Google Chrome vulnerabilities
4,008 known vulnerabilities affecting google/chrome.
Total CVEs
4,008
CISA KEV
74
actively exploited
Public exploits
64
Exploited in wild
65
Severity breakdown
CRITICAL298HIGH2025MEDIUM1626LOW17UNKNOWN42
Vulnerabilities
Page 163 of 201
CVE-2013-0904HIGHCVSS 7.5≤ 25.0.1364.126v25.0.1364.0+104 more2013-03-05
CVE-2013-0904 [HIGH] CWE-119 CVE-2013-0904: The Web Audio implementation in Google Chrome before 25.0.1364.152 allows remote attackers to cause
The Web Audio implementation in Google Chrome before 25.0.1364.152 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2013-0907HIGHCVSS 7.5≤ 25.0.1364.126v25.0.1364.0+104 more2013-03-05
CVE-2013-0907 [HIGH] CWE-362 CVE-2013-0907: Race condition in Google Chrome before 25.0.1364.152 allows remote attackers to cause a denial of se
Race condition in Google Chrome before 25.0.1364.152 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of media threads.
nvd
CVE-2013-0902HIGHCVSS 7.5≤ 25.0.1364.126v25.0.1364.0+104 more2013-03-05
CVE-2013-0902 [HIGH] CWE-399 CVE-2013-0902: Use-after-free vulnerability in the frame-loader implementation in Google Chrome before 25.0.1364.15
Use-after-free vulnerability in the frame-loader implementation in Google Chrome before 25.0.1364.152 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2013-0908HIGHCVSS 7.5≤ 25.0.1364.126v25.0.1364.0+104 more2013-03-05
CVE-2013-0908 [HIGH] CVE-2013-0908: Google Chrome before 25.0.1364.152 does not properly manage bindings of extension processes, which h
Google Chrome before 25.0.1364.152 does not properly manage bindings of extension processes, which has unspecified impact and attack vectors.
nvd
CVE-2013-0905HIGHCVSS 7.5≤ 25.0.1364.126v25.0.1364.0+104 more2013-03-05
CVE-2013-0905 [HIGH] CWE-399 CVE-2013-0905: Use-after-free vulnerability in Google Chrome before 25.0.1364.152 allows remote attackers to cause
Use-after-free vulnerability in Google Chrome before 25.0.1364.152 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving an SVG animation.
nvd
CVE-2013-0906HIGHCVSS 7.5≤ 25.0.1364.126v25.0.1364.0+104 more2013-03-05
CVE-2013-0906 [HIGH] CWE-119 CVE-2013-0906: The IndexedDB implementation in Google Chrome before 25.0.1364.152 allows remote attackers to cause
The IndexedDB implementation in Google Chrome before 25.0.1364.152 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2013-0911HIGHCVSS 7.5≤ 25.0.1364.126v25.0.1364.0+104 more2013-03-05
CVE-2013-0911 [HIGH] CWE-22 CVE-2013-0911: Directory traversal vulnerability in Google Chrome before 25.0.1364.152 allows remote attackers to h
Directory traversal vulnerability in Google Chrome before 25.0.1364.152 allows remote attackers to have an unspecified impact via vectors related to databases.
nvd
CVE-2013-0909MEDIUMCVSS 5.0≤ 25.0.1364.126v25.0.1364.0+104 more2013-03-05
CVE-2013-0909 [MEDIUM] CWE-200 CVE-2013-0909: The XSS Auditor in Google Chrome before 25.0.1364.152 allows remote attackers to obtain sensitive HT
The XSS Auditor in Google Chrome before 25.0.1364.152 allows remote attackers to obtain sensitive HTTP Referer information via unspecified vectors.
nvd
CVE-2013-0880HIGHCVSS 7.5fixed in 25.0.1364.97fixed in 25.0.1364.992013-02-23
CVE-2013-0880 [HIGH] CWE-416 CVE-2013-0880: Use-after-free vulnerability in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 2
Use-after-free vulnerability in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to databases.
nvd
CVE-2013-0885HIGHCVSS 7.5fixed in 25.0.1364.97fixed in 25.0.1364.992013-02-23
CVE-2013-0885 [HIGH] CWE-732 CVE-2013-0885: Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, does no
Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, does not properly restrict API privileges during interaction with the Chrome Web Store, which has unspecified impact and attack vectors.
