cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2

Vulnerabilities

Page 165 of 292
CVE-2014-1714P4HIGHCVSS 7.5fixed in 33.0.1750.152fixed in 33.0.1750.1542014-03-16
CVE-2014-1714 [HIGH] CWE-20 CVE-2014-1714: The ScopedClipboardWriter::WritePickledData function in ui/base/clipboard/scoped_clipboard_writer.cc The ScopedClipboardWriter::WritePickledData function in ui/base/clipboard/scoped_clipboard_writer.cc in Google Chrome before 33.0.1750.152 on OS X and Linux and before 33.0.1750.154 on Windows does not verify a certain format value, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to
nvd
CVE-2015-1205P4HIGHCVSS 7.5≤ 40.0.2214.852015-01-22
CVE-2015-1205 [HIGH] CVE-2015-1205: Multiple unspecified vulnerabilities in Google Chrome before 40.0.2214.91 allow attackers to cause a Multiple unspecified vulnerabilities in Google Chrome before 40.0.2214.91 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2010-3415P4CRITICALCVSS 10.0fixed in 6.0.472.592010-09-16
CVE-2010-3415 [CRITICAL] CWE-119 CVE-2010-3415: Google Chrome before 6.0.472.59 does not properly implement Geolocation, which allows remote attacke Google Chrome before 6.0.472.59 does not properly implement Geolocation, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2014-7931P4HIGHCVSS 7.5≤ 40.0.2214.852015-01-22
CVE-2014-7931 [HIGH] CWE-17 CVE-2014-7931: factory.cc in Google V8, as used in Google Chrome before 40.0.2214.91, allows remote attackers to ca factory.cc in Google V8, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via crafted JavaScript code that triggers improper maintenance of backing-store pointers.
nvd
CVE-2010-1823P4CRITICALCVSS 9.3fixed in 6.0.472.592010-09-24
CVE-2010-1823 [CRITICAL] CWE-416 CVE-2010-1823: Use-after-free vulnerability in WebKit before r65958, as used in Google Chrome before 6.0.472.59, al Use-after-free vulnerability in WebKit before r65958, as used in Google Chrome before 6.0.472.59, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger use of document APIs such as document.close during parsing, as demonstrated by a Cascading Style Sheets (CSS) file referencing an inv
nvd
CVE-2014-1734P4HIGHCVSS 7.5fixed in 34.0.1847.131fixed in 34.0.1847.1322014-04-26
CVE-2014-1734 [HIGH] CVE-2014-1734: Multiple unspecified vulnerabilities in Google Chrome before 34.0.1847.131 on Windows and OS X and b Multiple unspecified vulnerabilities in Google Chrome before 34.0.1847.131 on Windows and OS X and before 34.0.1847.132 on Linux allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2013-6621P4HIGHCVSS 7.5≤ 31.0.1650.47v31.0.1650.0+42 more2013-11-13
CVE-2013-6621 [HIGH] CWE-399 CVE-2013-6621: Use-after-free vulnerability in Google Chrome before 31.0.1650.48 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 31.0.1650.48 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the x-webkit-speech attribute in a text INPUT element.
nvd
CVE-2011-1292P4HIGHCVSS 7.5fixed in 10.0.648.2042011-03-25
CVE-2011-1292 [HIGH] CWE-416 CVE-2011-1292: Use-after-free vulnerability in the frame-loader implementation in Google Chrome before 10.0.648.204 Use-after-free vulnerability in the frame-loader implementation in Google Chrome before 10.0.648.204 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2013-6639P4HIGHCVSS 7.5≤ 31.0.1650.62v31.0.1650.0+56 more2013-12-07
CVE-2013-6639 [HIGH] CWE-119 CVE-2013-6639: The DehoistArrayIndex function in hydrogen-dehoist.cc (aka hydrogen.cc) in Google V8 before 3.22.24. The DehoistArrayIndex function in hydrogen-dehoist.cc (aka hydrogen.cc) in Google V8 before 3.22.24.7, as used in Google Chrome before 31.0.1650.63, allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via JavaScript code that sets the value of an array element with a crafted index.
nvd
CVE-2014-3168P4HIGHCVSS 7.5≤ 37.0.2062.93v37.0.2062.0+80 more2014-08-27
CVE-2014-3168 [HIGH] CVE-2014-3168: Use-after-free vulnerability in the SVG implementation in Blink, as used in Google Chrome before 37. Use-after-free vulnerability in the SVG implementation in Blink, as used in Google Chrome before 37.0.2062.94, allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging improper caching associated with animation.
