Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2
Vulnerabilities
Page 222 of 292
CVE-2011-3060P4MEDIUMCVSS 6.8fixed in 18.0.1025.1422012-03-30
CVE-2011-3060 [MEDIUM] CWE-125 CVE-2011-3060: Google Chrome before 18.0.1025.142 does not properly handle text fragments, which allows remote atta
Google Chrome before 18.0.1025.142 does not properly handle text fragments, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2011-3065P4MEDIUMCVSS 6.8fixed in 18.0.1025.1422012-03-30
CVE-2011-3065 [MEDIUM] CWE-190 CVE-2011-3065: Skia, as used in Google Chrome before 18.0.1025.142, allows remote attackers to cause a denial of se
Skia, as used in Google Chrome before 18.0.1025.142, allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2011-3059P4MEDIUMCVSS 6.8fixed in 18.0.1025.1422012-03-30
CVE-2011-3059 [MEDIUM] CWE-125 CVE-2011-3059: Google Chrome before 18.0.1025.142 does not properly handle SVG text elements, which allows remote a
Google Chrome before 18.0.1025.142 does not properly handle SVG text elements, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2015-1245P4MEDIUMCVSS 6.8≤ 41.0.2272.742015-04-19
CVE-2015-1245 [MEDIUM] CVE-2015-1245: Use-after-free vulnerability in the OpenPDFInReaderView::Update function in browser/ui/views/locatio
Use-after-free vulnerability in the OpenPDFInReaderView::Update function in browser/ui/views/location_bar/open_pdf_in_reader_view.cc in Google Chrome before 41.0.2272.76 might allow user-assisted remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact by triggering interaction with a PDFium "Open PDF in
nvd
CVE-2011-2854P4MEDIUMCVSS 6.8fixed in 14.0.835.1632011-09-19
CVE-2011-2854 [MEDIUM] CWE-416 CVE-2011-2854: Use-after-free vulnerability in Google Chrome before 14.0.835.163 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 14.0.835.163 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to "ruby / table style handing."
nvd
CVE-2011-1440P4MEDIUMCVSS 6.8fixed in 11.0.696.572011-05-03
CVE-2011-1440 [MEDIUM] CWE-416 CVE-2011-1440: Use-after-free vulnerability in Google Chrome before 11.0.696.57 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 11.0.696.57 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the ruby element and Cascading Style Sheets (CSS) token sequences.
nvd
CVE-2012-2807P4MEDIUMCVSS 6.8≤ 20.0.1132.42v20.0.1132.0+41 more2012-06-27
CVE-2012-2807 [MEDIUM] CWE-189 CVE-2012-2807: Multiple integer overflows in libxml2, as used in Google Chrome before 20.0.1132.43 and other produc
Multiple integer overflows in libxml2, as used in Google Chrome before 20.0.1132.43 and other products, on 64-bit Linux platforms allow remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2013-6635P4MEDIUMCVSS 6.8≤ 31.0.1650.62v31.0.1650.0+56 more2013-12-07
CVE-2013-6635 [MEDIUM] CWE-399 CVE-2013-6635: Use-after-free vulnerability in the editing implementation in Blink, as used in Google Chrome before
Use-after-free vulnerability in the editing implementation in Blink, as used in Google Chrome before 31.0.1650.63, allows remote attackers to cause a denial of service or possibly have unspecified other impact via JavaScript code that triggers removal of a node during processing of the DOM tree, related to CompositeEditCommand.cpp and ReplaceSelection
nvd
CVE-2015-1282P4MEDIUMCVSS 6.8≤ 43.0.2357.1342015-07-23
CVE-2015-1282 [MEDIUM] CVE-2015-1282: Multiple use-after-free vulnerabilities in fpdfsdk/src/javascript/Document.cpp in PDFium, as used in
Multiple use-after-free vulnerabilities in fpdfsdk/src/javascript/Document.cpp in PDFium, as used in Google Chrome before 44.0.2403.89, allow remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted PDF document, related to the (1) Document::delay and (2) Document::DoFieldDelay functions.
nvd
CVE-2011-2792P4MEDIUMCVSS 6.8fixed in 13.0.782.1072011-08-03
CVE-2011-2792 [MEDIUM] CWE-416 CVE-2011-2792: Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to float removal.
nvd
CVE-2011-2857P4MEDIUMCVSS 6.8fixed in 14.0.835.1632011-09-19
CVE-2011-2857 [MEDIUM] CWE-416 CVE-2011-2857: Use-after-free vulnerability in Google Chrome before 14.0.835.163 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 14.0.835.163 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the focus controller.
nvd
CVE-2011-3969P4MEDIUMCVSS 6.8fixed in 17.0.963.462012-02-09
CVE-2011-3969 [MEDIUM] CWE-416 CVE-2011-3969: Use-after-free vulnerability in Google Chrome before 17.0.963.46 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 17.0.963.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to layout of SVG documents.
nvd
CVE-2015-1255P4MEDIUMCVSS 6.8≤ 42.0.2311.1522015-05-20
CVE-2015-1255 [MEDIUM] CVE-2015-1255: Use-after-free vulnerability in content/renderer/media/webaudio_capturer_source.cc in the WebAudio i
Use-after-free vulnerability in content/renderer/media/webaudio_capturer_source.cc in the WebAudio implementation in Google Chrome before 43.0.2357.65 allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact by leveraging improper handling of a stop action for an audio track.
nvd
CVE-2015-6758P4MEDIUMCVSS 6.8≤ 45.0.2454.1012015-10-15
CVE-2015-6758 [MEDIUM] CWE-17 CVE-2015-6758: The CPDF_Document::GetPage function in fpdfapi/fpdf_parser/fpdf_parser_document.cpp in PDFium, as us
The CPDF_Document::GetPage function in fpdfapi/fpdf_parser/fpdf_parser_document.cpp in PDFium, as used in Google Chrome before 46.0.2490.71, does not properly perform a cast of a dictionary object, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted PDF document.
nvd
CVE-2013-2925P4MEDIUMCVSS 6.8≤ 30.0.1599.100v30.0.1599.0+72 more2013-10-16
CVE-2013-2925 [MEDIUM] CWE-399 CVE-2013-2925: Use-after-free vulnerability in core/xml/XMLHttpRequest.cpp in Blink, as used in Google Chrome befor
Use-after-free vulnerability in core/xml/XMLHttpRequest.cpp in Blink, as used in Google Chrome before 30.0.1599.101, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger multiple conflicting uses of the same XMLHttpRequest object.
nvd
CVE-2011-1816P4MEDIUMCVSS 6.8fixed in 12.0.742.912011-06-09
CVE-2011-1816 [MEDIUM] CWE-416 CVE-2011-1816: Use-after-free vulnerability in the developer tools in Google Chrome before 12.0.742.91 allows remot
Use-after-free vulnerability in the developer tools in Google Chrome before 12.0.742.91 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2016-1688P4MEDIUMCVSS 6.5≤ 50.0.2661.1022016-06-05
CVE-2016-1688 [MEDIUM] CWE-119 CVE-2016-1688: The regexp (aka regular expression) implementation in Google V8 before 5.0.71.40, as used in Google
The regexp (aka regular expression) implementation in Google V8 before 5.0.71.40, as used in Google Chrome before 51.0.2704.63, mishandles external string sizes, which allows remote attackers to cause a denial of service (out-of-bounds read) via crafted JavaScript code.
nvd
CVE-2013-0900P4MEDIUMCVSS 6.8fixed in 25.0.1364.97fixed in 25.0.1364.992013-02-23
CVE-2013-0900 [MEDIUM] CWE-362 CVE-2013-0900: Race condition in the International Components for Unicode (ICU) functionality in Google Chrome befo
Race condition in the International Components for Unicode (ICU) functionality in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2013-2921P4MEDIUMCVSS 6.8≤ 30.0.1599.65v30.0.1599.0+57 more2013-10-02
CVE-2013-2921 [MEDIUM] CWE-399 CVE-2013-2921: Double free vulnerability in the ResourceFetcher::didLoadResource function in core/fetch/ResourceFet
Double free vulnerability in the ResourceFetcher::didLoadResource function in core/fetch/ResourceFetcher.cpp in the resource loader in Blink, as used in Google Chrome before 30.0.1599.66, allows remote attackers to cause a denial of service or possibly have unspecified other impact by triggering certain callback processing during the reporting of a re
nvd
CVE-2012-2890P4MEDIUMCVSS 6.8≤ 22.0.1229.78v22.0.1229.0+51 more2012-09-26
CVE-2012-2890 [MEDIUM] CWE-399 CVE-2012-2890: Use-after-free vulnerability in the PDF functionality in Google Chrome before 22.0.1229.79 allows re
Use-after-free vulnerability in the PDF functionality in Google Chrome before 22.0.1229.79 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted document.
nvd