Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2
Vulnerabilities
Page 166 of 292
CVE-2013-6631P4HIGHCVSS 7.5≤ 31.0.1650.47v31.0.1650.0+42 more2013-11-19
CVE-2013-6631 [HIGH] CVE-2013-6631: Use-after-free vulnerability in the Channel::SendRTCPPacket function in voice_engine/channel.cc in l
Use-after-free vulnerability in the Channel::SendRTCPPacket function in voice_engine/channel.cc in libjingle in WebRTC, as used in Google Chrome before 31.0.1650.48 and other products, allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via vectors that trigger the absence of certain statistics
nvd
CVE-2014-7907P4HIGHCVSS 7.5≤ 39.0.2171.452014-11-19
CVE-2014-7907 [HIGH] CWE-399 CVE-2014-7907: Multiple use-after-free vulnerabilities in modules/screen_orientation/ScreenOrientationController.cp
Multiple use-after-free vulnerabilities in modules/screen_orientation/ScreenOrientationController.cpp in Blink, as used in Google Chrome before 39.0.2171.65, allow remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger improper handling of a detached frame, related to the (1) lock and (2) unlock
nvd
CVE-2014-7938P4HIGHCVSS 7.5≤ 40.0.2214.852015-01-22
CVE-2014-7938 [HIGH] CWE-119 CVE-2014-7938: The Fonts implementation in Google Chrome before 40.0.2214.91 allows remote attackers to cause a den
The Fonts implementation in Google Chrome before 40.0.2214.91 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2014-7932P4HIGHCVSS 7.5≤ 40.0.2214.852015-01-22
CVE-2014-7932 [HIGH] CVE-2014-7932: Use-after-free vulnerability in the Element::detach function in core/dom/Element.cpp in the DOM impl
Use-after-free vulnerability in the Element::detach function in core/dom/Element.cpp in the DOM implementation in Blink, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving pending updates of detached elements.
nvd
CVE-2014-7935P4HIGHCVSS 7.5≤ 40.0.2214.852015-01-22
CVE-2014-7935 [HIGH] CVE-2014-7935: Use-after-free vulnerability in browser/speech/tts_message_filter.cc in the Speech implementation in
Use-after-free vulnerability in browser/speech/tts_message_filter.cc in the Speech implementation in Google Chrome before 40.0.2214.91 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving utterances from a closed tab.
nvd
CVE-2015-1262P4HIGHCVSS 7.5≤ 42.0.2311.1522015-05-20
CVE-2015-1262 [HIGH] CWE-17 CVE-2015-1262: platform/fonts/shaping/HarfBuzzShaper.cpp in Blink, as used in Google Chrome before 43.0.2357.65, do
platform/fonts/shaping/HarfBuzzShaper.cpp in Blink, as used in Google Chrome before 43.0.2357.65, does not initialize a certain width field, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted Unicode text.
nvd
CVE-2015-1295P4HIGHCVSS 7.5≤ 44.0.24032015-09-03
CVE-2015-1295 [HIGH] CVE-2015-1295: Multiple use-after-free vulnerabilities in the PrintWebViewHelper class in components/printing/rende
Multiple use-after-free vulnerabilities in the PrintWebViewHelper class in components/printing/renderer/print_web_view_helper.cc in Google Chrome before 45.0.2454.85 allow user-assisted remote attackers to cause a denial of service or possibly have unspecified other impact by triggering nested IPC messages during preparation for printing, as demonstrated by mes
nvd
CVE-2015-1280P4HIGHCVSS 7.5≤ 43.0.2357.1342015-07-23
CVE-2015-1280 [HIGH] CWE-119 CVE-2015-1280: SkPictureShader.cpp in Skia, as used in Google Chrome before 44.0.2403.89, allows remote attackers t
SkPictureShader.cpp in Skia, as used in Google Chrome before 44.0.2403.89, allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging access to a renderer process and providing crafted serialized data.
nvd
CVE-2014-1742P4HIGHCVSS 7.5≤ 34.0.1847.136v34.0.1847.0+91 more2014-05-14
CVE-2014-1742 [HIGH] CWE-399 CVE-2014-1742: Use-after-free vulnerability in the FrameSelection::updateAppearance function in core/editing/FrameS
Use-after-free vulnerability in the FrameSelection::updateAppearance function in core/editing/FrameSelection.cpp in Blink, as used in Google Chrome before 34.0.1847.137, allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging improper RenderObject handling.
nvd
CVE-2015-6774P4HIGHCVSS 7.5≤ 46.0.2490.862015-12-06
CVE-2015-6774 [HIGH] CVE-2015-6774: Use-after-free vulnerability in the GetLoadTimes function in renderer/loadtimes_extension_bindings.c
Use-after-free vulnerability in the GetLoadTimes function in renderer/loadtimes_extension_bindings.cc in the Extensions implementation in Google Chrome before 47.0.2526.73 allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that modifies a pointer used for reporting loadTimes data.
