Google Chrome vulnerabilities

4,008 known vulnerabilities affecting google/chrome.

Total CVEs
4,008
CISA KEV
74
actively exploited
Public exploits
64
Exploited in wild
65
Severity breakdown
CRITICAL300HIGH2051MEDIUM1628LOW19UNKNOWN10

Vulnerabilities

Page 170 of 201
CVE-2012-2856HIGHCVSS 7.5≤ 21.0.1180.56v21.0.1180.0+25 more2012-08-06
CVE-2012-2856 [HIGH] CWE-119 CVE-2012-2856: The PDF functionality in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.11 The PDF functionality in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger out-of-bounds write operations.
nvd
CVE-2012-2854MEDIUMCVSS 5.0≤ 21.0.1180.56v21.0.1180.0+25 more2012-08-06
CVE-2012-2854 [MEDIUM] CWE-200 CVE-2012-2854: Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chro Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, allows remote attackers to obtain potentially sensitive information about pointer values by leveraging access to a WebUI renderer process.
nvd
CVE-2012-2852MEDIUMCVSS 6.8≤ 21.0.1180.56v21.0.1180.0+25 more2012-08-06
CVE-2012-2852 [MEDIUM] CWE-399 CVE-2012-2852: The PDF functionality in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.11 The PDF functionality in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, does not properly handle object linkage, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted document.
nvd
CVE-2012-2846MEDIUMCVSS 5.0≤ 21.0.1180.56v21.0.1180.0+22 more2012-08-06
CVE-2012-2846 [MEDIUM] CVE-2012-2846: Google Chrome before 21.0.1180.57 on Linux does not properly isolate renderer processes, which allow Google Chrome before 21.0.1180.57 on Linux does not properly isolate renderer processes, which allows remote attackers to cause a denial of service (cross-process interference) via unspecified vectors.
nvd
CVE-2012-2855MEDIUMCVSS 6.8≤ 21.0.1180.56v21.0.1180.0+25 more2012-08-06
CVE-2012-2855 [MEDIUM] CWE-399 CVE-2012-2855: Use-after-free vulnerability in the PDF functionality in Google Chrome before 21.0.1180.57 on Mac OS Use-after-free vulnerability in the PDF functionality in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted document.
nvd
CVE-2012-2851MEDIUMCVSS 6.8≤ 21.0.1180.56v21.0.1180.0+25 more2012-08-06
CVE-2012-2851 [MEDIUM] CWE-189 CVE-2012-2851: Multiple integer overflows in the PDF functionality in Google Chrome before 21.0.1180.57 on Mac OS X Multiple integer overflows in the PDF functionality in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, allow remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted document.
nvd
CVE-2012-2857MEDIUMCVSS 6.8≤ 21.0.1180.59v21.0.1180.0+25 more2012-08-06
CVE-2012-2857 [MEDIUM] CWE-399 CVE-2012-2857: Use-after-free vulnerability in the Cascading Style Sheets (CSS) DOM implementation in Google Chrome Use-after-free vulnerability in the Cascading Style Sheets (CSS) DOM implementation in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted document.
nvd
CVE-2012-2860MEDIUMCVSS 6.8≤ 21.0.1180.56v21.0.1180.0+25 more2012-08-06
CVE-2012-2860 [MEDIUM] CVE-2012-2860: The date-picker implementation in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and befor The date-picker implementation in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, allows user-assisted remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted web site.
nvd
CVE-2012-2850MEDIUMCVSS 6.8≤ 21.0.1180.56v21.0.1180.0+25 more2012-08-06
CVE-2012-2850 [MEDIUM] CVE-2012-2850: Multiple unspecified vulnerabilities in the PDF functionality in Google Chrome before 21.0.1180.57 o Multiple unspecified vulnerabilities in the PDF functionality in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, allow remote attackers to have an unknown impact via a crafted document.
nvd
CVE-2012-2848MEDIUMCVSS 4.3≤ 21.0.1180.56v21.0.1180.0+25 more2012-08-06