nvd
CVE-2013-0892HIGHCVSS 7.5fixed in 25.0.1364.97fixed in 25.0.1364.992013-02-23
CVE-2013-0892 [HIGH] CVE-2013-0892: Multiple unspecified vulnerabilities in the IPC layer in Google Chrome before 25.0.1364.97 on Window
Multiple unspecified vulnerabilities in the IPC layer in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allow remote attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2013-2268HIGHCVSS 7.5≤ 25.0.1364.95v25.0.1364.0+87 more2013-02-23
CVE-2013-2268 [HIGH] CVE-2013-2268: Unspecified vulnerability in the MathML implementation in WebKit in Google Chrome before 25.0.1364.9
Unspecified vulnerability in the MathML implementation in WebKit in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, has unknown impact and remote attack vectors, related to a "high severity security issue."
nvd
CVE-2013-0879HIGHCVSS 7.5fixed in 25.0.1364.97fixed in 25.0.1364.992013-02-23
CVE-2013-0879 [HIGH] CWE-787 CVE-2013-0879: Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, does no
Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, does not properly implement web audio nodes, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2013-0895HIGHCVSS 7.5fixed in 25.0.1364.97fixed in 25.0.1364.992013-02-23
CVE-2013-0895 [HIGH] CWE-22 CVE-2013-0895: Google Chrome before 25.0.1364.97 on Linux, and before 25.0.1364.99 on Mac OS X, does not properly h
Google Chrome before 25.0.1364.97 on Linux, and before 25.0.1364.99 on Mac OS X, does not properly handle pathnames during copy operations, which might make it easier for remote attackers to execute arbitrary programs via unspecified vectors.
nvd
CVE-2013-0894HIGHCVSS 7.5fixed in 25.0.1364.99fixed in 25.0.1364.972013-02-23
CVE-2013-0894 [HIGH] CWE-120 CVE-2013-0894: Buffer overflow in the vorbis_parse_setup_hdr_floors function in the Vorbis decoder in vorbisdec.c i
Buffer overflow in the vorbis_parse_setup_hdr_floors function in the Vorbis decoder in vorbisdec.c in libavcodec in FFmpeg through 1.1.3, as used in Google Chrome before 25.0.1364.97 on Windows and Linux and before 25.0.1364.99 on Mac OS X and other products, allows remote attackers to cause a denial of service (divide-by-zero error or out-of-bounds arr
nvd
CVE-2013-0886HIGHCVSS 7.5≤ 25.0.1364.98v25.0.1364.0+86 more2013-02-23
CVE-2013-0886 [HIGH] CVE-2013-0886: Google Chrome before 25.0.1364.99 on Mac OS X does not properly implement signal handling for Native
Google Chrome before 25.0.1364.99 on Mac OS X does not properly implement signal handling for Native Client (aka NaCl) code, which has unspecified impact and attack vectors.
nvd
CVE-2013-0882HIGHCVSS 7.5fixed in 25.0.1364.97fixed in 25.0.1364.992013-02-23
CVE-2013-0882 [HIGH] CWE-416 CVE-2013-0882: Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allows
Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allows remote attackers to cause a denial of service (incorrect memory access) or possibly have unspecified other impact via a large number of SVG parameters.
nvd
CVE-2013-0898HIGHCVSS 7.5fixed in 25.0.1364.97fixed in 25.0.1364.992013-02-23
CVE-2013-0898 [HIGH] CWE-416 CVE-2013-0898: Use-after-free vulnerability in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 2
Use-after-free vulnerability in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving a URL.
nvd
CVE-2013-0890HIGHCVSS 7.5fixed in 25.0.1364.97fixed in 25.0.1364.992013-02-23
CVE-2013-0890 [HIGH] CWE-787 CVE-2013-0890: Multiple unspecified vulnerabilities in the IPC layer in Google Chrome before 25.0.1364.97 on Window
Multiple unspecified vulnerabilities in the IPC layer in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allow remote attackers to cause a denial of service (memory corruption) or possibly have other impact via unknown vectors.
nvd
CVE-2013-0891HIGHCVSS 7.5fixed in 25.0.1364.97fixed in 25.0.1364.992013-02-23
CVE-2013-0891 [HIGH] CWE-190 CVE-2013-0891: Integer overflow in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99
Integer overflow in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a blob.
nvd