Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2
Vulnerabilities
Page 167 of 292
CVE-2015-1219P4HIGHCVSS 7.5≤ 40.0.2214.1152015-03-09
CVE-2015-1219 [HIGH] CWE-189 CVE-2015-1219: Integer overflow in the SkMallocPixelRef::NewAllocate function in core/SkMallocPixelRef.cpp in Skia,
Integer overflow in the SkMallocPixelRef::NewAllocate function in core/SkMallocPixelRef.cpp in Skia, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger an attempted allocation of a large amount of memory during WebGL rendering.
nvd
CVE-2014-1723P4HIGHCVSS 7.5≤ 34.0.1847.1152014-04-09
CVE-2014-1723 [HIGH] CWE-20 CVE-2014-1723: The UnescapeURLWithOffsetsImpl function in net/base/escape.cc in Google Chrome before 34.0.1847.116
The UnescapeURLWithOffsetsImpl function in net/base/escape.cc in Google Chrome before 34.0.1847.116 does not properly handle bidirectional Internationalized Resource Identifiers (IRIs), which makes it easier for remote attackers to spoof URLs via crafted use of right-to-left (RTL) Unicode text.
nvd
CVE-2014-7900P4HIGHCVSS 7.5≤ 39.0.2171.452014-11-19
CVE-2014-7900 [HIGH] CWE-399 CVE-2014-7900: Use-after-free vulnerability in the CPDF_Parser::IsLinearizedFile function in fpdfapi/fpdf_parser/fp
Use-after-free vulnerability in the CPDF_Parser::IsLinearizedFile function in fpdfapi/fpdf_parser/fpdf_parser_parser.cpp in PDFium, as used in Google Chrome before 39.0.2171.65, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted PDF document.
nvd
CVE-2014-7901P4HIGHCVSS 7.5≤ 39.0.2171.452014-11-19
CVE-2014-7901 [HIGH] CWE-189 CVE-2014-7901: Integer overflow in the opj_t2_read_packet_data function in fxcodec/fx_libopenjpeg/libopenjpeg20/t2.
Integer overflow in the opj_t2_read_packet_data function in fxcodec/fx_libopenjpeg/libopenjpeg20/t2.c in OpenJPEG in PDFium, as used in Google Chrome before 39.0.2171.65, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a long segment in a JPEG image.
nvd
CVE-2011-3018P4HIGHCVSS 7.5fixed in 17.0.963.562012-02-16
CVE-2011-3018 [HIGH] CWE-787 CVE-2011-3018: Heap-based buffer overflow in Google Chrome before 17.0.963.56 allows remote attackers to cause a de
Heap-based buffer overflow in Google Chrome before 17.0.963.56 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to path rendering.
nvd
CVE-2013-6641P4HIGHCVSS 7.5fixed in 32.0.1700.77fixed in 32.0.1700.762014-01-16
CVE-2013-6641 [HIGH] CWE-416 CVE-2013-6641: Use-after-free vulnerability in the FormAssociatedElement::formRemovedFromTree function in core/html
Use-after-free vulnerability in the FormAssociatedElement::formRemovedFromTree function in core/html/FormAssociatedElement.cpp in Blink, as used in Google Chrome before 32.0.1700.76 on Windows and before 32.0.1700.77 on Mac OS X and Linux, allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging improp
nvd
CVE-2016-5127P4HIGHCVSS 7.5≤ 51.0.2704.1062016-07-23
CVE-2016-5127 [HIGH] CWE-416 CVE-2016-5127: Use-after-free vulnerability in WebKit/Source/core/editing/VisibleUnits.cpp in Blink, as used in Goo
Use-after-free vulnerability in WebKit/Source/core/editing/VisibleUnits.cpp in Blink, as used in Google Chrome before 52.0.2743.82, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code involving an @import at-rule in a Cascading Style Sheets (CSS) token sequence in conjunction with a
nvd
CVE-2013-2903P4HIGHCVSS 7.5≤ 29.0.1547.56v29.0.1547.0+49 more2013-08-21
CVE-2013-2903 [HIGH] CWE-399 CVE-2013-2903: Use-after-free vulnerability in the HTMLMediaElement::didMoveToNewDocument function in core/html/HTM
Use-after-free vulnerability in the HTMLMediaElement::didMoveToNewDocument function in core/html/HTMLMediaElement.cpp in Blink, as used in Google Chrome before 29.0.1547.57, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving moving a (1) AUDIO or (2) VIDEO element between documents.
