Google Chrome vulnerabilities
4,008 known vulnerabilities affecting google/chrome.
Total CVEs
4,008
CISA KEV
74
actively exploited
Public exploits
64
Exploited in wild
65
Severity breakdown
CRITICAL300HIGH2051MEDIUM1628LOW19UNKNOWN10
Vulnerabilities
Page 167 of 201
CVE-2012-5115HIGHCVSS 7.5≤ 23.0.1271.62v23.0.1271.0+52 more2012-11-07
CVE-2012-5115 [HIGH] CWE-119 CVE-2012-5115: Google Chrome before 23.0.1271.64 on Mac OS X does not properly mitigate improper write behavior in
Google Chrome before 23.0.1271.64 on Mac OS X does not properly mitigate improper write behavior in graphics drivers, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that trigger "wild writes."
nvd
CVE-2012-5125HIGHCVSS 7.5≤ 23.0.1271.62v23.0.1271.0+52 more2012-11-07
CVE-2012-5125 [HIGH] CWE-416 CVE-2012-5125: Use-after-free vulnerability in Google Chrome before 23.0.1271.64 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 23.0.1271.64 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of extension tabs.
nvd
CVE-2012-5127HIGHCVSS 7.5≤ 23.0.1271.62v23.0.1271.0+52 more2012-11-07
CVE-2012-5127 [HIGH] CWE-189 CVE-2012-5127: Integer overflow in Google Chrome before 23.0.1271.64 allows remote attackers to cause a denial of s
Integer overflow in Google Chrome before 23.0.1271.64 allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted WebP image.
nvd
CVE-2012-5118HIGHCVSS 7.5≤ 23.0.1271.62v23.0.1271.0+52 more2012-11-07
CVE-2012-5118 [HIGH] CWE-20 CVE-2012-5118: Google Chrome before 23.0.1271.64 on Mac OS X does not properly validate an integer value during the
Google Chrome before 23.0.1271.64 on Mac OS X does not properly validate an integer value during the handling of GPU command buffers, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2012-5128HIGHCVSS 7.5≤ 23.0.1271.62v23.0.1271.0+52 more2012-11-07
CVE-2012-5128 [HIGH] CWE-119 CVE-2012-5128: Google V8 before 3.13.7.5, as used in Google Chrome before 23.0.1271.64, does not properly perform w
Google V8 before 3.13.7.5, as used in Google Chrome before 23.0.1271.64, does not properly perform write operations, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2012-5124HIGHCVSS 7.5≤ 23.0.1271.62v23.0.1271.0+52 more2012-11-07
CVE-2012-5124 [HIGH] CWE-119 CVE-2012-5124: Google Chrome before 23.0.1271.64 does not properly handle textures, which allows remote attackers t
Google Chrome before 23.0.1271.64 does not properly handle textures, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2012-5121HIGHCVSS 7.5≤ 23.0.1271.62v23.0.1271.0+52 more2012-11-07
CVE-2012-5121 [HIGH] CWE-416 CVE-2012-5121: Use-after-free vulnerability in Google Chrome before 23.0.1271.64 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 23.0.1271.64 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to video layout.
nvd
CVE-2012-5126HIGHCVSS 7.5≤ 23.0.1271.62v23.0.1271.0+52 more2012-11-07
CVE-2012-5126 [HIGH] CWE-416 CVE-2012-5126: Use-after-free vulnerability in Google Chrome before 23.0.1271.64 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 23.0.1271.64 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of plug-in placeholders.
nvd
CVE-2012-5122HIGHCVSS 7.5≤ 23.0.1271.62v23.0.1271.0+52 more2012-11-07
CVE-2012-5122 [HIGH] CWE-399 CVE-2012-5122: Google Chrome before 23.0.1271.64 does not properly perform a cast of an unspecified variable during
Google Chrome before 23.0.1271.64 does not properly perform a cast of an unspecified variable during handling of input, which allows remote attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2012-5123MEDIUMCVSS 5.0≤ 23.0.1271.62v23.0.1271.0+52 more2012-11-07
CVE-2012-5123 [MEDIUM] CWE-119 CVE-2012-5123: Skia, as used in Google Chrome before 23.0.1271.64, allows remote attackers to cause a denial of ser
Skia, as used in Google Chrome before 23.0.1271.64, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2012-5119MEDIUMCVSS 6.8≤ 23.0.1271.62v23.0.1271.0+52 more2012-11-07
CVE-2012-5119 [MEDIUM] CWE-362 CVE-2012-5119: Race condition in Pepper, as used in Google Chrome before 23.0.1271.64, allows remote attackers to c
Race condition in Pepper, as used in Google Chrome before 23.0.1271.64, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to buffers.
