Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2
Vulnerabilities
Page 153 of 292
CVE-2015-6778P4HIGHCVSS 7.5≤ 46.0.2490.862015-12-06
CVE-2015-6778 [HIGH] CWE-119 CVE-2015-6778: The CJBig2_SymbolDict class in fxcodec/jbig2/JBig2_SymbolDict.cpp in PDFium, as used in Google Chrom
The CJBig2_SymbolDict class in fxcodec/jbig2/JBig2_SymbolDict.cpp in PDFium, as used in Google Chrome before 47.0.2526.73, allows remote attackers to cause a denial of service (out-of-bounds memory access) or possibly have unspecified other impact via a PDF document containing crafted data with JBIG2 compression.
nvd
CVE-2015-1237P4HIGHCVSS 7.5≤ 42.0.2311.602015-04-19
CVE-2015-1237 [HIGH] CVE-2015-1237: Use-after-free vulnerability in the RenderFrameImpl::OnMessageReceived function in content/renderer/
Use-after-free vulnerability in the RenderFrameImpl::OnMessageReceived function in content/renderer/render_frame_impl.cc in Google Chrome before 42.0.2311.90 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger renderer IPC messages during a detach operation.
nvd
CVE-2014-3165P4HIGHCVSS 7.5≤ 36.0.1985.142v36.0.1985.1+116 more2014-08-13
CVE-2014-3165 [HIGH] CVE-2014-3165: Use-after-free vulnerability in modules/websockets/WorkerThreadableWebSocketChannel.cpp in the Web S
Use-after-free vulnerability in modules/websockets/WorkerThreadableWebSocketChannel.cpp in the Web Sockets implementation in Blink, as used in Google Chrome before 36.0.1985.143, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger an unexpectedly long lifetime of a temporary object during metho
nvd
CVE-2014-3154P4HIGHCVSS 7.5≤ 35.0.1916.152v35.0.1916.0+102 more2014-06-11
CVE-2014-3154 [HIGH] CVE-2014-3154: Use-after-free vulnerability in the ChildThread::Shutdown function in content/child/child_thread.cc
Use-after-free vulnerability in the ChildThread::Shutdown function in content/child/child_thread.cc in the filesystem API in Google Chrome before 35.0.1916.153 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to a Blink shutdown.
nvd
CVE-2015-6757P4HIGHCVSS 7.5≤ 45.0.2454.1012015-10-15
CVE-2015-6757 [HIGH] CVE-2015-6757: Use-after-free vulnerability in content/browser/service_worker/embedded_worker_instance.cc in the Se
Use-after-free vulnerability in content/browser/service_worker/embedded_worker_instance.cc in the ServiceWorker implementation in Google Chrome before 46.0.2490.71 allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging object destruction in a callback.
nvd
CVE-2015-1260P4HIGHCVSS 7.5≤ 42.0.2311.1522015-05-20
CVE-2015-1260 [HIGH] CVE-2015-1260: Multiple use-after-free vulnerabilities in content/renderer/media/user_media_client_impl.cc in the W
Multiple use-after-free vulnerabilities in content/renderer/media/user_media_client_impl.cc in the WebRTC implementation in Google Chrome before 43.0.2357.65 allow remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that executes upon completion of a getUserMedia request.
nvd
CVE-2014-1740P4HIGHCVSS 7.5≤ 34.0.1847.136v34.0.1847.0+91 more2014-05-14
CVE-2014-1740 [HIGH] CWE-399 CVE-2014-1740: Multiple use-after-free vulnerabilities in net/websockets/websocket_job.cc in the WebSockets impleme
Multiple use-after-free vulnerabilities in net/websockets/websocket_job.cc in the WebSockets implementation in Google Chrome before 34.0.1847.137 allow remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to WebSocketJob deletion.
nvd
CVE-2013-2909P4HIGHCVSS 7.5≤ 30.0.1599.65v30.0.1599.0+57 more2013-10-02
CVE-2013-2909 [HIGH] CWE-399 CVE-2013-2909: Use-after-free vulnerability in Blink, as used in Google Chrome before 30.0.1599.66, allows remote a
Use-after-free vulnerability in Blink, as used in Google Chrome before 30.0.1599.66, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to inline-block rendering for bidirectional Unicode text in an element isolated from its siblings.
nvd
CVE-2011-3081P4CRITICALCVSS 9.3fixed in 18.0.1025.1682012-05-01
CVE-2011-3081 [CRITICAL] CVE-2011-3081: Use-after-free vulnerability in Google Chrome before 18.0.1025.168 allows remote attackers to cause
Use-after-free vulnerability in Google Chrome before 18.0.1025.168 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the floating of elements, a different vulnerability than CVE-2011-3078.
