Google Chrome vulnerabilities
4,008 known vulnerabilities affecting google/chrome.
Total CVEs
4,008
CISA KEV
74
actively exploited
Public exploits
64
Exploited in wild
65
Severity breakdown
CRITICAL298HIGH2046MEDIUM1628LOW19UNKNOWN17
Vulnerabilities
Page 166 of 201
CVE-2012-5140CRITICALCVSS 10.0≤ 23.0.1271.96v23.0.1271.0+66 more2012-12-12
CVE-2012-5140 [CRITICAL] CWE-416 CVE-2012-5140: Use-after-free vulnerability in Google Chrome before 23.0.1271.97 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 23.0.1271.97 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the URL loader.
nvd
CVE-2012-5141CRITICALCVSS 10.0≤ 23.0.1271.96v23.0.1271.0+66 more2012-12-12
CVE-2012-5141 [CRITICAL] CVE-2012-5141: Google Chrome before 23.0.1271.97 does not properly restrict instantiation of the Chromoting client
Google Chrome before 23.0.1271.97 does not properly restrict instantiation of the Chromoting client plug-in, which has unspecified impact and attack vectors.
nvd
CVE-2012-5143CRITICALCVSS 10.0≤ 23.0.1271.96v23.0.1271.0+66 more2012-12-12
CVE-2012-5143 [CRITICAL] CWE-190 CVE-2012-5143: Integer overflow in Google Chrome before 23.0.1271.97 allows remote attackers to cause a denial of s
Integer overflow in Google Chrome before 23.0.1271.97 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to PPAPI image buffers.
nvd
CVE-2012-5142CRITICALCVSS 10.0≤ 23.0.1271.96v23.0.1271.0+66 more2012-12-12
CVE-2012-5142 [CRITICAL] CWE-94 CVE-2012-5142: Google Chrome before 23.0.1271.97 does not properly handle history navigation, which allows remote a
Google Chrome before 23.0.1271.97 does not properly handle history navigation, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors.
nvd
CVE-2012-5144CRITICALCVSS 10.0≤ 23.0.1271.96v23.0.1271.0+66 more2012-12-12
CVE-2012-5144 [CRITICAL] CWE-119 CVE-2012-5144: Google Chrome before 23.0.1271.97, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.5, do not prope
Google Chrome before 23.0.1271.97, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.5, do not properly perform AAC decoding, which allows remote attackers to cause a denial of service (stack memory corruption) or possibly have unspecified other impact via vectors related to "an off-by-one overwrite when switching to LTP profile from MAIN."
nvd
CVE-2012-5139CRITICALCVSS 10.0≤ 23.0.1271.96v23.0.1271.0+66 more2012-12-12
CVE-2012-5139 [CRITICAL] CWE-416 CVE-2012-5139: Use-after-free vulnerability in Google Chrome before 23.0.1271.97 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 23.0.1271.97 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to visibility events.
nvd
CVE-2012-5137CRITICALCVSS 10.0≤ 23.0.1271.94v23.0.1271.0+64 more2012-12-04
CVE-2012-5137 [CRITICAL] CWE-416 CVE-2012-5137: Use-after-free vulnerability in Google Chrome before 23.0.1271.95 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 23.0.1271.95 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the Media Source API.
nvd
CVE-2012-5138CRITICALCVSS 10.0≤ 23.0.1271.94v23.0.1271.0+64 more2012-12-04
CVE-2012-5138 [CRITICAL] CVE-2012-5138: Google Chrome before 23.0.1271.95 does not properly handle file paths, which has unspecified impact
Google Chrome before 23.0.1271.95 does not properly handle file paths, which has unspecified impact and attack vectors.
nvd
CVE-2012-5129HIGHCVSS 7.5v23.0.1271.91v23.0.1271.922012-12-04
CVE-2012-5129 [HIGH] CWE-119 CVE-2012-5129: Heap-based buffer overflow in the WebGL subsystem in Google Chrome OS before 23.0.1271.94 allows rem
Heap-based buffer overflow in the WebGL subsystem in Google Chrome OS before 23.0.1271.94 allows remote attackers to cause a denial of service (GPU process crash) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2012-5131HIGHCVSS 7.5≤ 23.0.1271.89v23.0.1271.0+60 more2012-11-28
CVE-2012-5131 [HIGH] CVE-2012-5131: Google Chrome before 23.0.1271.91 on Mac OS X does not properly mitigate improper rendering behavior
Google Chrome before 23.0.1271.91 on Mac OS X does not properly mitigate improper rendering behavior in the Intel GPU driver, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2012-5135HIGHCVSS 7.5≤ 23.0.1271.89v23.0.1271.0+60 more2012-11-28
CVE-2012-5135 [HIGH] CWE-399 CVE-2012-5135: Use-after-free vulnerability in Google Chrome before 23.0.1271.91 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 23.0.1271.91 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to printing.
