cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2

Vulnerabilities

Page 189 of 292
CVE-2010-4034P4CRITICALCVSS 9.3≤ 7.0.517.40v6.0.454.0+177 more2010-10-21
CVE-2010-4034 [CRITICAL] CWE-20 CVE-2010-4034: Google Chrome before 7.0.517.41 does not properly handle forms, which allows remote attackers to cau Google Chrome before 7.0.517.41 does not properly handle forms, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted HTML document.
nvd
CVE-2015-8478P4HIGHCVSS 7.5≤ 46.0.2490.862015-12-06
CVE-2015-8478 [HIGH] CVE-2015-8478: Multiple unspecified vulnerabilities in Google V8 before 4.7.80.23, as used in Google Chrome before Multiple unspecified vulnerabilities in Google V8 before 4.7.80.23, as used in Google Chrome before 47.0.2526.73, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2017-15422P4MEDIUMCVSS 6.5fixed in 63.0.3239.842018-08-28
CVE-2017-15422 [MEDIUM] CWE-190 CVE-2017-15422: Integer overflow in international date handling in International Components for Unicode (ICU) for C/ Integer overflow in international date handling in International Components for Unicode (ICU) for C/C++ before 60.1, as used in V8 in Google Chrome prior to 63.0.3239.84 and other products, allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
nvd
CVE-2015-1234P4MEDIUMCVSS 6.8≤ 41.0.2272.1022015-04-01
CVE-2015-1234 [MEDIUM] CWE-362 CVE-2015-1234: Race condition in gpu/command_buffer/service/gles2_cmd_decoder.cc in Google Chrome before 41.0.2272. Race condition in gpu/command_buffer/service/gles2_cmd_decoder.cc in Google Chrome before 41.0.2272.118 allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact by manipulating OpenGL ES commands.
nvd
CVE-2012-2850P4MEDIUMCVSS 6.8≤ 21.0.1180.56v21.0.1180.0+25 more2012-08-06
CVE-2012-2850 [MEDIUM] CVE-2012-2850: Multiple unspecified vulnerabilities in the PDF functionality in Google Chrome before 21.0.1180.57 o Multiple unspecified vulnerabilities in the PDF functionality in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, allow remote attackers to have an unknown impact via a crafted document.
nvd
CVE-2011-2805P4MEDIUMCVSS 6.8fixed in 13.0.782.1072011-08-03
CVE-2011-2805 [MEDIUM] CWE-74 CVE-2011-2805: Google Chrome before 13.0.782.107 allows remote attackers to bypass the Same Origin Policy and condu Google Chrome before 13.0.782.107 allows remote attackers to bypass the Same Origin Policy and conduct script injection attacks via unspecified vectors.
nvd
CVE-2014-3160P4MEDIUMCVSS 6.8v36.0.1985.1v36.0.1985.2+101 more2014-07-20
CVE-2014-3160 [MEDIUM] CWE-264 CVE-2014-3160: The ResourceFetcher::canRequest function in core/fetch/ResourceFetcher.cpp in Blink, as used in Goog The ResourceFetcher::canRequest function in core/fetch/ResourceFetcher.cpp in Blink, as used in Google Chrome before 36.0.1985.125, does not properly restrict subresource requests associated with SVG files, which allows remote attackers to bypass the Same Origin Policy via a crafted file.
nvd
CVE-2021-30597P4MEDIUMCVSS 6.8fixed in 92.0.4515.131≥ unspecified, < 92.0.4515.1312021-08-26
CVE-2021-30597 [MEDIUM] CWE-416 CVE-2021-30597: Use after free in Browser UI in Google Chrome on Chrome prior to 92.0.4515.131 allowed a remote atta Use after free in Browser UI in Google Chrome on Chrome prior to 92.0.4515.131 allowed a remote attacker to potentially exploit heap corruption via physical access to the device.
nvd
CVE-2018-6117P4MEDIUMCVSS 6.5fixed in 66.0.3359.117≥ unspecified, < 66.0.3359.1172019-01-09
CVE-2018-6117 [MEDIUM] CWE-200 CVE-2018-6117: Confusing settings in Autofill in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to Confusing settings in Autofill in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
nvd
CVE-2020-6408P4MEDIUMCVSS 6.5fixed in 80.0.3987.87≥ unspecified, < 80.0.3987.872020-02-11
CVE-2020-6408 [MEDIUM] CVE-2020-6408: Insufficient policy enforcement in CORS in Google Chrome prior to 80.0.3987.87 allowed a local attac Insufficient policy enforcement in CORS in Google Chrome prior to 80.0.3987.87 allowed a local attacker to obtain potentially sensitive information via a crafted HTML page.