nvd
CVE-2011-2822P4CRITICALCVSS 10.0fixed in 13.0.782.2152011-08-29
CVE-2011-2822 [CRITICAL] CWE-20 CVE-2011-2822: Google Chrome before 13.0.782.215 on Windows does not properly parse URLs located on the command lin
Google Chrome before 13.0.782.215 on Windows does not properly parse URLs located on the command line, which has unspecified impact and attack vectors.
nvd
CVE-2019-13666P4HIGHCVSS 7.4fixed in 77.0.3865.75≥ unspecified, < 77.0.3865.752019-11-25
CVE-2019-13666 [HIGH] CWE-203 CVE-2019-13666: Information leak in storage in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to leak
Information leak in storage in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2016-1677P4MEDIUMCVSS 6.5≤ 50.0.2661.1022016-06-05
CVE-2016-1677 [MEDIUM] CWE-200 CVE-2016-1677: uri.js in Google V8 before 5.1.281.26, as used in Google Chrome before 51.0.2704.63, uses an incorre
uri.js in Google V8 before 5.1.281.26, as used in Google Chrome before 51.0.2704.63, uses an incorrect array type, which allows remote attackers to obtain sensitive information by calling the decodeURI function and leveraging "type confusion."
nvd
CVE-2010-3255P4CRITICALCVSS 9.3fixed in 6.0.472.532010-09-07
CVE-2010-3255 [CRITICAL] CWE-119 CVE-2010-3255: Google Chrome before 6.0.472.53 and webkitgtk before 1.2.6 do not properly handle counter nodes, whi
Google Chrome before 6.0.472.53 and webkitgtk before 1.2.6 do not properly handle counter nodes, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2011-0475P4CRITICALCVSS 9.3fixed in 8.0.552.2372011-01-14
CVE-2011-0475 [CRITICAL] CWE-416 CVE-2011-0475: Use-after-free vulnerability in Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 al
Use-after-free vulnerability in Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a PDF document.
nvd
CVE-2020-6405P4MEDIUMCVSS 6.5fixed in 80.0.3987.87≥ unspecified, < 80.0.3987.872020-02-11
CVE-2020-6405 [MEDIUM] CWE-125 CVE-2020-6405: Out of bounds read in SQLite in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to obt
Out of bounds read in SQLite in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
nvd
CVE-2012-2834P4CRITICALCVSS 9.3≤ 20.0.1132.42v20.0.1132.0+41 more2012-06-27
CVE-2012-2834 [CRITICAL] CWE-189 CVE-2012-2834: Integer overflow in Google Chrome before 20.0.1132.43 allows remote attackers to cause a denial of s
Integer overflow in Google Chrome before 20.0.1132.43 allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted data in the Matroska container format.
nvd
CVE-2013-0889P4MEDIUMCVSS 6.8fixed in 25.0.1364.97fixed in 25.0.1364.992013-02-23
CVE-2013-0889 [MEDIUM] CWE-863 CVE-2013-0889: Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, does no
Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, does not properly enforce a user gesture requirement before proceeding with a file download, which might make it easier for remote attackers to execute arbitrary code via a crafted file.
nvd
CVE-2018-6091P4MEDIUMCVSS 6.5fixed in 66.0.3359.117≥ unspecified, < 66.0.3359.1172019-01-09
CVE-2018-6091 [MEDIUM] CWE-19 CVE-2018-6091: Service Workers can intercept any request made by an <embed> or <object> tag in Fetch API in Google
Service Workers can intercept any request made by an or tag in Fetch API in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2011-3067P4MEDIUMCVSS 6.8fixed in 18.0.1025.1512012-04-05
CVE-2011-3067 [MEDIUM] CWE-346 CVE-2011-3067: Google Chrome before 18.0.1025.151 allows remote attackers to bypass the Same Origin Policy via vect
Google Chrome before 18.0.1025.151 allows remote attackers to bypass the Same Origin Policy via vectors related to replacement of IFRAME elements.
nvd
CVE-2020-6400P4MEDIUMCVSS 6.5fixed in 80.0.3987.87≥ unspecified, < 80.0.3987.872020-02-11
CVE-2020-6400 [MEDIUM] CWE-203 CVE-2020-6400: Inappropriate implementation in CORS in Google Chrome prior to 80.0.3987.87 allowed a remote attacke
Inappropriate implementation in CORS in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2020-6399P4MEDIUMCVSS 6.5fixed in 80.0.3987.87≥ unspecified, < 80.0.3987.872020-02-11
CVE-2020-6399 [MEDIUM] CWE-20 CVE-2020-6399: Insufficient policy enforcement in AppCache in Google Chrome prior to 80.0.3987.87 allowed a remote
Insufficient policy enforcement in AppCache in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd