cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2

Vulnerabilities

Page 209 of 292
CVE-2011-3038P4MEDIUMCVSS 6.8fixed in 17.0.963.652012-03-05
CVE-2011-3038 [MEDIUM] CWE-416 CVE-2011-3038: Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to multi-column handling.
nvd
CVE-2011-3070P4MEDIUMCVSS 6.8fixed in 18.0.1025.1512012-04-05
CVE-2011-3070 [MEDIUM] CWE-416 CVE-2011-3070: Use-after-free vulnerability in Google Chrome before 18.0.1025.151 allows remote attackers to cause Use-after-free vulnerability in Google Chrome before 18.0.1025.151 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the Google V8 bindings.
nvd
CVE-2011-3076P4MEDIUMCVSS 6.8fixed in 18.0.1025.1512012-04-05
CVE-2011-3076 [MEDIUM] CWE-416 CVE-2011-3076: Use-after-free vulnerability in Google Chrome before 18.0.1025.151 allows remote attackers to cause Use-after-free vulnerability in Google Chrome before 18.0.1025.151 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to focus handling.
nvd
CVE-2011-3069P4MEDIUMCVSS 6.8fixed in 18.0.1025.1512012-04-05
CVE-2011-3069 [MEDIUM] CWE-416 CVE-2011-3069: Use-after-free vulnerability in the Cascading Style Sheets (CSS) implementation in Google Chrome bef Use-after-free vulnerability in the Cascading Style Sheets (CSS) implementation in Google Chrome before 18.0.1025.151 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to line boxes.
nvd
CVE-2011-3074P4MEDIUMCVSS 6.8fixed in 18.0.1025.1512012-04-05
CVE-2011-3074 [MEDIUM] CWE-416 CVE-2011-3074: Use-after-free vulnerability in Google Chrome before 18.0.1025.151 allows remote attackers to cause Use-after-free vulnerability in Google Chrome before 18.0.1025.151 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of media.
nvd
CVE-2011-3073P4MEDIUMCVSS 6.8fixed in 18.0.1025.1512012-04-05
CVE-2011-3073 [MEDIUM] CWE-416 CVE-2011-3073: Use-after-free vulnerability in Google Chrome before 18.0.1025.151 allows remote attackers to cause Use-after-free vulnerability in Google Chrome before 18.0.1025.151 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of SVG resources.
nvd
CVE-2011-3068P4MEDIUMCVSS 6.8fixed in 18.0.1025.1512012-04-05
CVE-2011-3068 [MEDIUM] CWE-416 CVE-2011-3068: Use-after-free vulnerability in the Cascading Style Sheets (CSS) implementation in Google Chrome bef Use-after-free vulnerability in the Cascading Style Sheets (CSS) implementation in Google Chrome before 18.0.1025.151 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to run-in boxes.
nvd
CVE-2011-3053P4MEDIUMCVSS 6.8fixed in 17.0.963.832012-03-22
CVE-2011-3053 [MEDIUM] CWE-416 CVE-2011-3053: Use-after-free vulnerability in Google Chrome before 17.0.963.83 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 17.0.963.83 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to block splitting.
nvd
CVE-2011-3042P4MEDIUMCVSS 6.8fixed in 17.0.963.652012-03-05
CVE-2011-3042 [MEDIUM] CWE-416 CVE-2011-3042: Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of table sections.
nvd
CVE-2011-3039P4MEDIUMCVSS 6.8fixed in 17.0.963.652012-03-05
CVE-2011-3039 [MEDIUM] CWE-416 CVE-2011-3039: Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to quote handling.
nvd
CVE-2011-3043P4MEDIUMCVSS 6.8fixed in 17.0.963.652012-03-05
CVE-2011-3043 [MEDIUM] CWE-416 CVE-2011-3043: Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving a flexbox (aka flexible box) in conjunction with the floating of elements.