nvd
CVE-2019-5818P4MEDIUMCVSS 6.5fixed in 74.0.3729.108≥ unspecified, < 74.0.3729.1082019-06-27
CVE-2019-5818 [MEDIUM] CWE-908 CVE-2019-5818: Uninitialized data in media in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to obt Uninitialized data in media in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted video file.
nvd
CVE-2018-6143P4MEDIUMCVSS 6.5fixed in 67.0.3396.62≥ unspecified, < 67.0.3396.622019-01-09
CVE-2018-6143 [MEDIUM] CWE-125 CVE-2018-6143: Insufficient validation in V8 in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to pe Insufficient validation in V8 in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
nvd
CVE-2018-6089P4MEDIUMCVSS 6.5fixed in 66.0.3359.117≥ unspecified, < 66.0.3359.1172018-12-04
CVE-2018-6089 [MEDIUM] CWE-20 CVE-2018-6089: A lack of CORS checks, after a Service Worker redirected to a cross-origin PDF, in Service Worker in A lack of CORS checks, after a Service Worker redirected to a cross-origin PDF, in Service Worker in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to leak limited cross-origin data via a crafted HTML page.
nvd
CVE-2019-5784P4MEDIUMCVSS 6.5fixed in 72.0.3626.96≥ unspecified, < 72.0.3626.962019-06-27
CVE-2019-5784 [MEDIUM] CWE-787 CVE-2019-5784: Incorrect handling of deferred code in V8 in Google Chrome prior to 72.0.3626.96 allowed a remote at Incorrect handling of deferred code in V8 in Google Chrome prior to 72.0.3626.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2018-16082P4MEDIUMCVSS 6.5fixed in 69.0.3497.81≥ unspecified, < 69.0.3497.812019-01-09
CVE-2018-16082 [MEDIUM] CWE-125 CVE-2018-16082: An out of bounds read in Swiftshader in Google Chrome prior to 69.0.3497.81 allowed a remote attacke An out of bounds read in Swiftshader in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
nvd
CVE-2020-6564P4MEDIUMCVSS 6.5fixed in 85.0.4183.83≥ unspecified, < 85.0.4183.832020-09-21
CVE-2020-6564 [MEDIUM] CWE-281 CVE-2020-6564: Inappropriate implementation in permissions in Google Chrome prior to 85.0.4183.83 allowed a remote Inappropriate implementation in permissions in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to spoof the contents of a permission dialog via a crafted HTML page.
nvd
CVE-2019-5837P4MEDIUMCVSS 6.5fixed in 75.0.3770.80≥ unspecified, < 75.0.3770.802019-06-27
CVE-2019-5837 [MEDIUM] CVE-2019-5837: Resource size information leakage in Blink in Google Chrome prior to 75.0.3770.80 allowed a remote a Resource size information leakage in Blink in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2018-6077P4MEDIUMCVSS 6.5fixed in 65.0.3325.146≥ unspecified, < 65.0.3325.1462018-11-14
CVE-2018-6077 [MEDIUM] CWE-200 CVE-2018-6077: Displacement map filters being applied to cross-origin images in Blink SVG rendering in Google Chrom Displacement map filters being applied to cross-origin images in Blink SVG rendering in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2020-6557P4MEDIUMCVSS 6.5fixed in 86.0.4240.75≥ unspecified, < 86.0.4240.752020-11-03
CVE-2020-6557 [MEDIUM] CVE-2020-6557: Inappropriate implementation in networking in Google Chrome prior to 86.0.4240.75 allowed a remote a Inappropriate implementation in networking in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
nvd
CVE-2020-6568P4MEDIUMCVSS 6.5fixed in 85.0.4183.83≥ unspecified, < 85.0.4183.832020-09-21
CVE-2020-6568 [MEDIUM] CVE-2020-6568: Insufficient policy enforcement in intent handling in Google Chrome on Android prior to 85.0.4183.83 Insufficient policy enforcement in intent handling in Google Chrome on Android prior to 85.0.4183.83 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
nvd
Google Chrome vulnerabilities | cvebase