cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2

Vulnerabilities

Page 186 of 292
CVE-2011-3892P4HIGHCVSS 7.5fixed in 15.0.874.1202011-11-11
CVE-2011-3892 [HIGH] CWE-415 CVE-2011-3892: Double free vulnerability in the Theora decoder in Google Chrome before 15.0.874.120 allows remote a Double free vulnerability in the Theora decoder in Google Chrome before 15.0.874.120 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted stream.
nvd
CVE-2011-3115P4HIGHCVSS 7.5≤ 19.0.1084.51v19.0.1028.0+130 more2012-05-24
CVE-2011-3115 [HIGH] CWE-119 CVE-2011-3115: Google V8, as used in Google Chrome before 19.0.1084.52, allows remote attackers to cause a denial o Google V8, as used in Google Chrome before 19.0.1084.52, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger "type corruption."
nvd
CVE-2010-4578P4HIGHCVSS 7.5fixed in 8.0.552.2242010-12-22
CVE-2010-4578 [HIGH] CVE-2010-4578: Google Chrome before 8.0.552.224 and Chrome OS before 8.0.552.343 do not properly perform cursor han Google Chrome before 8.0.552.224 and Chrome OS before 8.0.552.343 do not properly perform cursor handling, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to "stale pointers."
nvd
CVE-2011-3110P4HIGHCVSS 7.5≤ 19.0.1084.51v19.0.1028.0+130 more2012-05-24
CVE-2011-3110 [HIGH] CWE-119 CVE-2011-3110: The PDF functionality in Google Chrome before 19.0.1084.52 allows remote attackers to cause a denial The PDF functionality in Google Chrome before 19.0.1084.52 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger out-of-bounds write operations.
nvd
CVE-2011-0479P4HIGHCVSS 7.5fixed in 8.0.552.2372011-01-14
CVE-2011-0479 [HIGH] CWE-824 CVE-2011-0479: Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly interact with exte Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly interact with extensions, which allows remote attackers to cause a denial of service via a crafted extension that triggers an uninitialized pointer.
nvd
CVE-2013-2880P4HIGHCVSS 7.5≤ 28.0.1500.70v28.0.1500.0+61 more2013-07-10
CVE-2013-2880 [HIGH] CVE-2013-2880: Multiple unspecified vulnerabilities in Google Chrome before 28.0.1500.71 allow attackers to cause a Multiple unspecified vulnerabilities in Google Chrome before 28.0.1500.71 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2014-1718P4HIGHCVSS 7.5≤ 34.0.1847.1152014-04-09
CVE-2014-1718 [HIGH] CWE-189 CVE-2014-1718: Integer overflow in the SoftwareFrameManager::SwapToNewFrame function in content/browser/renderer_ho Integer overflow in the SoftwareFrameManager::SwapToNewFrame function in content/browser/renderer_host/software_frame_manager.cc in the software compositor in Google Chrome before 34.0.1847.116 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger an attempted mapping of a large amount of
nvd
CVE-2015-1238P4HIGHCVSS 7.5≤ 42.0.2311.602015-04-19
CVE-2015-1238 [HIGH] CWE-119 CVE-2015-1238: Skia, as used in Google Chrome before 42.0.2311.90, allows remote attackers to cause a denial of ser Skia, as used in Google Chrome before 42.0.2311.90, allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2011-3087P4CRITICALCVSS 10.0v19.0.1084.452012-05-16
CVE-2011-3087 [CRITICAL] CVE-2011-3087: Google Chrome before 19.0.1084.46 does not properly perform window navigation, which has unspecified Google Chrome before 19.0.1084.46 does not properly perform window navigation, which has unspecified impact and remote attack vectors.
nvd
CVE-2012-5120P4HIGHCVSS 7.5≤ 23.0.1271.62v23.0.1271.0+52 more2012-11-07
CVE-2012-5120 [HIGH] CWE-119 CVE-2012-5120: Google V8 before 3.13.7.5, as used in Google Chrome before 23.0.1271.64, on 64-bit Linux platforms a Google V8 before 3.13.7.5, as used in Google Chrome before 23.0.1271.64, on 64-bit Linux platforms allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that triggers an out-of-bounds access to an array.
