Google Chrome vulnerabilities

4,008 known vulnerabilities affecting google/chrome.

Total CVEs
4,008
CISA KEV
74
actively exploited
Public exploits
64
Exploited in wild
65
Severity breakdown
CRITICAL300HIGH2051MEDIUM1628LOW19UNKNOWN10

Vulnerabilities

Page 182 of 201
CVE-2011-2846MEDIUMCVSS 6.8fixed in 14.0.835.1632011-09-19
CVE-2011-2846 [MEDIUM] CWE-416 CVE-2011-2846: Use-after-free vulnerability in Google Chrome before 14.0.835.163 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 14.0.835.163 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to unload event handling.
nvd
CVE-2011-2874MEDIUMCVSS 6.8fixed in 14.0.835.1632011-09-19
CVE-2011-2874 [MEDIUM] CWE-295 CVE-2011-2874: Google Chrome before 14.0.835.163 does not perform an expected pin operation for a self-signed certi Google Chrome before 14.0.835.163 does not perform an expected pin operation for a self-signed certificate during a session, which has unspecified impact and remote attack vectors.
nvd
CVE-2011-2849MEDIUMCVSS 4.3fixed in 14.0.835.1632011-09-19
CVE-2011-2849 [MEDIUM] CWE-476 CVE-2011-2849: The WebSockets implementation in Google Chrome before 14.0.835.163 allows remote attackers to cause The WebSockets implementation in Google Chrome before 14.0.835.163 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via unspecified vectors.
nvd
CVE-2011-2854MEDIUMCVSS 6.8fixed in 14.0.835.1632011-09-19
CVE-2011-2854 [MEDIUM] CWE-416 CVE-2011-2854: Use-after-free vulnerability in Google Chrome before 14.0.835.163 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 14.0.835.163 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to "ruby / table style handing."
nvd
CVE-2011-2875MEDIUMCVSS 6.8fixed in 14.0.835.1632011-09-19
CVE-2011-2875 [MEDIUM] CWE-843 CVE-2011-2875: Google V8, as used in Google Chrome before 14.0.835.163, does not properly perform object sealing, w Google V8, as used in Google Chrome before 14.0.835.163, does not properly perform object sealing, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that leverage "type confusion."
nvd
CVE-2011-2844MEDIUMCVSS 5.0fixed in 14.0.835.1632011-09-19
CVE-2011-2844 [MEDIUM] CWE-125 CVE-2011-2844: Google Chrome before 14.0.835.163 does not properly process MP3 files, which allows remote attackers Google Chrome before 14.0.835.163 does not properly process MP3 files, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2011-2843MEDIUMCVSS 5.0fixed in 14.0.835.1632011-09-19
CVE-2011-2843 [MEDIUM] CWE-125 CVE-2011-2843: Google Chrome before 14.0.835.163 does not properly handle media buffers, which allows remote attack Google Chrome before 14.0.835.163 does not properly handle media buffers, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2011-2834MEDIUMCVSS 6.8fixed in 14.0.835.1632011-09-19
CVE-2011-2834 [MEDIUM] CWE-415 CVE-2011-2834: Double free vulnerability in libxml2, as used in Google Chrome before 14.0.835.163, allows remote at Double free vulnerability in libxml2, as used in Google Chrome before 14.0.835.163, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XPath handling.
nvd
CVE-2011-2859MEDIUMCVSS 6.8fixed in 14.0.835.1632011-09-19
CVE-2011-2859 [MEDIUM] CWE-276 CVE-2011-2859: Google Chrome before 14.0.835.163 uses incorrect permissions for non-gallery pages, which has unspec Google Chrome before 14.0.835.163 uses incorrect permissions for non-gallery pages, which has unspecified impact and attack vectors.
nvd
CVE-2011-2855MEDIUMCVSS 6.8fixed in 14.0.835.1632011-09-19