nvd
CVE-2011-3044P4MEDIUMCVSS 6.8fixed in 17.0.963.652012-03-05
CVE-2011-3044 [MEDIUM] CWE-416 CVE-2011-3044: Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving SVG animation elements.
nvd
CVE-2011-3035P4MEDIUMCVSS 6.8fixed in 17.0.963.652012-03-05
CVE-2011-3035 [MEDIUM] CWE-416 CVE-2011-3035: Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving SVG use elements.
nvd
CVE-2011-3034P4MEDIUMCVSS 6.8fixed in 17.0.963.652012-03-05
CVE-2011-3034 [MEDIUM] CWE-416 CVE-2011-3034: Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving an SVG document.
nvd
CVE-2013-2927P4MEDIUMCVSS 6.8≤ 30.0.1599.100v30.0.1599.0+72 more2013-10-16
CVE-2013-2927 [MEDIUM] CWE-399 CVE-2013-2927: Use-after-free vulnerability in the HTMLFormElement::prepareForSubmission function in core/html/HTML Use-after-free vulnerability in the HTMLFormElement::prepareForSubmission function in core/html/HTMLFormElement.cpp in Blink, as used in Google Chrome before 30.0.1599.101, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to submission for FORM elements.
nvd
CVE-2010-3249P4CRITICALCVSS 9.3fixed in 6.0.472.532010-09-07
CVE-2010-3249 [CRITICAL] CVE-2010-3249: Google Chrome before 6.0.472.53 does not properly implement SVG filters, which allows remote attacke Google Chrome before 6.0.472.53 does not properly implement SVG filters, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors, related to a "stale pointer" issue.
nvd
CVE-2015-1359P4MEDIUMCVSS 6.8≤ 40.0.2214.852015-01-27
CVE-2015-1359 [MEDIUM] CVE-2015-1359: Multiple off-by-one errors in fpdfapi/fpdf_font/font_int.h in PDFium, as used in Google Chrome befor Multiple off-by-one errors in fpdfapi/fpdf_font/font_int.h in PDFium, as used in Google Chrome before 40.0.2214.91, allow remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a crafted PDF document, related to an "intra-object-overflow" issue, a different vulnerability than CVE-2015-1205.
nvd
CVE-2011-2861P4MEDIUMCVSS 6.8fixed in 14.0.835.1632011-09-19
CVE-2011-2861 [MEDIUM] CWE-20 CVE-2011-2861: Google Chrome before 14.0.835.163 does not properly handle strings in PDF documents, which allows re Google Chrome before 14.0.835.163 does not properly handle strings in PDF documents, which allows remote attackers to have an unspecified impact via a crafted document that triggers an incorrect read operation.
nvd
CVE-2013-6634P4MEDIUMCVSS 6.8≤ 31.0.1650.62v31.0.1650.0+56 more2013-12-07
CVE-2013-6634 [MEDIUM] CWE-287 CVE-2013-6634: The OneClickSigninHelper::ShowInfoBarIfPossible function in browser/ui/sync/one_click_signin_helper. The OneClickSigninHelper::ShowInfoBarIfPossible function in browser/ui/sync/one_click_signin_helper.cc in Google Chrome before 31.0.1650.63 uses an incorrect URL during realm validation, which allows remote attackers to conduct session fixation attacks and hijack web sessions by triggering improper sync after a 302 (aka Found) HTTP status code.
nvd
CVE-2021-30594P4MEDIUMCVSS 6.8fixed in 92.0.4515.131≥ unspecified, < 92.0.4515.1312021-08-26
CVE-2021-30594 [MEDIUM] CWE-416 CVE-2021-30594: Use after free in Page Info UI in Google Chrome prior to 92.0.4515.131 allowed a remote attacker to Use after free in Page Info UI in Google Chrome prior to 92.0.4515.131 allowed a remote attacker to potentially exploit heap corruption via physical access to the device.
nvd
Google Chrome vulnerabilities | cvebase