nvd
CVE-2014-7904P4HIGHCVSS 7.5≤ 39.0.2171.452014-11-19
CVE-2014-7904 [HIGH] CWE-119 CVE-2014-7904: Buffer overflow in Skia, as used in Google Chrome before 39.0.2171.65, allows remote attackers to ca
Buffer overflow in Skia, as used in Google Chrome before 39.0.2171.65, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2015-1272P4HIGHCVSS 7.5≤ 43.0.2357.1342015-07-23
CVE-2015-1272 [HIGH] CVE-2015-1272: Use-after-free vulnerability in the GPU process implementation in Google Chrome before 44.0.2403.89
Use-after-free vulnerability in the GPU process implementation in Google Chrome before 44.0.2403.89 allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging the continued availability of a GPUChannelHost data structure during Blink shutdown, related to content/browser/gpu/browser_gpu_channel_host_factory.cc and
nvd
CVE-2014-3171P4HIGHCVSS 7.5≤ 37.0.2062.93v37.0.2062.0+80 more2014-08-27
CVE-2014-3171 [HIGH] CVE-2014-3171: Use-after-free vulnerability in the V8 bindings in Blink, as used in Google Chrome before 37.0.2062.
Use-after-free vulnerability in the V8 bindings in Blink, as used in Google Chrome before 37.0.2062.94, allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging improper use of HashMap add operations instead of HashMap set operations, related to bindings/core/v8/DOMWrapperMap.h and bindings/core/v8/SerializedS
nvd
CVE-2014-7908P4HIGHCVSS 7.5≤ 39.0.2171.452014-11-19
CVE-2014-7908 [HIGH] CWE-189 CVE-2014-7908: Multiple integer overflows in the CheckMov function in media/base/container_names.cc in Google Chrom
Multiple integer overflows in the CheckMov function in media/base/container_names.cc in Google Chrome before 39.0.2171.65 allow remote attackers to cause a denial of service or possibly have unspecified other impact via a large atom in (1) MPEG-4 or (2) QuickTime .mov data.
nvd
CVE-2014-7929P4HIGHCVSS 7.5≤ 40.0.2214.852015-01-22
CVE-2014-7929 [HIGH] CWE-17 CVE-2014-7929: Use-after-free vulnerability in the HTMLScriptElement::didMoveToNewDocument function in core/html/HT
Use-after-free vulnerability in the HTMLScriptElement::didMoveToNewDocument function in core/html/HTMLScriptElement.cpp in the DOM implementation in Blink, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving movement of a SCRIPT element across d
nvd
CVE-2015-6777P4HIGHCVSS 7.5≤ 46.0.2490.862015-12-06
CVE-2015-6777 [HIGH] CVE-2015-6777: Use-after-free vulnerability in the ContainerNode::notifyNodeInsertedInternal function in WebKit/Sou
Use-after-free vulnerability in the ContainerNode::notifyNodeInsertedInternal function in WebKit/Source/core/dom/ContainerNode.cpp in the DOM implementation in Google Chrome before 47.0.2526.73 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to DOMCharacterDataModified events for certain detache
nvd
CVE-2016-5139P4HIGHCVSS 7.6v52.0.2743.822016-08-07
CVE-2016-5139 [HIGH] CWE-119 CVE-2016-5139: Multiple integer overflows in the opj_tcd_init_tile function in tcd.c in OpenJPEG, as used in PDFium
Multiple integer overflows in the opj_tcd_init_tile function in tcd.c in OpenJPEG, as used in PDFium in Google Chrome before 52.0.2743.116, allow remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted JPEG 2000 data.
nvd
CVE-2014-7903P4HIGHCVSS 7.5≤ 39.0.2171.452014-11-19
CVE-2014-7903 [HIGH] CWE-119 CVE-2014-7903: Buffer overflow in OpenJPEG before r2911 in PDFium, as used in Google Chrome before 39.0.2171.65, al
Buffer overflow in OpenJPEG before r2911 in PDFium, as used in Google Chrome before 39.0.2171.65, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted JPEG image.
nvd
CVE-2015-8548P4CRITICALCVSS 10.0≤ 47.0.2526.732015-12-14
CVE-2015-8548 [CRITICAL] CVE-2015-8548: Multiple unspecified vulnerabilities in Google V8 before 4.7.80.23, as used in Google Chrome before
Multiple unspecified vulnerabilities in Google V8 before 4.7.80.23, as used in Google Chrome before 47.0.2526.80, allow attackers to cause a denial of service or possibly have other impact via unknown vectors, a different issue than CVE-2015-8478.
nvd
CVE-2010-1231P4HIGHCVSS 7.5≤ 4.1.249.1035v0.2.149.27+82 more2010-04-01
CVE-2010-1231 [HIGH] CVE-2010-1231: Google Chrome before 4.1.249.1036 processes HTTP headers before invoking the SafeBrowsing feature, w
Google Chrome before 4.1.249.1036 processes HTTP headers before invoking the SafeBrowsing feature, which allows remote attackers to have an unspecified impact via crafted headers.
nvd
CVE-2015-1216P4HIGHCVSS 7.5≤ 40.0.2214.1152015-03-09
CVE-2015-1216 [HIGH] CVE-2015-1216: Use-after-free vulnerability in the V8Window::namedPropertyGetterCustom function in bindings/core/v8
Use-after-free vulnerability in the V8Window::namedPropertyGetterCustom function in bindings/core/v8/custom/V8WindowCustom.cpp in the V8 bindings in Blink, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger a frame detachment.
nvd