nvd
CVE-2015-1213P4HIGHCVSS 7.5≤ 40.0.2214.1152015-03-09
CVE-2015-1213 [HIGH] CWE-119 CVE-2015-1213: The SkBitmap::ReadRawPixels function in core/SkBitmap.cpp in the filters implementation in Skia, as The SkBitmap::ReadRawPixels function in core/SkBitmap.cpp in the filters implementation in Skia, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger an out-of-bounds write operation.
nvd
CVE-2015-1214P4HIGHCVSS 7.5≤ 40.0.2214.1152015-03-09
CVE-2015-1214 [HIGH] CWE-190 CVE-2015-1214: Integer overflow in the SkAutoSTArray implementation in include/core/SkTemplates.h in the filters im Integer overflow in the SkAutoSTArray implementation in include/core/SkTemplates.h in the filters implementation in Skia, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger a reset action with a large count value, leading to an out-of-bound
nvd
CVE-2012-2817P4HIGHCVSS 7.5≤ 20.0.1132.42v20.0.1132.0+41 more2012-06-27
CVE-2012-2817 [HIGH] CWE-399 CVE-2012-2817: Use-after-free vulnerability in Google Chrome before 20.0.1132.43 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 20.0.1132.43 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to tables that have sections.
nvd
CVE-2013-6624P4HIGHCVSS 7.5≤ 31.0.1650.47v31.0.1650.0+42 more2013-11-13
CVE-2013-6624 [HIGH] CWE-399 CVE-2013-6624: Use-after-free vulnerability in Google Chrome before 31.0.1650.48 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 31.0.1650.48 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving the string values of id attributes.
nvd
CVE-2011-0777P4HIGHCVSS 7.5fixed in 9.0.597.842011-02-04
CVE-2011-0777 [HIGH] CWE-416 CVE-2011-0777: Use-after-free vulnerability in Google Chrome before 9.0.597.84 allows remote attackers to cause a d Use-after-free vulnerability in Google Chrome before 9.0.597.84 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to image loading.
nvd
CVE-2014-3200P4HIGHCVSS 7.5≤ 38.0.2125.72014-10-08
CVE-2014-3200 [HIGH] CVE-2014-3200: Multiple unspecified vulnerabilities in Google Chrome before 38.0.2125.101 allow attackers to cause Multiple unspecified vulnerabilities in Google Chrome before 38.0.2125.101 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2011-3957P4HIGHCVSS 7.5fixed in 17.0.963.462012-02-09
CVE-2011-3957 [HIGH] CWE-416 CVE-2011-3957: Use-after-free vulnerability in the garbage-collection functionality in Google Chrome before 17.0.96 Use-after-free vulnerability in the garbage-collection functionality in Google Chrome before 17.0.963.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving PDF documents.
nvd
CVE-2013-0882P4HIGHCVSS 7.5fixed in 25.0.1364.97fixed in 25.0.1364.992013-02-23
CVE-2013-0882 [HIGH] CWE-416 CVE-2013-0882: Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allows Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allows remote attackers to cause a denial of service (incorrect memory access) or possibly have unspecified other impact via a large number of SVG parameters.
nvd
CVE-2013-2885P4HIGHCVSS 7.5≤ 28.0.1500.94v28.0.1500.0+67 more2013-07-31
CVE-2013-2885 [HIGH] CWE-399 CVE-2013-2885: Use-after-free vulnerability in Google Chrome before 28.0.1500.95 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 28.0.1500.95 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to not properly considering focus during the processing of JavaScript events in the presence of a multiple-fields input type.
nvd
CVE-2013-2845P4HIGHCVSS 7.5≤ 27.0.1453.91v27.0.1453.0+69 more2013-05-22
CVE-2013-2845 [HIGH] CWE-119 CVE-2013-2845: The Web Audio implementation in Google Chrome before 27.0.1453.93 allows remote attackers to cause a The Web Audio implementation in Google Chrome before 27.0.1453.93 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
nvd
Google Chrome vulnerabilities | cvebase