nvd
CVE-2011-3114P4HIGHCVSS 7.5≤ 19.0.1084.51v19.0.1028.0+130 more2012-05-24
CVE-2011-3114 [HIGH] CWE-119 CVE-2011-3114: Multiple buffer overflows in the PDF functionality in Google Chrome before 19.0.1084.52 allow remote
Multiple buffer overflows in the PDF functionality in Google Chrome before 19.0.1084.52 allow remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger unknown function calls.
nvd
CVE-2011-3959P4HIGHCVSS 7.5fixed in 17.0.963.462012-02-09
CVE-2011-3959 [HIGH] CWE-120 CVE-2011-3959: Buffer overflow in the locale implementation in Google Chrome before 17.0.963.46 allows remote attac
Buffer overflow in the locale implementation in Google Chrome before 17.0.963.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2014-3191P4HIGHCVSS 7.5≤ 38.0.2125.72014-10-08
CVE-2014-3191 [HIGH] CWE-416 CVE-2014-3191: Use-after-free vulnerability in Blink, as used in Google Chrome before 38.0.2125.101, allows remote
Use-after-free vulnerability in Blink, as used in Google Chrome before 38.0.2125.101, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that triggers a widget-position update that improperly interacts with the render tree, related to the FrameView::updateLayoutAndStyleForPainting fu
nvd
CVE-2013-2918P4HIGHCVSS 7.5≤ 30.0.1599.65v30.0.1599.0+57 more2013-10-02
CVE-2013-2918 [HIGH] CWE-399 CVE-2013-2918: Use-after-free vulnerability in the RenderBlock::collapseAnonymousBlockChild function in core/render
Use-after-free vulnerability in the RenderBlock::collapseAnonymousBlockChild function in core/rendering/RenderBlock.cpp in the DOM implementation in Blink, as used in Google Chrome before 30.0.1599.66, allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging incorrect handling of parent-child relations
nvd
CVE-2014-1702P4HIGHCVSS 7.5≤ 33.0.1750.146v33.0.1750.0+105 more2014-03-16
CVE-2014-1702 [HIGH] CWE-399 CVE-2014-1702: Use-after-free vulnerability in the DatabaseThread::cleanupDatabaseThread function in modules/webdat
Use-after-free vulnerability in the DatabaseThread::cleanupDatabaseThread function in modules/webdatabase/DatabaseThread.cpp in the web database implementation in Blink, as used in Google Chrome before 33.0.1750.149, allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging improper handling of schedule
nvd
CVE-2012-2859P4HIGHCVSS 7.5≤ 21.0.1180.56v21.0.1180.0+22 more2012-08-06
CVE-2012-2859 [HIGH] CWE-119 CVE-2012-2859: Google Chrome before 21.0.1180.57 on Linux does not properly handle tabs, which allows remote attack
Google Chrome before 21.0.1180.57 on Linux does not properly handle tabs, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors.
nvd
CVE-2015-6760P4HIGHCVSS 7.5≤ 45.0.2454.1012015-10-15
CVE-2015-6760 [HIGH] CWE-17 CVE-2015-6760: The Image11::map function in renderer/d3d/d3d11/Image11.cpp in libANGLE, as used in Google Chrome be
The Image11::map function in renderer/d3d/d3d11/Image11.cpp in libANGLE, as used in Google Chrome before 46.0.2490.71, mishandles mapping failures after device-lost events, which allows remote attackers to cause a denial of service (invalid read or write) or possibly have unspecified other impact via vectors involving a removed device.
nvd
CVE-2014-1729P4HIGHCVSS 7.5≤ 34.0.1847.1152014-04-09
CVE-2014-1729 [HIGH] CVE-2014-1729: Multiple unspecified vulnerabilities in Google V8 before 3.24.35.22, as used in Google Chrome before
Multiple unspecified vulnerabilities in Google V8 before 3.24.35.22, as used in Google Chrome before 34.0.1847.116, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2012-5125P4HIGHCVSS 7.5≤ 23.0.1271.62v23.0.1271.0+52 more2012-11-07
CVE-2012-5125 [HIGH] CWE-416 CVE-2012-5125: Use-after-free vulnerability in Google Chrome before 23.0.1271.64 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 23.0.1271.64 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of extension tabs.
nvd
CVE-2012-5126P4HIGHCVSS 7.5≤ 23.0.1271.62v23.0.1271.0+52 more2012-11-07
CVE-2012-5126 [HIGH] CWE-416 CVE-2012-5126: Use-after-free vulnerability in Google Chrome before 23.0.1271.64 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 23.0.1271.64 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of plug-in placeholders.
nvd