cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2

Vulnerabilities

Page 177 of 292
CVE-2012-5133P4HIGHCVSS 7.5≤ 23.0.1271.89v23.0.1271.0+60 more2012-11-28
CVE-2012-5133 [HIGH] CWE-416 CVE-2012-5133: Use-after-free vulnerability in Google Chrome before 23.0.1271.91 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 23.0.1271.91 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to SVG filters.
nvd
CVE-2012-5135P4HIGHCVSS 7.5≤ 23.0.1271.89v23.0.1271.0+60 more2012-11-28
CVE-2012-5135 [HIGH] CWE-399 CVE-2012-5135: Use-after-free vulnerability in Google Chrome before 23.0.1271.91 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 23.0.1271.91 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to printing.
nvd
CVE-2011-3096P4HIGHCVSS 7.5≤ 19.0.1084.452012-05-16
CVE-2011-3096 [HIGH] CWE-399 CVE-2011-3096: Use-after-free vulnerability in Google Chrome before 19.0.1084.46 on Linux allows remote attackers t Use-after-free vulnerability in Google Chrome before 19.0.1084.46 on Linux allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging an error in the GTK implementation of the omnibox.
nvd
CVE-2011-3080P4HIGHCVSS 7.6fixed in 18.0.1025.1682012-05-01
CVE-2011-3080 [HIGH] CWE-362 CVE-2011-3080: Race condition in the Inter-process Communication (IPC) implementation in Google Chrome before 18.0. Race condition in the Inter-process Communication (IPC) implementation in Google Chrome before 18.0.1025.168 allows attackers to bypass intended sandbox restrictions via unspecified vectors.
nvd
CVE-2013-2901P4HIGHCVSS 7.5≤ 29.0.1547.56v29.0.1547.0+49 more2013-08-21
CVE-2013-2901 [HIGH] CWE-189 CVE-2013-2901: Multiple integer overflows in (1) libGLESv2/renderer/Renderer9.cpp and (2) libGLESv2/renderer/Render Multiple integer overflows in (1) libGLESv2/renderer/Renderer9.cpp and (2) libGLESv2/renderer/Renderer11.cpp in Almost Native Graphics Layer Engine (ANGLE), as used in Google Chrome before 29.0.1547.57, allow remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2012-5116P4HIGHCVSS 7.5≤ 23.0.1271.62v23.0.1271.0+52 more2012-11-07
CVE-2012-5116 [HIGH] CWE-416 CVE-2012-5116: Use-after-free vulnerability in Google Chrome before 23.0.1271.64 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 23.0.1271.64 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of SVG filters.
nvd
CVE-2015-1222P4HIGHCVSS 7.5≤ 40.0.2214.1152015-03-09
CVE-2015-1222 [HIGH] CVE-2015-1222: Multiple use-after-free vulnerabilities in the ServiceWorkerScriptCacheMap implementation in content Multiple use-after-free vulnerabilities in the ServiceWorkerScriptCacheMap implementation in content/browser/service_worker/service_worker_script_cache_map.cc in Google Chrome before 41.0.2272.76 allow remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger a ServiceWorkerContextWrapper::DeleteAndStartOve
nvd
CVE-2015-1228P4HIGHCVSS 7.5≤ 40.0.2214.1152015-03-09
CVE-2015-1228 [HIGH] CWE-399 CVE-2015-1228: The RenderCounter::updateCounter function in core/rendering/RenderCounter.cpp in Blink, as used in G The RenderCounter::updateCounter function in core/rendering/RenderCounter.cpp in Blink, as used in Google Chrome before 41.0.2272.76, does not force a relayout operation and consequently does not initialize memory for a data structure, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impac
nvd
CVE-2014-1719P4HIGHCVSS 7.5≤ 34.0.1847.1152014-04-09
CVE-2014-1719 [HIGH] CWE-399 CVE-2014-1719: Use-after-free vulnerability in the WebSharedWorkerStub::OnTerminateWorkerContext function in conten Use-after-free vulnerability in the WebSharedWorkerStub::OnTerminateWorkerContext function in content/worker/websharedworker_stub.cc in the Web Workers implementation in Google Chrome before 34.0.1847.116 allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via vectors that trigger a Sha
nvd
CVE-2014-1722P4HIGHCVSS 7.5≤ 34.0.1847.1152014-04-09
CVE-2014-1722 [HIGH] CWE-399 CVE-2014-1722: Use-after-free vulnerability in the RenderBlock::addChildIgnoringAnonymousColumnBlocks function in c Use-after-free vulnerability in the RenderBlock::addChildIgnoringAnonymousColumnBlocks function in core/rendering/RenderBlock.cpp in Blink, as used in Google Chrome before 34.0.1847.116, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving addition of a child node.
