Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2
Vulnerabilities
Page 176 of 292
CVE-2011-1195P4HIGHCVSS 7.5fixed in 10.0.648.1272011-03-11
CVE-2011-1195 [HIGH] CWE-416 CVE-2011-1195: Use-after-free vulnerability in Google Chrome before 10.0.648.127 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 10.0.648.127 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to "document script lifetime handling."
nvd
CVE-2015-6781P4HIGHCVSS 7.5≤ 46.0.2490.862015-12-06
CVE-2015-6781 [HIGH] CWE-189 CVE-2015-6781: Integer overflow in the FontData::Bound function in data/font_data.cc in Google sfntly, as used in G
Integer overflow in the FontData::Bound function in data/font_data.cc in Google sfntly, as used in Google Chrome before 47.0.2526.73, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted offset or length value within font data in an SFNT container.
nvd
CVE-2010-4492P4HIGHCVSS 7.5fixed in 8.0.552.2152010-12-07
CVE-2010-4492 [HIGH] CWE-416 CVE-2010-4492: Use-after-free vulnerability in Google Chrome before 8.0.552.215 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 8.0.552.215 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving SVG animations.
nvd
CVE-2014-1732P4HIGHCVSS 7.5fixed in 34.0.1847.131fixed in 34.0.1847.1322014-04-26
CVE-2014-1732 [HIGH] CWE-416 CVE-2014-1732: Use-after-free vulnerability in browser/ui/views/speech_recognition_bubble_views.cc in Google Chrome
Use-after-free vulnerability in browser/ui/views/speech_recognition_bubble_views.cc in Google Chrome before 34.0.1847.131 on Windows and OS X and before 34.0.1847.132 on Linux allows remote attackers to cause a denial of service or possibly have unspecified other impact via an INPUT element that triggers the presence of a Speech Recognition Bubble windo
nvd
CVE-2015-1256P4HIGHCVSS 7.5≤ 42.0.2311.1522015-05-20
CVE-2015-1256 [HIGH] CVE-2015-1256: Use-after-free vulnerability in the SVG implementation in Blink, as used in Google Chrome before 43.
Use-after-free vulnerability in the SVG implementation in Blink, as used in Google Chrome before 43.0.2357.65, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted document that leverages improper handling of a shadow tree for a use element.
nvd
CVE-2014-7930P4HIGHCVSS 7.5≤ 40.0.2214.852015-01-22
CVE-2014-7930 [HIGH] CVE-2014-7930: Use-after-free vulnerability in core/events/TreeScopeEventContext.cpp in the DOM implementation in B
Use-after-free vulnerability in core/events/TreeScopeEventContext.cpp in the DOM implementation in Blink, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that triggers improper maintenance of TreeScope data.
nvd
CVE-2014-1715P4HIGHCVSS 7.5fixed in 33.0.1750.152fixed in 33.0.1750.1542014-03-16
CVE-2014-1715 [HIGH] CWE-22 CVE-2014-1715: Directory traversal vulnerability in Google Chrome before 33.0.1750.152 on OS X and Linux and before
Directory traversal vulnerability in Google Chrome before 33.0.1750.152 on OS X and Linux and before 33.0.1750.154 on Windows has unspecified impact and attack vectors.
nvd
CVE-2014-7942P4HIGHCVSS 7.5≤ 40.0.2214.852015-01-22
CVE-2014-7942 [HIGH] CWE-399 CVE-2014-7942: The Fonts implementation in Google Chrome before 40.0.2214.91 does not initialize memory for a data
The Fonts implementation in Google Chrome before 40.0.2214.91 does not initialize memory for a data structure, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2013-6646P4HIGHCVSS 7.5fixed in 32.0.1700.77fixed in 32.0.1700.762014-01-16
CVE-2013-6646 [HIGH] CWE-416 CVE-2013-6646: Use-after-free vulnerability in the Web Workers implementation in Google Chrome before 32.0.1700.76
Use-after-free vulnerability in the Web Workers implementation in Google Chrome before 32.0.1700.76 on Windows and before 32.0.1700.77 on Mac OS X and Linux allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the shutting down of a worker process.
