cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2

Vulnerabilities

Page 187 of 292
CVE-2015-1301P4HIGHCVSS 7.5≤ 44.0.24032015-09-03
CVE-2015-1301 [HIGH] CVE-2015-1301: Multiple unspecified vulnerabilities in Google Chrome before 45.0.2454.85 allow attackers to cause a Multiple unspecified vulnerabilities in Google Chrome before 45.0.2454.85 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2015-1249P4HIGHCVSS 7.5≤ 42.0.2311.602015-04-19
CVE-2015-1249 [HIGH] CVE-2015-1249: Multiple unspecified vulnerabilities in Google Chrome before 42.0.2311.90 allow attackers to cause a Multiple unspecified vulnerabilities in Google Chrome before 42.0.2311.90 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2012-2824P4HIGHCVSS 7.5≤ 20.0.1132.42v20.0.1132.0+41 more2012-06-27
CVE-2012-2824 [HIGH] CWE-399 CVE-2012-2824: Use-after-free vulnerability in Google Chrome before 20.0.1132.43 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 20.0.1132.43 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to SVG painting.
nvd
CVE-2015-1289P4HIGHCVSS 7.5≤ 43.0.2357.1342015-07-23
CVE-2015-1289 [HIGH] CVE-2015-1289: Multiple unspecified vulnerabilities in Google Chrome before 44.0.2403.89 allow attackers to cause a Multiple unspecified vulnerabilities in Google Chrome before 44.0.2403.89 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2014-1717P4HIGHCVSS 7.5≤ 34.0.1847.1152014-04-09
CVE-2014-1717 [HIGH] CWE-189 CVE-2014-1717: Google V8, as used in Google Chrome before 34.0.1847.116, does not properly use numeric casts during Google V8, as used in Google Chrome before 34.0.1847.116, does not properly use numeric casts during handling of typed arrays, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted JavaScript code.
nvd
CVE-2013-6664P4HIGHCVSS 7.5≤ 33.0.1750.144v33.0.1750.0+104 more2014-03-05
CVE-2013-6664 [HIGH] CWE-399 CVE-2013-6664: Use-after-free vulnerability in the FormAssociatedElement::formRemovedFromTree function in core/html Use-after-free vulnerability in the FormAssociatedElement::formRemovedFromTree function in core/html/FormAssociatedElement.cpp in Blink, as used in Google Chrome before 33.0.1750.146, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving FORM elements, as demonstrated by use of the speech-re
nvd
CVE-2013-6653P4HIGHCVSS 7.5≤ 33.0.1750.116v33.0.1750.0+95 more2014-02-24
CVE-2013-6653 [HIGH] CWE-399 CVE-2013-6653: Use-after-free vulnerability in the web contents implementation in Google Chrome before 33.0.1750.11 Use-after-free vulnerability in the web contents implementation in Google Chrome before 33.0.1750.117 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving attempted conflicting access to the color chooser.
nvd
CVE-2011-3084P4HIGHCVSS 7.5≤ 19.0.1084.452012-05-16
CVE-2011-3084 [HIGH] CWE-264 CVE-2011-3084: Google Chrome before 19.0.1084.46 does not use a dedicated process for the loading of links found on Google Chrome before 19.0.1084.46 does not use a dedicated process for the loading of links found on an internal page, which might allow attackers to bypass intended sandbox restrictions via a crafted page.
nvd
CVE-2013-0843P4HIGHCVSS 7.5v24.0.1272.0v24.0.1272.1+123 more2013-01-24
CVE-2013-0843 [HIGH] CWE-119 CVE-2013-0843: content/renderer/media/webrtc_audio_renderer.cc in Google Chrome before 24.0.1312.56 on Mac OS X doe content/renderer/media/webrtc_audio_renderer.cc in Google Chrome before 24.0.1312.56 on Mac OS X does not use an appropriate buffer size for the 96 kHz sampling rate, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via a web site that provides WebRTC audio.
