cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2

Vulnerabilities

Page 196 of 292
CVE-2011-1198P4HIGHCVSS 7.5fixed in 10.0.648.1272011-03-11
CVE-2011-1198 [HIGH] CWE-119 CVE-2011-1198: The video functionality in Google Chrome before 10.0.648.127 allows remote attackers to cause a deni The video functionality in Google Chrome before 10.0.648.127 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that trigger use of a malformed "out-of-bounds structure."
nvd
CVE-2011-1196P4HIGHCVSS 7.5fixed in 10.0.648.1272011-03-11
CVE-2011-1196 [HIGH] CVE-2011-1196: The OGG container implementation in Google Chrome before 10.0.648.127 allows remote attackers to cau The OGG container implementation in Google Chrome before 10.0.648.127 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that trigger an out-of-bounds write.
nvd
CVE-2014-1743P4HIGHCVSS 7.5≤ 35.0.1916.113v35.0.1916.0+78 more2014-05-21
CVE-2014-1743 [HIGH] CWE-399 CVE-2014-1743: Use-after-free vulnerability in the StyleElement::removedFromDocument function in core/dom/StyleElem Use-after-free vulnerability in the StyleElement::removedFromDocument function in core/dom/StyleElement.cpp in Blink, as used in Google Chrome before 35.0.1916.114, allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted JavaScript code that triggers tree mutation.
nvd
CVE-2011-1286P4HIGHCVSS 7.5fixed in 10.0.648.1272011-03-11
CVE-2011-1286 [HIGH] CVE-2011-1286: Google V8, as used in Google Chrome before 10.0.648.127, allows remote attackers to cause a denial o Google V8, as used in Google Chrome before 10.0.648.127, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that trigger incorrect access to memory.
nvd
CVE-2011-1285P4HIGHCVSS 7.5fixed in 10.0.648.1272011-03-11
CVE-2011-1285 [HIGH] CWE-119 CVE-2011-1285: The regular-expression functionality in Google Chrome before 10.0.648.127 does not properly implemen The regular-expression functionality in Google Chrome before 10.0.648.127 does not properly implement reentrancy, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2011-0985P4HIGHCVSS 7.5fixed in 9.0.597.942011-02-10
CVE-2011-0985 [HIGH] CWE-400 CVE-2011-0985: Google Chrome before 9.0.597.94 does not properly perform process termination upon memory exhaustion Google Chrome before 9.0.597.94 does not properly perform process termination upon memory exhaustion, which has unspecified impact and remote attack vectors.
nvd
CVE-2016-1670P4MEDIUMCVSS 5.3≤ 50.0.2661.872016-05-14
CVE-2016-1670 [MEDIUM] CWE-362 CVE-2016-1670: Race condition in the ResourceDispatcherHostImpl::BeginRequest function in content/browser/loader/re Race condition in the ResourceDispatcherHostImpl::BeginRequest function in content/browser/loader/resource_dispatcher_host_impl.cc in Google Chrome before 50.0.2661.102 allows remote attackers to make arbitrary HTTP requests by leveraging access to a renderer process and reusing a request ID.
nvd
CVE-2011-3925P4HIGHCVSS 7.5fixed in 16.0.912.752012-01-24
CVE-2011-3925 [HIGH] CWE-416 CVE-2011-3925: Use-after-free vulnerability in the Safe Browsing feature in Google Chrome before 16.0.912.75 allows Use-after-free vulnerability in the Safe Browsing feature in Google Chrome before 16.0.912.75 allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via vectors related to a navigation entry and an interstitial page.
nvd
CVE-2011-3113P4HIGHCVSS 7.5≤ 19.0.1084.51v19.0.1028.0+130 more2012-05-24
CVE-2011-3113 [HIGH] CVE-2011-3113: The PDF functionality in Google Chrome before 19.0.1084.52 does not properly perform a cast of an un The PDF functionality in Google Chrome before 19.0.1084.52 does not properly perform a cast of an unspecified variable during handling of color spaces, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted document.
nvd
CVE-2014-3190P4HIGHCVSS 7.5≤ 38.0.2125.72014-10-08
CVE-2014-3190 [HIGH] CWE-416 CVE-2014-3190: Use-after-free vulnerability in the Event::currentTarget function in core/events/Event.cpp in Blink, Use-after-free vulnerability in the Event::currentTarget function in core/events/Event.cpp in Blink, as used in Google Chrome before 38.0.2125.101, allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted JavaScript code that accesses the path property of an Event object.
