cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2

Vulnerabilities

Page 199 of 292
CVE-2014-7967P4HIGHCVSS 7.5≤ 38.0.2125.72014-10-08
CVE-2014-7967 [HIGH] CVE-2014-7967: Multiple unspecified vulnerabilities in Google V8 before 3.28.71.15, as used in Google Chrome before Multiple unspecified vulnerabilities in Google V8 before 3.28.71.15, as used in Google Chrome before 38.0.2125.101, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2011-3071P4MEDIUMCVSS 6.8fixed in 18.0.1025.1512012-04-05
CVE-2011-3071 [MEDIUM] CWE-416 CVE-2011-3071: Use-after-free vulnerability in the HTMLMediaElement implementation in Google Chrome before 18.0.102 Use-after-free vulnerability in the HTMLMediaElement implementation in Google Chrome before 18.0.1025.151 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2015-1220P4MEDIUMCVSS 6.8≤ 40.0.2214.1152015-03-09
CVE-2015-1220 [MEDIUM] CVE-2015-1220: Use-after-free vulnerability in the GIFImageReader::parseData function in platform/image-decoders/gi Use-after-free vulnerability in the GIFImageReader::parseData function in platform/image-decoders/gif/GIFImageReader.cpp in Blink, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted frame size in a GIF image.
nvd
CVE-2010-4490P4CRITICALCVSS 9.3≤ 8.0.552.2142010-12-07
CVE-2010-4490 [CRITICAL] CVE-2010-4490: Google Chrome before 8.0.552.215 allows remote attackers to cause a denial of service (application c Google Chrome before 8.0.552.215 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via malformed video content that triggers an indexing error.
nvd
CVE-2010-0661P4MEDIUMCVSS 6.8≤ 4.0.249.0v0.2.149.27+46 more2010-02-18
CVE-2010-0661 [MEDIUM] CWE-264 CVE-2010-0661: WebCore/bindings/v8/custom/V8DOMWindowCustom.cpp in WebKit before r52401, as used in Google Chrome b WebCore/bindings/v8/custom/V8DOMWindowCustom.cpp in WebKit before r52401, as used in Google Chrome before 4.0.249.78, allows remote attackers to bypass the Same Origin Policy via vectors involving the window.open method.
nvd
CVE-2010-2651P4CRITICALCVSS 9.3fixed in 5.0.375.992010-07-06
CVE-2010-2651 [CRITICAL] CWE-119 CVE-2010-2651: The Cascading Style Sheets (CSS) implementation in Google Chrome before 5.0.375.99 does not properly The Cascading Style Sheets (CSS) implementation in Google Chrome before 5.0.375.99 does not properly perform style rendering, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2010-0649P4CRITICALCVSS 9.3≤ 4.0.249.78v0.2.149.27+45 more2010-02-18
CVE-2010-0649 [CRITICAL] CWE-189 CVE-2010-0649: Integer overflow in the CrossCallParamsEx::CreateFromBuffer function in sandbox/src/crosscall_server Integer overflow in the CrossCallParamsEx::CreateFromBuffer function in sandbox/src/crosscall_server.cc in Google Chrome before 4.0.249.89 allows attackers to leverage renderer access to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a malformed message, related to deserializing of sandbox messages.
nvd
CVE-2012-4907P4CRITICALCVSS 9.3≤ 18.0.10253062012-09-13
CVE-2012-4907 [CRITICAL] CWE-264 CVE-2012-4907: Google Chrome before 18.0.1025308 on Android does not properly restrict access from JavaScript code Google Chrome before 18.0.1025308 on Android does not properly restrict access from JavaScript code to Android APIs, which allows remote attackers to have an unspecified impact via a crafted web page.
nvd
CVE-2016-5135P4MEDIUMCVSS 6.5≤ 51.0.2704.1062016-07-23
CVE-2016-5135 [MEDIUM] CWE-20 CVE-2016-5135: WebKit/Source/core/html/parser/HTMLPreloadScanner.cpp in Blink, as used in Google Chrome before 52.0 WebKit/Source/core/html/parser/HTMLPreloadScanner.cpp in Blink, as used in Google Chrome before 52.0.2743.82, does not consider referrer-policy information inside an HTML document during a preload request, which allows remote attackers to bypass the Content Security Policy (CSP) protection mechanism via a crafted web site, as demonstrated by a "Content
nvd
CVE-2017-5094P4MEDIUMCVSS 6.5fixed in 60.0.3112.782017-10-27
CVE-2017-5094 [MEDIUM] CWE-843 CVE-2017-5094: Type confusion in extensions JavaScript bindings in Google Chrome prior to 60.0.3112.78 for Mac, Win Type confusion in extensions JavaScript bindings in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attacker to potentially maliciously modify objects via a crafted HTML page.
