SVG implementation in Google Chrome before 5.0.375.125 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2017-5037P4HIGHCVSS 7.8≤ 57.0.2987.75≤ 57.0.2987.1002017-04-24
CVE-2017-5037 [HIGH] CWE-190 CVE-2017-5037: An integer overflow in FFmpeg in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and
An integer overflow in FFmpeg in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed a remote attacker to perform an out of bounds memory write via a crafted video file, related to ChunkDemuxer.
nvd
CVE-2014-7925P4HIGHCVSS 7.5≤ 40.0.2214.852015-01-22
CVE-2014-7925 [HIGH] CVE-2014-7925: Use-after-free vulnerability in the WebAudio implementation in Blink, as used in Google Chrome befor
Use-after-free vulnerability in the WebAudio implementation in Blink, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger an audio-rendering thread in which AudioNode data is improperly maintained.
nvd
CVE-2014-7934P4HIGHCVSS 7.5≤ 40.0.2214.852015-01-22
CVE-2014-7934 [HIGH] CVE-2014-7934: Use-after-free vulnerability in the DOM implementation in Blink, as used in Google Chrome before 40.
Use-after-free vulnerability in the DOM implementation in Blink, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to unexpected absence of document data structures.
nvd
CVE-2014-3156P4HIGHCVSS 7.5≤ 35.0.1916.152v35.0.1916.0+102 more2014-06-11
CVE-2014-3156 [HIGH] CWE-119 CVE-2014-3156: Buffer overflow in the clipboard implementation in Google Chrome before 35.0.1916.153 allows remote
Buffer overflow in the clipboard implementation in Google Chrome before 35.0.1916.153 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger unexpected bitmap data, related to content/renderer/renderer_clipboard_client.cc and content/renderer/webclipboard_impl.cc.
nvd
CVE-2013-0894P4HIGHCVSS 7.5fixed in 25.0.1364.99fixed in 25.0.1364.972013-02-23
CVE-2013-0894 [HIGH] CWE-120 CVE-2013-0894: Buffer overflow in the vorbis_parse_setup_hdr_floors function in the Vorbis decoder in vorbisdec.c i
Buffer overflow in the vorbis_parse_setup_hdr_floors function in the Vorbis decoder in vorbisdec.c in libavcodec in FFmpeg through 1.1.3, as used in Google Chrome before 25.0.1364.97 on Windows and Linux and before 25.0.1364.99 on Mac OS X and other products, allows remote attackers to cause a denial of service (divide-by-zero error or out-of-bounds arr
nvd
CVE-2015-1299P4HIGHCVSS 7.5≤ 44.0.24032015-09-03
CVE-2015-1299 [HIGH] CVE-2015-1299: Use-after-free vulnerability in the shared-timer implementation in Blink, as used in Google Chrome b
Use-after-free vulnerability in the shared-timer implementation in Blink, as used in Google Chrome before 45.0.2454.85, allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging erroneous timer firing, related to ThreadTimers.cpp and Timer.cpp.
nvd
CVE-2014-3193P4HIGHCVSS 7.5≤ 38.0.2125.72014-10-08
CVE-2014-3193 [HIGH] CWE-416 CVE-2014-3193: The SessionService::GetLastSession function in browser/sessions/session_service.cc in Google Chrome
The SessionService::GetLastSession function in browser/sessions/session_service.cc in Google Chrome before 38.0.2125.101 allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via vectors that leverage "type confusion" for callback processing.
nvd