nvd
CVE-2012-5133HIGHCVSS 7.5≤ 23.0.1271.89v23.0.1271.0+60 more2012-11-28
CVE-2012-5133 [HIGH] CWE-416 CVE-2012-5133: Use-after-free vulnerability in Google Chrome before 23.0.1271.91 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 23.0.1271.91 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to SVG filters.
nvd
CVE-2012-5130MEDIUMCVSS 5.0≤ 23.0.1271.89v23.0.1271.0+60 more2012-11-28
CVE-2012-5130 [MEDIUM] CWE-125 CVE-2012-5130: Skia, as used in Google Chrome before 23.0.1271.91, allows remote attackers to cause a denial of ser
Skia, as used in Google Chrome before 23.0.1271.91, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2012-5132MEDIUMCVSS 5.0≤ 23.0.1271.89v23.0.1271.0+60 more2012-11-28
CVE-2012-5132 [MEDIUM] CVE-2012-5132: Google Chrome before 23.0.1271.91 allows remote attackers to cause a denial of service (application
Google Chrome before 23.0.1271.91 allows remote attackers to cause a denial of service (application crash) via a response with chunked transfer coding.
nvd
CVE-2012-5136MEDIUMCVSS 6.8≤ 23.0.1271.89v23.0.1271.0+60 more2012-11-28
CVE-2012-5136 [MEDIUM] CWE-20 CVE-2012-5136: Google Chrome before 23.0.1271.91 does not properly perform a cast of an unspecified variable during
Google Chrome before 23.0.1271.91 does not properly perform a cast of an unspecified variable during handling of the INPUT element, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted HTML document.
nvd
CVE-2012-5134MEDIUMCVSS 6.8≤ 23.0.1271.89v23.0.1271.0+58 more2012-11-28
CVE-2012-5134 [MEDIUM] CWE-119 CVE-2012-5134: Heap-based buffer underflow in the xmlParseAttValueComplex function in parser.c in libxml2 2.9.0 and
Heap-based buffer underflow in the xmlParseAttValueComplex function in parser.c in libxml2 2.9.0 and earlier, as used in Google Chrome before 23.0.1271.91 and other products, allows remote attackers to cause a denial of service or possibly execute arbitrary code via crafted entities in an XML document.
nvd
CVE-2012-5851MEDIUMCVSS 4.3PoC≤ 22.0.1229.96v22.0.1229.0+58 more2012-11-15
CVE-2012-5851 [MEDIUM] CWE-79 CVE-2012-5851: html/parser/XSSAuditor.cpp in WebCore in WebKit, as used in Google Chrome through 22 and Safari 5.1.
html/parser/XSSAuditor.cpp in WebCore in WebKit, as used in Google Chrome through 22 and Safari 5.1.7, does not consider all possible output contexts of reflected data, which makes it easier for remote attackers to bypass a cross-site scripting (XSS) protection mechanism via a crafted string, aka rdar problem 12019108.
nvd
CVE-2012-5117HIGHCVSS 7.5≤ 23.0.1271.62v23.0.1271.0+52 more2012-11-07
CVE-2012-5117 [HIGH] CWE-264 CVE-2012-5117: Google Chrome before 23.0.1271.64 does not properly restrict the loading of an SVG subresource in th
Google Chrome before 23.0.1271.64 does not properly restrict the loading of an SVG subresource in the context of an IMG element, which has unspecified impact and remote attack vectors.
nvd
CVE-2012-5120HIGHCVSS 7.5≤ 23.0.1271.62v23.0.1271.0+52 more2012-11-07
CVE-2012-5120 [HIGH] CWE-119 CVE-2012-5120: Google V8 before 3.13.7.5, as used in Google Chrome before 23.0.1271.64, on 64-bit Linux platforms a
Google V8 before 3.13.7.5, as used in Google Chrome before 23.0.1271.64, on 64-bit Linux platforms allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that triggers an out-of-bounds access to an array.
nvd
CVE-2012-5116HIGHCVSS 7.5≤ 23.0.1271.62v23.0.1271.0+52 more2012-11-07
CVE-2012-5116 [HIGH] CWE-416 CVE-2012-5116: Use-after-free vulnerability in Google Chrome before 23.0.1271.64 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 23.0.1271.64 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of SVG filters.
nvd