Google Chrome vulnerabilities
4,008 known vulnerabilities affecting google/chrome.
Total CVEs
4,008
CISA KEV
74
actively exploited
Public exploits
64
Exploited in wild
65
Severity breakdown
CRITICAL300HIGH2051MEDIUM1628LOW19UNKNOWN10
Vulnerabilities
Page 189 of 201
CVE-2011-1413MEDIUMCVSS 5.0fixed in 10.0.648.1272011-03-11
CVE-2011-1413 [MEDIUM] CVE-2011-1413: Google Chrome before 10.0.648.127 on Linux does not properly mitigate an unspecified flaw in an X se
Google Chrome before 10.0.648.127 on Linux does not properly mitigate an unspecified flaw in an X server, which allows remote attackers to cause a denial of service (application crash) via vectors involving long messages.
nvd
CVE-2011-1204MEDIUMCVSS 6.8fixed in 10.0.648.1272011-03-11
CVE-2011-1204 [MEDIUM] CWE-20 CVE-2011-1204: Google Chrome before 10.0.648.127 does not properly handle attributes, which allows remote attackers
Google Chrome before 10.0.648.127 does not properly handle attributes, which allows remote attackers to cause a denial of service (DOM tree corruption) or possibly have unspecified other impact via a crafted document.
nvd
CVE-2011-1186MEDIUMCVSS 5.0fixed in 10.0.648.1272011-03-11
CVE-2011-1186 [MEDIUM] CWE-20 CVE-2011-1186: Google Chrome before 10.0.648.127 on Linux does not properly handle parallel execution of calls to t
Google Chrome before 10.0.648.127 on Linux does not properly handle parallel execution of calls to the print method, which might allow remote attackers to cause a denial of service (application crash) via crafted JavaScript code.
nvd
CVE-2011-1192MEDIUMCVSS 5.0fixed in 10.0.648.1272011-03-11
CVE-2011-1192 [MEDIUM] CWE-125 CVE-2011-1192: Google Chrome before 10.0.648.127 on Linux does not properly handle Unicode ranges, which allows rem
Google Chrome before 10.0.648.127 on Linux does not properly handle Unicode ranges, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2011-1194MEDIUMCVSS 5.0fixed in 10.0.648.1272011-03-11
CVE-2011-1194 [MEDIUM] CVE-2011-1194: Multiple unspecified vulnerabilities in Google Chrome before 10.0.648.127 allow remote attackers to
Multiple unspecified vulnerabilities in Google Chrome before 10.0.648.127 allow remote attackers to bypass the pop-up blocker via unknown vectors.
nvd
CVE-2011-1124HIGHCVSS 7.5fixed in 9.0.597.1072011-03-01
CVE-2011-1124 [HIGH] CWE-416 CVE-2011-1124: Use-after-free vulnerability in Google Chrome before 9.0.597.107 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 9.0.597.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to blocked plug-ins.
nvd
CVE-2011-1123HIGHCVSS 7.5fixed in 9.0.597.1072011-03-01
CVE-2011-1123 [HIGH] CWE-863 CVE-2011-1123: Google Chrome before 9.0.597.107 does not properly restrict access to internal extension functions,
Google Chrome before 9.0.597.107 does not properly restrict access to internal extension functions, which has unspecified impact and remote attack vectors.
nvd
CVE-2011-1119HIGHCVSS 7.5fixed in 9.0.597.1072011-03-01
CVE-2011-1119 [HIGH] CVE-2011-1119: Google Chrome before 9.0.597.107 does not properly determine device orientation, which allows remote
Google Chrome before 9.0.597.107 does not properly determine device orientation, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."
nvd
CVE-2011-1117HIGHCVSS 7.5fixed in 9.0.597.1072011-03-01
CVE-2011-1117 [HIGH] CVE-2011-1117: Google Chrome before 9.0.597.107 does not properly handle XHTML documents, which allows remote attac
Google Chrome before 9.0.597.107 does not properly handle XHTML documents, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to "stale nodes."
nvd
CVE-2011-1121HIGHCVSS 7.5fixed in 9.0.597.1072011-03-01
CVE-2011-1121 [HIGH] CWE-190 CVE-2011-1121: Integer overflow in Google Chrome before 9.0.597.107 allows remote attackers to cause a denial of se
Integer overflow in Google Chrome before 9.0.597.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving a TEXTAREA element.
nvd
CVE-2011-1112HIGHCVSS 7.5fixed in 9.0.597.1072011-03-01
CVE-2011-1112 [HIGH] CVE-2011-1112: Google Chrome before 9.0.597.107 does not properly perform SVG rendering, which allows remote attack
Google Chrome before 9.0.597.107 does not properly perform SVG rendering, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2011-1116HIGHCVSS 7.5fixed in 9.0.597.1072011-03-01
CVE-2011-1116 [HIGH] CVE-2011-1116: Google Chrome before 9.0.597.107 does not properly handle SVG animations, which allows remote attack
Google Chrome before 9.0.597.107 does not properly handle SVG animations, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."
nvd
CVE-2011-1110HIGHCVSS 7.5fixed in 9.0.597.1072011-03-01
CVE-2011-1110 [HIGH] CWE-20 CVE-2011-1110: Google Chrome before 9.0.597.107 does not properly implement key frame rules, which allows remote at
Google Chrome before 9.0.597.107 does not properly implement key frame rules, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."
nvd
CVE-2011-1114HIGHCVSS 7.5fixed in 9.0.597.1072011-03-01
CVE-2011-1114 [HIGH] CVE-2011-1114: Google Chrome before 9.0.597.107 does not properly handle tables, which allows remote attackers to c
Google Chrome before 9.0.597.107 does not properly handle tables, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale node."
nvd
CVE-2011-1125HIGHCVSS 7.5fixed in 9.0.597.1072011-03-01
CVE-2011-1125 [HIGH] CVE-2011-1125: Google Chrome before 9.0.597.107 does not properly perform layout, which allows remote attackers to
Google Chrome before 9.0.597.107 does not properly perform layout, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."
nvd
CVE-2011-1111HIGHCVSS 7.5fixed in 9.0.597.1072011-03-01
CVE-2011-1111 [HIGH] CWE-20 CVE-2011-1111: Google Chrome before 9.0.597.107 does not properly implement forms controls, which allows remote att
Google Chrome before 9.0.597.107 does not properly implement forms controls, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2011-1115HIGHCVSS 7.5fixed in 9.0.597.1072011-03-01
CVE-2011-1115 [HIGH] CVE-2011-1115: Google Chrome before 9.0.597.107 does not properly render tables, which allows remote attackers to c
Google Chrome before 9.0.597.107 does not properly render tables, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."
nvd
CVE-2011-1109HIGHCVSS 7.5fixed in 9.0.597.1072011-03-01
CVE-2011-1109 [HIGH] CWE-20 CVE-2011-1109: Google Chrome before 9.0.597.107 does not properly process nodes in Cascading Style Sheets (CSS) sty
Google Chrome before 9.0.597.107 does not properly process nodes in Cascading Style Sheets (CSS) stylesheets, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."
nvd
CVE-2011-1113MEDIUMCVSS 5.0fixed in 9.0.597.1072011-03-01
CVE-2011-1113 [MEDIUM] CWE-125 CVE-2011-1113: Google Chrome before 9.0.597.107 on 64-bit Linux platforms does not properly perform pickle deserial
Google Chrome before 9.0.597.107 on 64-bit Linux platforms does not properly perform pickle deserialization, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2011-1107MEDIUMCVSS 4.3fixed in 9.0.597.1072011-03-01
CVE-2011-1107 [MEDIUM] CVE-2011-1107: Unspecified vulnerability in Google Chrome before 9.0.597.107 allows remote attackers to spoof the U
Unspecified vulnerability in Google Chrome before 9.0.597.107 allows remote attackers to spoof the URL bar via unknown vectors.
nvd