nvd
CVE-2012-5112CRITICALCVSS 10.0≤ 22.0.1229.92v22.0.1229.0+55 more2012-10-11
CVE-2012-5112 [CRITICAL] CWE-399 CVE-2012-5112: Use-after-free vulnerability in the SVG implementation in WebKit, as used in Google Chrome before 22
Use-after-free vulnerability in the SVG implementation in WebKit, as used in Google Chrome before 22.0.1229.94, allows remote attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2012-5376CRITICALCVSS 9.6fixed in 22.0.1229.942012-10-11
CVE-2012-5376 [CRITICAL] CVE-2012-5376: The Inter-process Communication (IPC) implementation in Google Chrome before 22.0.1229.94 allows rem
The Inter-process Communication (IPC) implementation in Google Chrome before 22.0.1229.94 allows remote attackers to bypass intended sandbox restrictions and write to arbitrary files by leveraging access to a renderer process, a different vulnerability than CVE-2012-5112.
nvd
CVE-2012-5108CRITICALCVSS 9.3≤ 22.0.1229.91v22.0.1229.0+54 more2012-10-09
CVE-2012-5108 [CRITICAL] CWE-362 CVE-2012-5108: Race condition in Google Chrome before 22.0.1229.92 allows remote attackers to execute arbitrary cod
Race condition in Google Chrome before 22.0.1229.92 allows remote attackers to execute arbitrary code via vectors related to audio devices.
nvd
CVE-2012-2900HIGHCVSS 7.5≤ 22.0.1229.91v22.0.1229.0+54 more2012-10-09
CVE-2012-2900 [HIGH] CVE-2012-2900: Skia, as used in Google Chrome before 22.0.1229.92, does not properly render text, which allows remo
Skia, as used in Google Chrome before 22.0.1229.92, does not properly render text, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2012-5111HIGHCVSS 7.5≤ 22.0.1229.91v22.0.1229.0+54 more2012-10-09
CVE-2012-5111 [HIGH] CVE-2012-5111: Google Chrome before 22.0.1229.92 does not monitor for crashes of Pepper plug-ins, which has unspeci
Google Chrome before 22.0.1229.92 does not monitor for crashes of Pepper plug-ins, which has unspecified impact and remote attack vectors.
nvd
CVE-2012-5110MEDIUMCVSS 5.0≤ 22.0.1229.91v22.0.1229.0+54 more2012-10-09
CVE-2012-5110 [MEDIUM] CWE-125 CVE-2012-5110: The compositor in Google Chrome before 22.0.1229.92 allows remote attackers to cause a denial of ser
The compositor in Google Chrome before 22.0.1229.92 allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2012-5109MEDIUMCVSS 5.0≤ 22.0.1229.91v22.0.1229.0+54 more2012-10-09
CVE-2012-5109 [MEDIUM] CWE-125 CVE-2012-5109: The International Components for Unicode (ICU) functionality in Google Chrome before 22.0.1229.92 al
The International Components for Unicode (ICU) functionality in Google Chrome before 22.0.1229.92 allows remote attackers to cause a denial of service (out-of-bounds read) via vectors related to a regular expression.
nvd
CVE-2012-2885HIGHCVSS 7.5≤ 22.0.1229.78v22.0.1229.0+51 more2012-09-26
CVE-2012-2885 [HIGH] CWE-399 CVE-2012-2885: Double free vulnerability in Google Chrome before 22.0.1229.79 allows remote attackers to cause a de
Double free vulnerability in Google Chrome before 22.0.1229.79 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to application exit.
nvd
CVE-2012-2896HIGHCVSS 7.5≤ 22.0.1229.78v22.0.1229.0+51 more2012-09-26
CVE-2012-2896 [HIGH] CWE-189 CVE-2012-2896: Integer overflow in the WebGL implementation in Google Chrome before 22.0.1229.79 on Mac OS X allows
Integer overflow in the WebGL implementation in Google Chrome before 22.0.1229.79 on Mac OS X allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd