cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2

Vulnerabilities

Page 206 of 292
CVE-2011-1294P4HIGHCVSS 7.5fixed in 10.0.648.2042011-03-25
CVE-2011-1294 [HIGH] CWE-20 CVE-2011-1294: Google Chrome before 10.0.648.204 does not properly handle Cascading Style Sheets (CSS) token sequen Google Chrome before 10.0.648.204 does not properly handle Cascading Style Sheets (CSS) token sequences, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."
nvd
CVE-2011-1201P4HIGHCVSS 7.5fixed in 10.0.648.1272011-03-11
CVE-2011-1201 [HIGH] CVE-2011-1201: The context implementation in WebKit, as used in Google Chrome before 10.0.648.127, allows remote at The context implementation in WebKit, as used in Google Chrome before 10.0.648.127, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."
nvd
CVE-2010-1665P4HIGHCVSS 7.5≤ 4.1.249.1063v0.2.149.27+106 more2010-05-03
CVE-2010-1665 [HIGH] CWE-119 CVE-2010-1665: Google Chrome before 4.1.249.1064 does not properly handle fonts, which allows remote attackers to c Google Chrome before 4.1.249.1064 does not properly handle fonts, which allows remote attackers to cause a denial of service (memory corruption) and possibly have unspecified other impact via unknown vectors.
nvd
CVE-2011-1116P4HIGHCVSS 7.5fixed in 9.0.597.1072011-03-01
CVE-2011-1116 [HIGH] CVE-2011-1116: Google Chrome before 9.0.597.107 does not properly handle SVG animations, which allows remote attack Google Chrome before 9.0.597.107 does not properly handle SVG animations, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."
nvd
CVE-2011-1110P4HIGHCVSS 7.5fixed in 9.0.597.1072011-03-01
CVE-2011-1110 [HIGH] CWE-20 CVE-2011-1110: Google Chrome before 9.0.597.107 does not properly implement key frame rules, which allows remote at Google Chrome before 9.0.597.107 does not properly implement key frame rules, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."
nvd
CVE-2011-1125P4HIGHCVSS 7.5fixed in 9.0.597.1072011-03-01
CVE-2011-1125 [HIGH] CVE-2011-1125: Google Chrome before 9.0.597.107 does not properly perform layout, which allows remote attackers to Google Chrome before 9.0.597.107 does not properly perform layout, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."
nvd
CVE-2011-1119P4HIGHCVSS 7.5fixed in 9.0.597.1072011-03-01
CVE-2011-1119 [HIGH] CVE-2011-1119: Google Chrome before 9.0.597.107 does not properly determine device orientation, which allows remote Google Chrome before 9.0.597.107 does not properly determine device orientation, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."
nvd
CVE-2011-1804P4HIGHCVSS 7.5fixed in 11.0.696.712011-05-26
CVE-2011-1804 [HIGH] CWE-20 CVE-2011-1804: rendering/RenderBox.cpp in WebCore in WebKit before r86862, as used in Google Chrome before 11.0.696 rendering/RenderBox.cpp in WebCore in WebKit before r86862, as used in Google Chrome before 11.0.696.71, does not properly render floats, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."
nvd
CVE-2011-3927P4HIGHCVSS 7.5fixed in 16.0.912.772012-01-24
CVE-2011-3927 [HIGH] CWE-665 CVE-2011-3927: Skia, as used in Google Chrome before 16.0.912.77, does not perform all required initialization of v Skia, as used in Google Chrome before 16.0.912.77, does not perform all required initialization of values, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2012-2866P4HIGHCVSS 7.5≤ 21.0.1180.88v21.0.1180.0+50 more2012-08-31
CVE-2012-2866 [HIGH] CVE-2012-2866: Google Chrome before 21.0.1180.89 does not properly perform a cast of an unspecified variable during Google Chrome before 21.0.1180.89 does not properly perform a cast of an unspecified variable during handling of run-in elements, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted document.
nvd
CVE-2013-0891P4HIGHCVSS 7.5fixed in 25.0.1364.97fixed in 25.0.1364.992013-02-23
CVE-2013-0891 [HIGH] CWE-190 CVE-2013-0891: Integer overflow in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 Integer overflow in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a blob.
