Google Chrome vulnerabilities

4,008 known vulnerabilities affecting google/chrome.

Total CVEs
4,008
CISA KEV
74
actively exploited
Public exploits
64
Exploited in wild
65
Severity breakdown
CRITICAL298HIGH2046MEDIUM1628LOW19UNKNOWN17

Vulnerabilities

Page 165 of 201
CVE-2013-0838HIGHCVSS 7.5≤ 24.0.1312.51v24.0.1272.0+119 more2013-01-15
CVE-2013-0838 [HIGH] CWE-264 CVE-2013-0838: Google Chrome before 24.0.1312.52 on Linux uses weak permissions for shared memory segments, which h Google Chrome before 24.0.1312.52 on Linux uses weak permissions for shared memory segments, which has unspecified impact and attack vectors.
nvd
CVE-2013-0832HIGHCVSS 7.5≤ 24.0.1312.51v24.0.1272.0+110 more2013-01-15
CVE-2013-0832 [HIGH] CWE-399 CVE-2013-0832: Use-after-free vulnerability in Google Chrome before 24.0.1312.52 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 24.0.1312.52 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to printing.
nvd
CVE-2012-5154HIGHCVSS 7.5≤ 24.0.1312.51v24.0.1272.0+119 more2013-01-15
CVE-2012-5154 [HIGH] CWE-189 CVE-2012-5154: Integer overflow in Google Chrome before 24.0.1312.52 on Windows allows attackers to cause a denial Integer overflow in Google Chrome before 24.0.1312.52 on Windows allows attackers to cause a denial of service or possibly have unspecified other impact via vectors related to allocation of shared memory.
nvd
CVE-2012-5153HIGHCVSS 7.5≤ 24.0.1312.51v24.0.1272.0+119 more2013-01-15
CVE-2012-5153 [HIGH] CWE-119 CVE-2012-5153: Google V8 before 3.14.5.3, as used in Google Chrome before 24.0.1312.52, allows remote attackers to Google V8 before 3.14.5.3, as used in Google Chrome before 24.0.1312.52, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that triggers an out-of-bounds access to stack memory.
nvd
CVE-2013-0837HIGHCVSS 7.5≤ 24.0.1312.51v24.0.1272.0+110 more2013-01-15
CVE-2013-0837 [HIGH] CWE-20 CVE-2013-0837: Google Chrome before 24.0.1312.52 allows remote attackers to cause a denial of service or possibly h Google Chrome before 24.0.1312.52 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of extension tabs.
nvd
CVE-2012-5148HIGHCVSS 7.5≤ 24.0.1312.51v24.0.1272.0+119 more2013-01-15
CVE-2012-5148 [HIGH] CWE-20 CVE-2012-5148: The hyphenation functionality in Google Chrome before 24.0.1312.52 does not properly validate file n The hyphenation functionality in Google Chrome before 24.0.1312.52 does not properly validate file names, which has unspecified impact and attack vectors.
nvd
CVE-2012-5150HIGHCVSS 7.5≤ 24.0.1312.51v24.0.1272.0+110 more2013-01-15
CVE-2012-5150 [HIGH] CWE-399 CVE-2012-5150: Use-after-free vulnerability in Google Chrome before 24.0.1312.52 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 24.0.1312.52 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving seek operations on video data.
nvd
CVE-2013-0831HIGHCVSS 7.5≤ 24.0.1312.51v24.0.1272.0+110 more2013-01-15
CVE-2013-0831 [HIGH] CWE-22 CVE-2013-0831: Directory traversal vulnerability in Google Chrome before 24.0.1312.52 allows remote attackers to ha Directory traversal vulnerability in Google Chrome before 24.0.1312.52 allows remote attackers to have an unspecified impact by leveraging access to an extension process.
nvd
CVE-2013-0833MEDIUMCVSS 5.0≤ 24.0.1312.51v24.0.1272.0+119 more2013-01-15
CVE-2013-0833 [MEDIUM] CWE-119 CVE-2013-0833: Google Chrome before 24.0.1312.52 allows remote attackers to cause a denial of service (out-of-bound Google Chrome before 24.0.1312.52 allows remote attackers to cause a denial of service (out-of-bounds read) via vectors related to printing.
nvd
CVE-2013-0835MEDIUMCVSS 5.0≤ 24.0.1312.51v24.0.1272.0+110 more2013-01-15
CVE-2013-0835 [MEDIUM] CVE-2013-0835: Unspecified vulnerability in the Geolocation implementation in Google Chrome before 24.0.1312.52 all Unspecified vulnerability in the Geolocation implementation in Google Chrome before 24.0.1312.52 allows remote attackers to cause a denial of service (application crash) via unknown vectors.