nvd
CVE-2015-1259P4HIGHCVSS 7.5≤ 42.0.2311.1522015-05-20
CVE-2015-1259 [HIGH] CWE-17 CVE-2015-1259: PDFium, as used in Google Chrome before 43.0.2357.65, does not properly initialize memory, which all PDFium, as used in Google Chrome before 43.0.2357.65, does not properly initialize memory, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2011-3109P4HIGHCVSS 7.5≤ 19.0.1084.51v19.0.1028.0+130 more2012-05-24
CVE-2011-3109 [HIGH] CVE-2011-3109: Google Chrome before 19.0.1084.52 on Linux does not properly perform a cast of an unspecified variab Google Chrome before 19.0.1084.52 on Linux does not properly perform a cast of an unspecified variable, which allows remote attackers to cause a denial of service or possibly have unknown other impact by leveraging an error in the GTK implementation of the UI.
nvd
CVE-2013-0890P4HIGHCVSS 7.5fixed in 25.0.1364.97fixed in 25.0.1364.992013-02-23
CVE-2013-0890 [HIGH] CWE-787 CVE-2013-0890: Multiple unspecified vulnerabilities in the IPC layer in Google Chrome before 25.0.1364.97 on Window Multiple unspecified vulnerabilities in the IPC layer in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allow remote attackers to cause a denial of service (memory corruption) or possibly have other impact via unknown vectors.
nvd
CVE-2012-5124P4HIGHCVSS 7.5≤ 23.0.1271.62v23.0.1271.0+52 more2012-11-07
CVE-2012-5124 [HIGH] CWE-119 CVE-2012-5124: Google Chrome before 23.0.1271.64 does not properly handle textures, which allows remote attackers t Google Chrome before 23.0.1271.64 does not properly handle textures, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2012-2885P4HIGHCVSS 7.5≤ 22.0.1229.78v22.0.1229.0+51 more2012-09-26
CVE-2012-2885 [HIGH] CWE-399 CVE-2012-2885: Double free vulnerability in Google Chrome before 22.0.1229.79 allows remote attackers to cause a de Double free vulnerability in Google Chrome before 22.0.1229.79 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to application exit.
nvd
CVE-2016-1612P4HIGHCVSS 7.6≤ 47.0.2526.1062016-01-25
CVE-2016-1612 [HIGH] CWE-20 CVE-2016-1612: The LoadIC::UpdateCaches function in ic/ic.cc in Google V8, as used in Google Chrome before 48.0.256 The LoadIC::UpdateCaches function in ic/ic.cc in Google V8, as used in Google Chrome before 48.0.2564.82, does not ensure receiver compatibility before performing a cast of an unspecified variable, which allows remote attackers to cause a denial of service or possibly have unknown other impact via crafted JavaScript code.
nvd
CVE-2016-1619P4HIGHCVSS 7.6≤ 47.0.2526.1062016-01-25
CVE-2016-1619 [HIGH] CWE-119 CVE-2016-1619: Multiple integer overflows in the (1) sycc422_to_rgb and (2) sycc444_to_rgb functions in fxcodec/cod Multiple integer overflows in the (1) sycc422_to_rgb and (2) sycc444_to_rgb functions in fxcodec/codec/fx_codec_jpx_opj.cpp in PDFium, as used in Google Chrome before 48.0.2564.82, allow remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted PDF document.
nvd
CVE-2011-2853P4HIGHCVSS 7.5fixed in 14.0.835.1632011-09-19
CVE-2011-2853 [HIGH] CWE-416 CVE-2011-2853: Use-after-free vulnerability in Google Chrome before 14.0.835.163 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 14.0.835.163 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to plug-in handling.
nvd
CVE-2013-2887P4HIGHCVSS 7.5≤ 29.0.1547.56v29.0.1547.0+49 more2013-08-21
CVE-2013-2887 [HIGH] CVE-2013-2887: Multiple unspecified vulnerabilities in Google Chrome before 29.0.1547.57 allow attackers to cause a Multiple unspecified vulnerabilities in Google Chrome before 29.0.1547.57 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2013-6637P4HIGHCVSS 7.5≤ 31.0.1650.62v31.0.1650.0+56 more2013-12-07
CVE-2013-6637 [HIGH] CVE-2013-6637: Multiple unspecified vulnerabilities in Google Chrome before 31.0.1650.63 allow attackers to cause a Multiple unspecified vulnerabilities in Google Chrome before 31.0.1650.63 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
Google Chrome vulnerabilities | cvebase