nvd
CVE-2012-2843P4HIGHCVSS 7.5≤ 20.0.1132.56v20.0.1132.0+48 more2012-07-12
CVE-2012-2843 [HIGH] CWE-399 CVE-2012-2843: Use-after-free vulnerability in Google Chrome before 20.0.1132.57 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 20.0.1132.57 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to layout height tracking.
nvd
CVE-2015-1215P4HIGHCVSS 7.5≤ 40.0.2214.1152015-03-09
CVE-2015-1215 [HIGH] CWE-119 CVE-2015-1215: The filters implementation in Skia, as used in Google Chrome before 41.0.2272.76, allows remote atta The filters implementation in Skia, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger an out-of-bounds write operation.
nvd
CVE-2011-3924P4HIGHCVSS 7.5fixed in 16.0.912.772012-01-24
CVE-2011-3924 [HIGH] CWE-416 CVE-2011-3924: Use-after-free vulnerability in Google Chrome before 16.0.912.77 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 16.0.912.77 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to DOM selections.
nvd
CVE-2011-3928P4HIGHCVSS 7.5fixed in 16.0.912.772012-01-24
CVE-2011-3928 [HIGH] CWE-416 CVE-2011-3928: Use-after-free vulnerability in Google Chrome before 16.0.912.77 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 16.0.912.77 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to DOM handling.
nvd
CVE-2012-2818P4HIGHCVSS 7.5≤ 20.0.1132.42v20.0.1132.0+41 more2012-06-27
CVE-2012-2818 [HIGH] CWE-399 CVE-2012-2818: Use-after-free vulnerability in Google Chrome before 20.0.1132.43 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 20.0.1132.43 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the layout of documents that use the Cascading Style Sheets (CSS) counters feature.
nvd
CVE-2010-1505P4CRITICALCVSS 10.0≤ 4.1.249.1058v1.0.154.53+232 more2010-04-23
CVE-2010-1505 [CRITICAL] CWE-264 CVE-2010-1505: Google Chrome before 4.1.249.1059 does not prevent pages from loading with the New Tab page's privil Google Chrome before 4.1.249.1059 does not prevent pages from loading with the New Tab page's privileges, which has unknown impact and attack vectors.
nvd
CVE-2013-2904P4HIGHCVSS 7.5≤ 29.0.1547.56v29.0.1547.0+49 more2013-08-21
CVE-2013-2904 [HIGH] CWE-399 CVE-2013-2904: Use-after-free vulnerability in the Document::finishedParsing function in core/dom/Document.cpp in B Use-after-free vulnerability in the Document::finishedParsing function in core/dom/Document.cpp in Blink, as used in Google Chrome before 29.0.1547.57, allows remote attackers to cause a denial of service or possibly have unspecified other impact via an onload event that changes an IFRAME element so that its src attribute is no longer an XML document, l
nvd
CVE-2012-5121P4HIGHCVSS 7.5≤ 23.0.1271.62v23.0.1271.0+52 more2012-11-07
CVE-2012-5121 [HIGH] CWE-416 CVE-2012-5121: Use-after-free vulnerability in Google Chrome before 23.0.1271.64 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 23.0.1271.64 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to video layout.
nvd
CVE-2015-1257P4HIGHCVSS 7.5≤ 42.0.2311.1522015-05-20
CVE-2015-1257 [HIGH] CWE-119 CVE-2015-1257: platform/graphics/filters/FEColorMatrix.cpp in the SVG implementation in Blink, as used in Google Ch platform/graphics/filters/FEColorMatrix.cpp in the SVG implementation in Blink, as used in Google Chrome before 43.0.2357.65, does not properly handle an insufficient number of values in an feColorMatrix filter, which allows remote attackers to cause a denial of service (container overflow) or possibly have unspecified other impact via a crafted documen
nvd
CVE-2015-1277P4HIGHCVSS 7.5≤ 43.0.2357.1342015-07-23
CVE-2015-1277 [HIGH] CVE-2015-1277: Use-after-free vulnerability in the accessibility implementation in Google Chrome before 44.0.2403.8 Use-after-free vulnerability in the accessibility implementation in Google Chrome before 44.0.2403.89 allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging lack of certain validity checks for accessibility-tree data structures.
nvd
Google Chrome vulnerabilities | cvebase