nvd
CVE-2012-5152MEDIUMCVSS 5.0≤ 24.0.1312.51v24.0.1272.0+119 more2013-01-15
CVE-2012-5152 [MEDIUM] CWE-119 CVE-2012-5152: Google Chrome before 24.0.1312.52 allows remote attackers to cause a denial of service (out-of-bound Google Chrome before 24.0.1312.52 allows remote attackers to cause a denial of service (out-of-bounds read) via vectors involving seek operations on video data.
nvd
CVE-2012-5157MEDIUMCVSS 4.3≤ 24.0.1312.51v24.0.1272.0+110 more2013-01-15
CVE-2012-5157 [MEDIUM] CWE-119 CVE-2012-5157: Google Chrome before 24.0.1312.52 does not properly handle image data in PDF documents, which allows Google Chrome before 24.0.1312.52 does not properly handle image data in PDF documents, which allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted document.
nvd
CVE-2012-5155MEDIUMCVSS 5.0≤ 24.0.1312.51v24.0.1272.0+119 more2013-01-15
CVE-2012-5155 [MEDIUM] CWE-264 CVE-2012-5155: Google Chrome before 24.0.1312.52 on Mac OS X does not use an appropriate sandboxing approach for wo Google Chrome before 24.0.1312.52 on Mac OS X does not use an appropriate sandboxing approach for worker processes, which makes it easier for remote attackers to bypass intended access restrictions via unspecified vectors.
nvd
CVE-2013-0828MEDIUMCVSS 6.8≤ 24.0.1312.51v24.0.1272.0+110 more2013-01-15
CVE-2013-0828 [MEDIUM] CWE-399 CVE-2013-0828: The PDF functionality in Google Chrome before 24.0.1312.52 does not properly perform a cast of an un The PDF functionality in Google Chrome before 24.0.1312.52 does not properly perform a cast of an unspecified variable during processing of the root of the structure tree, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted document.
nvd
CVE-2013-0836MEDIUMCVSS 6.8≤ 24.0.1312.51v24.0.1272.0+119 more2013-01-15
CVE-2013-0836 [MEDIUM] CWE-399 CVE-2013-0836: Google V8 before 3.14.5.3, as used in Google Chrome before 24.0.1312.52, does not properly implement Google V8 before 3.14.5.3, as used in Google Chrome before 24.0.1312.52, does not properly implement garbage collection, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted JavaScript code.
nvd
CVE-2012-5156MEDIUMCVSS 6.8≤ 24.0.1312.51v24.0.1272.0+119 more2013-01-15
CVE-2012-5156 [MEDIUM] CWE-399 CVE-2012-5156: Use-after-free vulnerability in Google Chrome before 24.0.1312.52 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 24.0.1312.52 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving PDF fields.
nvd
CVE-2013-0829MEDIUMCVSS 6.4≤ 24.0.1312.51v24.0.1272.0+110 more2013-01-15
CVE-2013-0829 [MEDIUM] CWE-264 CVE-2013-0829: Google Chrome before 24.0.1312.52 does not properly maintain database metadata, which allows remote Google Chrome before 24.0.1312.52 does not properly maintain database metadata, which allows remote attackers to bypass intended file-access restrictions via unspecified vectors.
nvd
CVE-2012-5146MEDIUMCVSS 5.0≤ 24.0.1312.51v24.0.1272.0+110 more2013-01-15
CVE-2012-5146 [MEDIUM] CWE-264 CVE-2012-5146: Google Chrome before 24.0.1312.52 allows remote attackers to bypass the Same Origin Policy via a mal Google Chrome before 24.0.1312.52 allows remote attackers to bypass the Same Origin Policy via a malformed URL.
nvd
CVE-2013-0834MEDIUMCVSS 5.0≤ 24.0.1312.51v24.0.1272.0+110 more2013-01-15
CVE-2013-0834 [MEDIUM] CWE-119 CVE-2013-0834: Google Chrome before 24.0.1312.52 allows remote attackers to cause a denial of service (out-of-bound Google Chrome before 24.0.1312.52 allows remote attackers to cause a denial of service (out-of-bounds read) via vectors involving glyphs.
nvd
CVE-2012-5151MEDIUMCVSS 6.8≤ 24.0.1312.51v24.0.1272.0+110 more2013-01-15
CVE-2012-5151 [MEDIUM] CWE-189 CVE-2012-5151: Integer overflow in Google Chrome before 24.0.1312.52 allows remote attackers to cause a denial of s Integer overflow in Google Chrome before 24.0.1312.52 allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code in a PDF document.
nvd