nvd
CVE-2014-1727P4HIGHCVSS 7.5≤ 34.0.1847.1152014-04-09
CVE-2014-1727 [HIGH] CWE-399 CVE-2014-1727: Use-after-free vulnerability in content/renderer/renderer_webcolorchooser_impl.h in Google Chrome be Use-after-free vulnerability in content/renderer/renderer_webcolorchooser_impl.h in Google Chrome before 34.0.1847.116 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to forms.
nvd
CVE-2014-1720P4HIGHCVSS 7.5≤ 34.0.1847.1152014-04-09
CVE-2014-1720 [HIGH] CWE-399 CVE-2014-1720: Use-after-free vulnerability in the HTMLBodyElement::insertedInto function in core/html/HTMLBodyElem Use-after-free vulnerability in the HTMLBodyElement::insertedInto function in core/html/HTMLBodyElement.cpp in Blink, as used in Google Chrome before 34.0.1847.116, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving attributes.
nvd
CVE-2016-1613P4HIGHCVSS 7.6≤ 47.0.2526.1062016-01-25
CVE-2016-1613 [HIGH] CVE-2016-1613: Multiple use-after-free vulnerabilities in the formfiller implementation in PDFium, as used in Googl Multiple use-after-free vulnerabilities in the formfiller implementation in PDFium, as used in Google Chrome before 48.0.2564.82, allow remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted PDF document, related to improper tracking of the destruction of (1) IPWL_FocusHandler and (2) IPWL_Provider objects.
nvd
CVE-2014-1724P4HIGHCVSS 7.5≤ 34.0.1847.1152014-04-09
CVE-2014-1724 [HIGH] CWE-399 CVE-2014-1724: Use-after-free vulnerability in Free(b)soft Laboratory Speech Dispatcher 0.7.1, as used in Google Ch Use-after-free vulnerability in Free(b)soft Laboratory Speech Dispatcher 0.7.1, as used in Google Chrome before 34.0.1847.116, allows remote attackers to cause a denial of service (application hang) or possibly have unspecified other impact via a text-to-speech request.
nvd
CVE-2013-6654P4HIGHCVSS 7.5≤ 33.0.1750.116v33.0.1750.0+95 more2014-02-24
CVE-2013-6654 [HIGH] CWE-20 CVE-2013-6654: The SVGAnimateElement::calculateAnimatedValue function in core/svg/SVGAnimateElement.cpp in Blink, a The SVGAnimateElement::calculateAnimatedValue function in core/svg/SVGAnimateElement.cpp in Blink, as used in Google Chrome before 33.0.1750.117, does not properly handle unexpected data types, which allows remote attackers to cause a denial of service (incorrect cast) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2013-6655P4HIGHCVSS 7.5≤ 33.0.1750.116v33.0.1750.0+95 more2014-02-24
CVE-2013-6655 [HIGH] CWE-399 CVE-2013-6655: Use-after-free vulnerability in Blink, as used in Google Chrome before 33.0.1750.117, allows remote Use-after-free vulnerability in Blink, as used in Google Chrome before 33.0.1750.117, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to improper handling of overflowchanged DOM events during interaction between JavaScript and layout.
nvd
CVE-2015-1360P4HIGHCVSS 7.5≤ 40.0.2214.852015-01-27
CVE-2015-1360 [HIGH] CVE-2015-1360: Skia, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of ser Skia, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via crafted data that is improperly handled during text drawing, related to gpu/GrBitmapTextContext.cpp and gpu/GrDistanceFieldTextContext.cpp, a different vulnerability than CVE-2015-1205.
nvd
CVE-2013-2902P4HIGHCVSS 7.5≤ 29.0.1547.56v29.0.1547.0+49 more2013-08-21
CVE-2013-2902 [HIGH] CWE-399 CVE-2013-2902: Use-after-free vulnerability in the XSLT ProcessingInstruction implementation in Blink, as used in G Use-after-free vulnerability in the XSLT ProcessingInstruction implementation in Blink, as used in Google Chrome before 29.0.1547.57, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to an applyXSLTransform call involving (1) an HTML document or (2) an xsl:processing-instruction element t
nvd
CVE-2013-2884P4HIGHCVSS 7.5≤ 28.0.1500.94v28.0.1500.0+67 more2013-07-31
CVE-2013-2884 [HIGH] CWE-399 CVE-2013-2884: Use-after-free vulnerability in the DOM implementation in Google Chrome before 28.0.1500.95 allows r Use-after-free vulnerability in the DOM implementation in Google Chrome before 28.0.1500.95 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to improper tracking of which document owns an Attr object.
nvd
CVE-2013-2873P4HIGHCVSS 7.5≤ 28.0.1500.70v28.0.1500.0+61 more2013-07-10
CVE-2013-2873 [HIGH] CWE-399 CVE-2013-2873: Use-after-free vulnerability in Google Chrome before 28.0.1500.71 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 28.0.1500.71 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving a 404 HTTP status code during the loading of resources.
nvd
Google Chrome vulnerabilities | cvebase