nvd
CVE-2017-15420P4MEDIUMCVSS 6.5fixed in 63.0.3239.84≥ unspecified, < 63.0.3239.842018-08-28
CVE-2017-15420 [MEDIUM] CWE-20 CVE-2017-15420: Incorrect handling of back navigations in error pages in Navigation in Google Chrome prior to 63.0.3 Incorrect handling of back navigations in error pages in Navigation in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd
CVE-2018-6038P4MEDIUMCVSS 6.5fixed in 64.0.3282.119≥ unspecified, < 64.0.3282.1192018-09-25
CVE-2018-6038 [MEDIUM] CWE-119 CVE-2018-6038: Heap buffer overflow in WebGL in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to p Heap buffer overflow in WebGL in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
nvd
CVE-2017-15386P4MEDIUMCVSS 6.5fixed in 62.0.3202.622018-02-07
CVE-2017-15386 [MEDIUM] CWE-20 CVE-2017-15386: Incorrect implementation in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker t Incorrect implementation in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd
CVE-2018-17468P4MEDIUMCVSS 6.5fixed in 70.0.3538.67≥ unspecified, < 70.0.3538.672018-11-14
CVE-2018-17468 [MEDIUM] CWE-200 CVE-2018-17468: Incorrect handling of timer information during navigation in Blink in Google Chrome prior to 70.0.35 Incorrect handling of timer information during navigation in Blink in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to obtain cross origin URLs via a crafted HTML page.
nvd
CVE-2018-6165P4MEDIUMCVSS 6.5fixed in 68.0.3440.75≥ unspecified, < 68.0.3440.752019-01-09
CVE-2018-6165 [MEDIUM] CVE-2018-6165: Incorrect handling of reloads in Navigation in Google Chrome prior to 68.0.3440.75 allowed a remote Incorrect handling of reloads in Navigation in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd
CVE-2018-6096P4MEDIUMCVSS 6.5fixed in 66.0.3359.117≥ unspecified, < 66.0.3359.1172019-01-09
CVE-2018-6096 [MEDIUM] CWE-20 CVE-2018-6096: A JavaScript focused window could overlap the fullscreen notification in Fullscreen in Google Chrome A JavaScript focused window could overlap the fullscreen notification in Fullscreen in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to obscure the full screen warning via a crafted HTML page.
nvd
CVE-2018-6075P4MEDIUMCVSS 6.5fixed in 65.0.3325.146≥ unspecified, < 65.0.3325.1462018-11-14
CVE-2018-6075 [MEDIUM] CWE-200 CVE-2018-6075: Incorrect handling of specified filenames in file downloads in Google Chrome prior to 65.0.3325.146 Incorrect handling of specified filenames in file downloads in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to leak cross-origin data via a crafted HTML page and user interaction.
nvd
CVE-2019-5776P4MEDIUMCVSS 6.5fixed in 72.0.3626.81≥ unspecified, < 72.0.3626.812019-02-19
CVE-2019-5776 [MEDIUM] CVE-2019-5776: Incorrect handling of a confusable character in Omnibox in Google Chrome prior to 72.0.3626.81 allow Incorrect handling of a confusable character in Omnibox in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.
nvd
CVE-2019-5777P4MEDIUMCVSS 6.5fixed in 72.0.3626.81≥ unspecified, < 72.0.3626.812019-02-19
CVE-2019-5777 [MEDIUM] CVE-2019-5777: Incorrect handling of a confusable character in Omnibox in Google Chrome prior to 72.0.3626.81 allow Incorrect handling of a confusable character in Omnibox in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.
nvd
CVE-2019-5775P4MEDIUMCVSS 6.5fixed in 72.0.3626.81≥ unspecified, < 72.0.3626.812019-02-19
CVE-2019-5775 [MEDIUM] CVE-2019-5775: Incorrect handling of a confusable character in Omnibox in Google Chrome prior to 72.0.3626.81 allow Incorrect handling of a confusable character in Omnibox in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.
nvd
Google Chrome vulnerabilities | cvebase