nvd
CVE-2013-2836P4HIGHCVSS 7.5≤ 27.0.1453.91v27.0.1453.0+69 more2013-05-22
CVE-2013-2836 [HIGH] CVE-2013-2836: Multiple unspecified vulnerabilities in Google Chrome before 27.0.1453.93 allow attackers to cause a Multiple unspecified vulnerabilities in Google Chrome before 27.0.1453.93 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2011-2839P4HIGHCVSS 7.5fixed in 13.0.782.2152011-08-29
CVE-2011-2839 [HIGH] CWE-20 CVE-2011-2839: The PDF implementation in Google Chrome before 13.0.782.215 on Linux does not properly use the memse The PDF implementation in Google Chrome before 13.0.782.215 on Linux does not properly use the memset library function, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2012-5131P4HIGHCVSS 7.5≤ 23.0.1271.89v23.0.1271.0+60 more2012-11-28
CVE-2012-5131 [HIGH] CVE-2012-5131: Google Chrome before 23.0.1271.91 on Mac OS X does not properly mitigate improper rendering behavior Google Chrome before 23.0.1271.91 on Mac OS X does not properly mitigate improper rendering behavior in the Intel GPU driver, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2012-5115P4HIGHCVSS 7.5≤ 23.0.1271.62v23.0.1271.0+52 more2012-11-07
CVE-2012-5115 [HIGH] CWE-119 CVE-2012-5115: Google Chrome before 23.0.1271.64 on Mac OS X does not properly mitigate improper write behavior in Google Chrome before 23.0.1271.64 on Mac OS X does not properly mitigate improper write behavior in graphics drivers, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that trigger "wild writes."
nvd
CVE-2012-5118P4HIGHCVSS 7.5≤ 23.0.1271.62v23.0.1271.0+52 more2012-11-07
CVE-2012-5118 [HIGH] CWE-20 CVE-2012-5118: Google Chrome before 23.0.1271.64 on Mac OS X does not properly validate an integer value during the Google Chrome before 23.0.1271.64 on Mac OS X does not properly validate an integer value during the handling of GPU command buffers, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2010-3414P4CRITICALCVSS 10.0fixed in 6.0.472.592010-09-16
CVE-2010-3414 [CRITICAL] CVE-2010-3414: Google Chrome before 6.0.472.59 on Mac OS X does not properly implement file dialogs, which allows a Google Chrome before 6.0.472.59 on Mac OS X does not properly implement file dialogs, which allows attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors. NOTE: this issue exists because of an incorrect fix for CVE-2010-3112 on Mac OS X.
nvd
CVE-2010-2105P4CRITICALCVSS 10.0fixed in 5.0.375.552010-05-28
CVE-2010-2105 [CRITICAL] CVE-2010-2105: Google Chrome before 5.0.375.55 does not properly follow the Safe Browsing specification's requireme Google Chrome before 5.0.375.55 does not properly follow the Safe Browsing specification's requirements for canonicalization of URLs, which has unspecified impact and remote attack vectors.
nvd
CVE-2012-2883P4HIGHCVSS 7.5≤ 22.0.1229.78v22.0.1229.0+51 more2012-09-26
CVE-2012-2883 [HIGH] CVE-2012-2883: Skia, as used in Google Chrome before 22.0.1229.79, allows remote attackers to cause a denial of ser Skia, as used in Google Chrome before 22.0.1229.79, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger an out-of-bounds write operation, a different vulnerability than CVE-2012-2874.
nvd
CVE-2012-2874P4HIGHCVSS 7.5≤ 22.0.1229.78v22.0.1229.0+51 more2012-09-26
CVE-2012-2874 [HIGH] CWE-119 CVE-2012-2874: Skia, as used in Google Chrome before 22.0.1229.79, allows remote attackers to cause a denial of ser Skia, as used in Google Chrome before 22.0.1229.79, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger an out-of-bounds write operation, a different vulnerability than CVE-2012-2883.
nvd
Google Chrome vulnerabilities | cvebase