CVE-2012-2848 [MEDIUM] CWE-264 CVE-2012-2848: The drag-and-drop implementation in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and bef The drag-and-drop implementation in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, allows user-assisted remote attackers to bypass intended file access restrictions via a crafted web site.
nvd
CVE-2012-2853MEDIUMCVSS 6.8≤ 21.0.1180.56v21.0.1180.0+25 more2012-08-06
CVE-2012-2853 [MEDIUM] CVE-2012-2853: The webRequest API in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180. The webRequest API in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, does not properly interact with the Chrome Web Store, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted web site.
nvd
CVE-2012-2849MEDIUMCVSS 4.3≤ 21.0.1180.56v21.0.1180.0+25 more2012-08-06
CVE-2012-2849 [MEDIUM] CWE-189 CVE-2012-2849: Off-by-one error in the GIF decoder in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and Off-by-one error in the GIF decoder in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted image.
nvd
CVE-2012-2858MEDIUMCVSS 6.8≤ 21.0.1180.56v21.0.1180.0+25 more2012-08-06
CVE-2012-2858 [MEDIUM] CWE-119 CVE-2012-2858: Buffer overflow in the WebP decoder in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and Buffer overflow in the WebP decoder in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted WebP image.
nvd
CVE-2012-2847MEDIUMCVSS 4.3≤ 21.0.1180.56v21.0.1180.0+25 more2012-08-06
CVE-2012-2847 [MEDIUM] CWE-399 CVE-2012-2847: Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chro Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, does not request user confirmation before continuing a large series of downloads, which allows user-assisted remote attackers to cause a denial of service (resource consumption) via a crafted web site.
nvd
CVE-2012-2844CRITICALCVSS 9.3≤ 20.0.1132.56v20.0.1132.0+48 more2012-07-12
CVE-2012-2844 [CRITICAL] CVE-2012-2844: The PDF functionality in Google Chrome before 20.0.1132.57 does not properly handle JavaScript code, The PDF functionality in Google Chrome before 20.0.1132.57 does not properly handle JavaScript code, which allows remote attackers to cause a denial of service (incorrect object access) or possibly have unspecified other impact via a crafted document.
nvd
CVE-2012-2842HIGHCVSS 7.5≤ 20.0.1132.56v20.0.1132.0+48 more2012-07-12
CVE-2012-2842 [HIGH] CWE-399 CVE-2012-2842: Use-after-free vulnerability in Google Chrome before 20.0.1132.57 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 20.0.1132.57 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to counter handling.
nvd
CVE-2012-2843HIGHCVSS 7.5≤ 20.0.1132.56v20.0.1132.0+48 more2012-07-12
CVE-2012-2843 [HIGH] CWE-399 CVE-2012-2843: Use-after-free vulnerability in Google Chrome before 20.0.1132.57 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 20.0.1132.57 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to layout height tracking.
nvd
CVE-2012-2834CRITICALCVSS 9.3≤ 20.0.1132.42v20.0.1132.0+41 more2012-06-27
CVE-2012-2834 [CRITICAL] CWE-189 CVE-2012-2834: Integer overflow in Google Chrome before 20.0.1132.43 allows remote attackers to cause a denial of s Integer overflow in Google Chrome before 20.0.1132.43 allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted data in the Matroska container format.
nvd
CVE-2012-2821HIGHCVSS 7.5≤ 20.0.1132.42v20.0.1132.0+41 more2012-06-27
CVE-2012-2821 [HIGH] CVE-2012-2821: The autofill implementation in Google Chrome before 20.0.1132.43 does not properly display text, whi The autofill implementation in Google Chrome before 20.0.1132.43 does not properly display text, which has unspecified impact and remote attack vectors.
nvd
CVE-2012-2816HIGHCVSS 7.8≤ 20.0.1132.42v20.0.1132.0+41 more2012-06-27
CVE-2012-2816 [HIGH] CVE-2012-2816: Google Chrome before 20.0.1132.43 on Windows does not properly isolate sandboxed processes, which mi Google Chrome before 20.0.1132.43 on Windows does not properly isolate sandboxed processes, which might allow remote attackers to cause a denial of service (process interference) via unspecified vectors.
nvd