nvd
CVE-2014-1721P4HIGHCVSS 7.5≤ 34.0.1847.1152014-04-09
CVE-2014-1721 [HIGH] CWE-189 CVE-2014-1721: Google V8, as used in Google Chrome before 34.0.1847.116, does not properly implement lazy deoptimiz
Google V8, as used in Google Chrome before 34.0.1847.116, does not properly implement lazy deoptimization, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via crafted JavaScript code, as demonstrated by improper handling of a heap allocation of a number outside the Small Integer (a
nvd
CVE-2011-1124P4HIGHCVSS 7.5fixed in 9.0.597.1072011-03-01
CVE-2011-1124 [HIGH] CWE-416 CVE-2011-1124: Use-after-free vulnerability in Google Chrome before 9.0.597.107 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 9.0.597.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to blocked plug-ins.
nvd
CVE-2011-3921P4HIGHCVSS 7.5fixed in 16.0.912.752012-01-07
CVE-2011-3921 [HIGH] CWE-416 CVE-2011-3921: Use-after-free vulnerability in Google Chrome before 16.0.912.75 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 16.0.912.75 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving animation frames.
nvd
CVE-2012-2887P4HIGHCVSS 7.5≤ 22.0.1229.78v22.0.1229.0+51 more2012-09-26
CVE-2012-2887 [HIGH] CWE-399 CVE-2012-2887: Use-after-free vulnerability in Google Chrome before 22.0.1229.79 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 22.0.1229.79 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving onclick events.
nvd
CVE-2014-3178P4HIGHCVSS 7.5v37.0.2062.0v37.0.2062.1+87 more2014-09-10
CVE-2014-3178 [HIGH] CVE-2014-3178: Use-after-free vulnerability in core/dom/Node.cpp in Blink, as used in Google Chrome before 37.0.206
Use-after-free vulnerability in core/dom/Node.cpp in Blink, as used in Google Chrome before 37.0.2062.120, allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging improper handling of render-tree inconsistencies.
nvd
CVE-2012-2842P4HIGHCVSS 7.5≤ 20.0.1132.56v20.0.1132.0+48 more2012-07-12
CVE-2012-2842 [HIGH] CWE-399 CVE-2012-2842: Use-after-free vulnerability in Google Chrome before 20.0.1132.57 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 20.0.1132.57 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to counter handling.
nvd
CVE-2012-2831P4HIGHCVSS 7.5≤ 20.0.1132.42v20.0.1132.0+41 more2012-06-27
CVE-2012-2831 [HIGH] CWE-399 CVE-2012-2831: Use-after-free vulnerability in Google Chrome before 20.0.1132.43 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 20.0.1132.43 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to SVG references.
nvd
CVE-2012-2829P4HIGHCVSS 7.5≤ 20.0.1132.42v20.0.1132.0+41 more2012-06-27
CVE-2012-2829 [HIGH] CWE-399 CVE-2012-2829: Use-after-free vulnerability in the Cascading Style Sheets (CSS) implementation in Google Chrome bef
Use-after-free vulnerability in the Cascading Style Sheets (CSS) implementation in Google Chrome before 20.0.1132.43 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the :first-letter pseudo-element.
nvd
CVE-2013-2910P4HIGHCVSS 7.5≤ 30.0.1599.65v30.0.1599.0+57 more2013-10-02
CVE-2013-2910 [HIGH] CWE-399 CVE-2013-2910: Use-after-free vulnerability in modules/webaudio/AudioScheduledSourceNode.cpp in the Web Audio imple
Use-after-free vulnerability in modules/webaudio/AudioScheduledSourceNode.cpp in the Web Audio implementation in Blink, as used in Google Chrome before 30.0.1599.66, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2013-6649P4HIGHCVSS 7.5≤ 32.0.1700.101v32.0.1700.0+67 more2014-01-28
CVE-2013-6649 [HIGH] CWE-399 CVE-2013-6649: Use-after-free vulnerability in the RenderSVGImage::paint function in core/rendering/svg/RenderSVGIm
Use-after-free vulnerability in the RenderSVGImage::paint function in core/rendering/svg/RenderSVGImage.cpp in Blink, as used in Google Chrome before 32.0.1700.102, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving a zero-size SVG image.
nvd
CVE-2014-1700P4HIGHCVSS 7.5≤ 33.0.1750.146v33.0.1750.0+105 more2014-03-16
CVE-2014-1700 [HIGH] CWE-399 CVE-2014-1700: Use-after-free vulnerability in modules/speech/SpeechSynthesis.cpp in Blink, as used in Google Chrom
Use-after-free vulnerability in modules/speech/SpeechSynthesis.cpp in Blink, as used in Google Chrome before 33.0.1750.149, allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging improper handling of a certain utterance data structure.
nvd