CVE-2011-2855 [MEDIUM] CWE-74 CVE-2011-2855: Google Chrome before 14.0.835.163 does not properly handle Cascading Style Sheets (CSS) token sequen Google Chrome before 14.0.835.163 does not properly handle Cascading Style Sheets (CSS) token sequences, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale node."
nvd
CVE-2011-2848MEDIUMCVSS 4.3fixed in 14.0.835.1632011-09-19
CVE-2011-2848 [MEDIUM] CWE-20 CVE-2011-2848: Google Chrome before 14.0.835.163 allows user-assisted remote attackers to spoof the URL bar via vec Google Chrome before 14.0.835.163 allows user-assisted remote attackers to spoof the URL bar via vectors related to the forward button.
nvd
CVE-2011-2847MEDIUMCVSS 6.8fixed in 14.0.835.1632011-09-19
CVE-2011-2847 [MEDIUM] CWE-416 CVE-2011-2847: Use-after-free vulnerability in the document loader in Google Chrome before 14.0.835.163 allows remo Use-after-free vulnerability in the document loader in Google Chrome before 14.0.835.163 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted document.
nvd
CVE-2011-2825CRITICALCVSS 9.3fixed in 13.0.782.2152011-08-29
CVE-2011-2825 [CRITICAL] CWE-416 CVE-2011-2825: Use-after-free vulnerability in Google Chrome before 13.0.782.215 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 13.0.782.215 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving custom fonts.
nvd
CVE-2011-2806CRITICALCVSS 10.0fixed in 13.0.782.2152011-08-29
CVE-2011-2806 [CRITICAL] CWE-119 CVE-2011-2806: Google Chrome before 13.0.782.215 on Windows does not properly handle vertex data, which allows remo Google Chrome before 13.0.782.215 on Windows does not properly handle vertex data, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
nvd
CVE-2011-2822CRITICALCVSS 10.0fixed in 13.0.782.2152011-08-29
CVE-2011-2822 [CRITICAL] CWE-20 CVE-2011-2822: Google Chrome before 13.0.782.215 on Windows does not properly parse URLs located on the command lin Google Chrome before 13.0.782.215 on Windows does not properly parse URLs located on the command line, which has unspecified impact and attack vectors.
nvd
CVE-2011-2823HIGHCVSS 7.5fixed in 13.0.782.2152011-08-29
CVE-2011-2823 [HIGH] CWE-416 CVE-2011-2823: Use-after-free vulnerability in Google Chrome before 13.0.782.215 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 13.0.782.215 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving a line box.
nvd
CVE-2011-2839HIGHCVSS 7.5fixed in 13.0.782.2152011-08-29
CVE-2011-2839 [HIGH] CWE-20 CVE-2011-2839: The PDF implementation in Google Chrome before 13.0.782.215 on Linux does not properly use the memse The PDF implementation in Google Chrome before 13.0.782.215 on Linux does not properly use the memset library function, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2011-2821HIGHCVSS 7.5fixed in 13.0.782.2152011-08-29
CVE-2011-2821 [HIGH] CWE-415 CVE-2011-2821: Double free vulnerability in libxml2, as used in Google Chrome before 13.0.782.215, allows remote at Double free vulnerability in libxml2, as used in Google Chrome before 13.0.782.215, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted XPath expression.
nvd
CVE-2011-2824HIGHCVSS 7.5fixed in 13.0.782.2152011-08-29
CVE-2011-2824 [HIGH] CWE-416 CVE-2011-2824: Use-after-free vulnerability in Google Chrome before 13.0.782.215 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 13.0.782.215 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving counter nodes.
nvd
CVE-2011-2826HIGHCVSS 7.5fixed in 13.0.782.2152011-08-29
CVE-2011-2826 [HIGH] CVE-2011-2826: Google Chrome before 13.0.782.215 allows remote attackers to bypass the Same Origin Policy via vecto Google Chrome before 13.0.782.215 allows remote attackers to bypass the Same Origin Policy via vectors related to empty origins.
nvd