nvd
CVE-2014-3189P4HIGHCVSS 7.5≤ 38.0.2125.72014-10-08
CVE-2014-3189 [HIGH] CWE-264 CVE-2014-3189: The chrome_pdf::CopyImage function in pdf/draw_utils.cc in the PDFium component in Google Chrome bef The chrome_pdf::CopyImage function in pdf/draw_utils.cc in the PDFium component in Google Chrome before 38.0.2125.101 does not properly validate image-data dimensions, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2012-2888P4HIGHCVSS 7.5≤ 22.0.1229.78v22.0.1229.0+51 more2012-09-26
CVE-2012-2888 [HIGH] CWE-399 CVE-2012-2888: Use-after-free vulnerability in Google Chrome before 22.0.1229.79 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 22.0.1229.79 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving SVG text references.
nvd
CVE-2013-0840P4CRITICALCVSS 10.0≤ 24.0.1312.55v24.0.1272.0+114 more2013-01-24
CVE-2013-0840 [CRITICAL] CVE-2013-0840: Google Chrome before 24.0.1312.56 does not validate URLs during the opening of new windows, which ha Google Chrome before 24.0.1312.56 does not validate URLs during the opening of new windows, which has unspecified impact and remote attack vectors.
nvd
CVE-2013-0880P4HIGHCVSS 7.5fixed in 25.0.1364.97fixed in 25.0.1364.992013-02-23
CVE-2013-0880 [HIGH] CWE-416 CVE-2013-0880: Use-after-free vulnerability in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 2 Use-after-free vulnerability in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to databases.
nvd
CVE-2011-2836P4HIGHCVSS 7.5fixed in 14.0.835.1632011-09-19
CVE-2011-2836 [HIGH] CVE-2011-2836: Google Chrome before 14.0.835.163 does not require Infobar interaction before use of the Windows Med Google Chrome before 14.0.835.163 does not require Infobar interaction before use of the Windows Media Player plug-in, which makes it easier for remote attackers to have an unspecified impact via crafted Flash content.
nvd
CVE-2011-1795P4HIGHCVSS 7.5≤ 11.0.696.642014-12-26
CVE-2011-1795 [HIGH] CWE-189 CVE-2011-1795: Integer underflow in the HTMLFormElement::removeFormElement function in html/HTMLFormElement.cpp in Integer underflow in the HTMLFormElement::removeFormElement function in html/HTMLFormElement.cpp in WebCore in WebKit in Google Chrome before 11.0.696.65 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted HTML document containing a FORM element.
nvd
CVE-2013-2858P4HIGHCVSS 7.5≤ 27.0.1453.109v27.0.1453.0+79 more2013-06-05
CVE-2013-2858 [HIGH] CWE-416 CVE-2013-2858: Use-after-free vulnerability in the HTML5 Audio implementation in Google Chrome before 27.0.1453.110 Use-after-free vulnerability in the HTML5 Audio implementation in Google Chrome before 27.0.1453.110 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2013-2861P4HIGHCVSS 7.5≤ 27.0.1453.109v27.0.1453.0+79 more2013-06-05
CVE-2013-2861 [HIGH] CWE-399 CVE-2013-2861: Use-after-free vulnerability in the SVG implementation in Google Chrome before 27.0.1453.110 allows Use-after-free vulnerability in the SVG implementation in Google Chrome before 27.0.1453.110 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2013-2860P4HIGHCVSS 7.5≤ 27.0.1453.109v27.0.1453.0+79 more2013-06-05
CVE-2013-2860 [HIGH] CWE-416 CVE-2013-2860: Use-after-free vulnerability in Google Chrome before 27.0.1453.110 allows remote attackers to cause Use-after-free vulnerability in Google Chrome before 27.0.1453.110 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving access to a database API by a worker process.
nvd
CVE-2013-0839P4HIGHCVSS 7.5≤ 24.0.1312.55v24.0.1272.0+114 more2013-01-24
CVE-2013-0839 [HIGH] CWE-399 CVE-2013-0839: Use-after-free vulnerability in Google Chrome before 24.0.1312.56 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 24.0.1312.56 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of fonts in CANVAS elements.
nvd
CVE-2013-2837P4HIGHCVSS 7.5≤ 27.0.1453.91v27.0.1453.0+69 more2013-05-22
CVE-2013-2837 [HIGH] CWE-399 CVE-2013-2837: Use-after-free vulnerability in the SVG implementation in Google Chrome before 27.0.1453.93 allows r Use-after-free vulnerability in the SVG implementation in Google Chrome before 27.0.1453.93 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd