cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2

Vulnerabilities

Page 223 of 292
CVE-2013-2906P4MEDIUMCVSS 6.8≤ 30.0.1599.65v30.0.1599.0+57 more2013-10-02
CVE-2013-2906 [MEDIUM] CWE-362 CVE-2013-2906: Multiple race conditions in the Web Audio implementation in Blink, as used in Google Chrome before 3 Multiple race conditions in the Web Audio implementation in Blink, as used in Google Chrome before 30.0.1599.66, allow remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to threading in core/html/HTMLMediaElement.cpp, core/platform/audio/AudioDSPKernelProcessor.cpp, core/platform/audio/HRTFEleva
nvd
CVE-2011-2346P4MEDIUMCVSS 6.8fixed in 12.0.742.1122011-06-29
CVE-2011-2346 [MEDIUM] CWE-416 CVE-2011-2346: Use-after-free vulnerability in Google Chrome before 12.0.742.112 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 12.0.742.112 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving SVG fonts.
nvd
CVE-2015-1361P4MEDIUMCVSS 6.8≤ 40.0.2214.852015-01-27
CVE-2015-1361 [MEDIUM] CVE-2015-1361: platform/image-decoders/ImageFrame.h in Blink, as used in Google Chrome before 40.0.2214.91, does no platform/image-decoders/ImageFrame.h in Blink, as used in Google Chrome before 40.0.2214.91, does not initialize a variable that is used in calls to the Skia SkBitmap::setAlphaType function, which might allow remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted HTML document, a different vulnerability than CVE-
nvd
CVE-2011-3017P4MEDIUMCVSS 6.8fixed in 17.0.963.562012-02-16
CVE-2011-3017 [MEDIUM] CWE-416 CVE-2011-3017: Use-after-free vulnerability in Google Chrome before 17.0.963.56 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 17.0.963.56 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to database handling.
nvd
CVE-2014-9647P4MEDIUMCVSS 6.8≤ 40.0.2214.852015-01-27
CVE-2014-9647 [MEDIUM] CVE-2014-9647: Use-after-free vulnerability in PDFium, as used in Google Chrome before 40.0.2214.91, allows remote Use-after-free vulnerability in PDFium, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted PDF document, related to fpdfsdk/src/fpdfview.cpp and fpdfsdk/src/fsdk_mgr.cpp, a different vulnerability than CVE-2015-1205.
nvd
CVE-2015-1288P4MEDIUMCVSS 6.8≤ 43.0.2357.1342015-07-23
CVE-2015-1288 [MEDIUM] CVE-2015-1288: The Spellcheck API implementation in Google Chrome before 44.0.2403.89 does not use an HTTPS session The Spellcheck API implementation in Google Chrome before 44.0.2403.89 does not use an HTTPS session for downloading a Hunspell dictionary, which allows man-in-the-middle attackers to deliver incorrect spelling suggestions or possibly have unspecified other impact via a crafted file, a related issue to CVE-2015-1263.
nvd
CVE-2010-1767P4MEDIUMCVSS 6.8≤ 4.1.249.1058v1.0.154.53+232 more2010-09-24
CVE-2010-1767 [MEDIUM] CWE-352 CVE-2010-1767: Cross-site request forgery (CSRF) vulnerability in loader/DocumentThreadableLoader.cpp in WebCore in Cross-site request forgery (CSRF) vulnerability in loader/DocumentThreadableLoader.cpp in WebCore in WebKit before r57041, as used in Google Chrome before 4.1.249.1059, allows remote attackers to hijack the authentication of unspecified victims via a crafted synchronous preflight XMLHttpRequest operation.
nvd
CVE-2010-3412P4CRITICALCVSS 9.3fixed in 6.0.472.592010-09-16
CVE-2010-3412 [CRITICAL] CWE-362 CVE-2010-3412: Race condition in the console implementation in Google Chrome before 6.0.472.59 has unspecified impa Race condition in the console implementation in Google Chrome before 6.0.472.59 has unspecified impact and attack vectors.
nvd
CVE-2014-3187P4MEDIUMCVSS 6.8≤ 37.0.2062.59v37.0.2062.0+52 more2014-10-08
CVE-2014-3187 [MEDIUM] CWE-79 CVE-2014-3187: Google Chrome before 37.0.2062.60 and 38.x before 38.0.2125.59 on iOS does not properly restrict pro Google Chrome before 37.0.2062.60 and 38.x before 38.0.2125.59 on iOS does not properly restrict processing of (1) facetime:// and (2) facetime-audio:// URLs, which allows remote attackers to obtain video and audio data from a device via a crafted web site.
nvd
CVE-2021-21140P4MEDIUMCVSS 6.8fixed in 88.0.4324.96≥ unspecified, < 88.0.4324.962021-02-09
CVE-2021-21140 [MEDIUM] CWE-119 CVE-2021-21140: Uninitialized use in USB in Google Chrome prior to 88.0.4324.96 allowed a local attacker to potentia Uninitialized use in USB in Google Chrome prior to 88.0.4324.96 allowed a local attacker to potentially perform out of bounds memory access via via a USB device.
nvd
CVE-2013-0921P4MEDIUMCVSS 6.8≤ 26.0.1410.42v26.0.1410.0+40 more2013-03-28
CVE-2013-0921 [MEDIUM] CWE-264 CVE-2013-0921: The Isolated Sites feature in Google Chrome before 26.0.1410.43 does not properly enforce the use of The Isolated Sites feature in Google Chrome before 26.0.1410.43 does not properly enforce the use of separate processes, which makes it easier for remote attackers to bypass intended access restrictions via a crafted web site.
nvd
CVE-2015-1291P4MEDIUMCVSS 6.4≤ 44.0.24032015-09-03
CVE-2015-1291 [MEDIUM] CWE-264 CVE-2015-1291: The ContainerNode::parserRemoveChild function in core/dom/ContainerNode.cpp in Blink, as used in Goo The ContainerNode::parserRemoveChild function in core/dom/ContainerNode.cpp in Blink, as used in Google Chrome before 45.0.2454.85, does not check whether a node is expected, which allows remote attackers to bypass the Same Origin Policy or cause a denial of service (DOM tree corruption) via a web site with crafted JavaScript code and IFRAME elements.
nvd
CVE-2016-1686P4MEDIUMCVSS 6.5≤ 50.0.2661.1022016-06-05
CVE-2016-1686 [MEDIUM] CWE-119 CVE-2016-1686: The CPDF_DIBSource::CreateDecoder function in core/fpdfapi/fpdf_render/fpdf_render_loadimage.cpp in The CPDF_DIBSource::CreateDecoder function in core/fpdfapi/fpdf_render/fpdf_render_loadimage.cpp in PDFium, as used in Google Chrome before 51.0.2704.63, mishandles decoder-initialization failure, which allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PDF document.
nvd
CVE-2022-3048P4MEDIUMCVSS 6.8fixed in 105.0.5195.52≥ unspecified, < 105.0.5195.522022-09-26
CVE-2022-3048 [MEDIUM] CWE-863 CVE-2022-3048: Inappropriate implementation in Chrome OS lockscreen in Google Chrome on Chrome OS prior to 105.0.51 Inappropriate implementation in Chrome OS lockscreen in Google Chrome on Chrome OS prior to 105.0.5195.52 allowed a local attacker to bypass lockscreen navigation restrictions via physical access to the device.
nvd
CVE-2016-1637P4MEDIUMCVSS 6.5≤ 48.0.2564.1162016-03-06
CVE-2016-1637 [MEDIUM] CWE-200 CVE-2016-1637: The SkATan2_255 function in effects/gradients/SkSweepGradient.cpp in Skia, as used in Google Chrome The SkATan2_255 function in effects/gradients/SkSweepGradient.cpp in Skia, as used in Google Chrome before 49.0.2623.75, mishandles arctangent calculations, which allows remote attackers to obtain sensitive information via a crafted web site.
nvd
CVE-2017-5007P4MEDIUMCVSS 6.1≤ 55.0.2883.872017-02-17
CVE-2017-5007 [MEDIUM] CWE-79 CVE-2017-5007: Blink in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Androi Blink in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, incorrectly handled the sequence of events when closing a page, which allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page.
nvd
CVE-2016-5181P4MEDIUMCVSS 6.1≤ 53.0.2785.1432016-12-18
CVE-2016-5181 [MEDIUM] CWE-79 CVE-2016-5181: Blink in Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android p Blink in Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android permitted execution of v8 microtasks while the DOM was in an inconsistent state, which allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via crafted HTML pages.
nvd
CVE-2011-2336P4MEDIUMCVSS 6.5vbefore Blink M122019-11-07
CVE-2011-2336 [MEDIUM] CWE-755 CVE-2011-2336: An issue exists in WebKit in Google Chrome before Blink M12. when clearing lists in AnimationControl An issue exists in WebKit in Google Chrome before Blink M12. when clearing lists in AnimationControllerPrivate that signal when a hardware animation starts.
nvd
CVE-2011-1803P4MEDIUMCVSS 6.5vbefore Blink M11 and M122019-11-12
CVE-2011-1803 [MEDIUM] CWE-415 CVE-2011-1803: An issue exists in third_party/WebKit/Source/WebCore/svg/animation/SVGSMILElement.h in WebKit in Goo An issue exists in third_party/WebKit/Source/WebCore/svg/animation/SVGSMILElement.h in WebKit in Google Chrome before Blink M11 and M12 when trying to access a removed smil element.
nvd
CVE-2017-5085P4MEDIUMCVSS 6.1v58.0.30292017-10-27
CVE-2017-5085 [MEDIUM] CWE-79 CVE-2017-5085: Inappropriate implementation in Bookmarks in Google Chrome prior to 59 for iOS allowed a remote atta Inappropriate implementation in Bookmarks in Google Chrome prior to 59 for iOS allowed a remote attacker who convinced the user to perform certain operations to run JavaScript on chrome:// pages via a crafted bookmark.
nvd
Google Chrome vulnerabilities | cvebase