cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2

Vulnerabilities

Page 228 of 292
CVE-2011-1818P4MEDIUMCVSS 6.8fixed in 12.0.742.912011-06-09
CVE-2011-1818 [MEDIUM] CWE-416 CVE-2011-1818: Use-after-free vulnerability in the image loader in Google Chrome before 12.0.742.91 allows remote a Use-after-free vulnerability in the image loader in Google Chrome before 12.0.742.91 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2015-6756P4MEDIUMCVSS 6.8≤ 45.0.2454.1012015-10-15
CVE-2015-6756 [MEDIUM] CVE-2015-6756: Use-after-free vulnerability in the CPDFSDK_PageView implementation in fpdfsdk/src/fsdk_mgr.cpp in P Use-after-free vulnerability in the CPDFSDK_PageView implementation in fpdfsdk/src/fsdk_mgr.cpp in PDFium, as used in Google Chrome before 46.0.2490.71, allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact by leveraging mishandling of a focused annotation in a PDF document.
nvd
CVE-2013-6645P4MEDIUMCVSS 6.8fixed in 32.0.1700.76fixed in 32.0.1700.772014-01-16
CVE-2013-6645 [MEDIUM] CWE-416 CVE-2013-6645: Use-after-free vulnerability in the OnWindowRemovingFromRootWindow function in content/browser/web_c Use-after-free vulnerability in the OnWindowRemovingFromRootWindow function in content/browser/web_contents/web_contents_view_aura.cc in Google Chrome before 32.0.1700.76 on Windows and before 32.0.1700.77 on Mac OS X and Linux allows user-assisted remote attackers to cause a denial of service or possibly have unspecified other impact via vectors invo
nvd
CVE-2011-3098P4HIGHCVSS 7.2≤ 19.0.1084.452012-05-16
CVE-2011-3098 [HIGH] CWE-264 CVE-2011-3098: Google Chrome before 19.0.1084.46 on Windows uses an incorrect search path for the Windows Media Pla Google Chrome before 19.0.1084.46 on Windows uses an incorrect search path for the Windows Media Player plug-in, which might allow local users to gain privileges via a Trojan horse plug-in in an unspecified directory.
nvd
CVE-2013-2922P4MEDIUMCVSS 6.8≤ 30.0.1599.65v30.0.1599.0+57 more2013-10-02
CVE-2013-2922 [MEDIUM] CWE-399 CVE-2013-2922: Use-after-free vulnerability in core/html/HTMLTemplateElement.cpp in Blink, as used in Google Chrome Use-after-free vulnerability in core/html/HTMLTemplateElement.cpp in Blink, as used in Google Chrome before 30.0.1599.66, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that operates on a TEMPLATE element.
nvd
CVE-2013-2914P4MEDIUMCVSS 6.8≤ 30.0.1599.65v30.0.1599.0+57 more2013-10-02
CVE-2013-2914 [MEDIUM] CWE-399 CVE-2013-2914: Use-after-free vulnerability in the color-chooser dialog in Google Chrome before 30.0.1599.66 on Win Use-after-free vulnerability in the color-chooser dialog in Google Chrome before 30.0.1599.66 on Windows allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to color_chooser_dialog.cc and color_chooser_win.cc in browser/ui/views/.
nvd
CVE-2011-2793P4MEDIUMCVSS 6.8fixed in 13.0.782.1072011-08-03
CVE-2011-2793 [MEDIUM] CWE-416 CVE-2011-2793: Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to media selectors.
nvd
CVE-2011-2349P4MEDIUMCVSS 6.8fixed in 12.0.742.1122011-06-29
CVE-2011-2349 [MEDIUM] CWE-416 CVE-2011-2349: Use-after-free vulnerability in Google Chrome before 12.0.742.112 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 12.0.742.112 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to text selection.
nvd
CVE-2011-2796P4MEDIUMCVSS 6.8fixed in 13.0.782.1072011-08-03
CVE-2011-2796 [MEDIUM] CWE-416 CVE-2011-2796: Use-after-free vulnerability in Skia, as used in Google Chrome before 13.0.782.107, allows remote at Use-after-free vulnerability in Skia, as used in Google Chrome before 13.0.782.107, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2012-2857P4MEDIUMCVSS 6.8≤ 21.0.1180.59v21.0.1180.0+25 more2012-08-06
CVE-2012-2857 [MEDIUM] CWE-399 CVE-2012-2857: Use-after-free vulnerability in the Cascading Style Sheets (CSS) DOM implementation in Google Chrome Use-after-free vulnerability in the Cascading Style Sheets (CSS) DOM implementation in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted document.
nvd
CVE-2013-2853P4MEDIUMCVSS 6.8≤ 28.0.1500.70v28.0.1500.0+61 more2013-07-10
CVE-2013-2853 [MEDIUM] CVE-2013-2853: The HTTPS implementation in Google Chrome before 28.0.1500.71 does not ensure that headers are termi The HTTPS implementation in Google Chrome before 28.0.1500.71 does not ensure that headers are terminated by \r\n\r\n (carriage return, newline, carriage return, newline), which allows man-in-the-middle attackers to have an unspecified impact via vectors that trigger header truncation.
nvd
CVE-2012-2862P4MEDIUMCVSS 6.8≤ 21.0.1180.74v21.0.1180.0+36 more2012-08-09
CVE-2012-2862 [MEDIUM] CWE-399 CVE-2012-2862: Use-after-free vulnerability in the PDF functionality in Google Chrome before 21.0.1180.75 allows re Use-after-free vulnerability in the PDF functionality in Google Chrome before 21.0.1180.75 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted document.
nvd
CVE-2010-2646P4CRITICALCVSS 9.3fixed in 5.0.375.992010-07-06
CVE-2010-2646 [CRITICAL] CVE-2010-2646: Google Chrome before 5.0.375.99 does not properly isolate sandboxed IFRAME elements, which has unspe Google Chrome before 5.0.375.99 does not properly isolate sandboxed IFRAME elements, which has unspecified impact and remote attack vectors.
nvd
CVE-2015-6761P4MEDIUMCVSS 6.8≤ 45.0.2454.1012015-10-15
CVE-2015-6761 [MEDIUM] CWE-362 CVE-2015-6761: The update_dimensions function in libavcodec/vp8.c in FFmpeg through 2.8.1, as used in Google Chrome The update_dimensions function in libavcodec/vp8.c in FFmpeg through 2.8.1, as used in Google Chrome before 46.0.2490.71 and other products, relies on a coefficient-partition count during multi-threaded operation, which allows remote attackers to cause a denial of service (race condition and memory corruption) or possibly have unspecified other impact
nvd
CVE-2011-2783P4MEDIUMCVSS 6.8fixed in 13.0.782.1072011-08-03
CVE-2011-2783 [MEDIUM] CWE-20 CVE-2011-2783: Google Chrome before 13.0.782.107 does not ensure that developer-mode NPAPI extension installations Google Chrome before 13.0.782.107 does not ensure that developer-mode NPAPI extension installations are confirmed by a browser dialog, which makes it easier for remote attackers to modify the product's functionality via a Trojan horse extension.
nvd
CVE-2011-2358P4MEDIUMCVSS 6.8fixed in 13.0.782.1072011-08-03
CVE-2011-2358 [MEDIUM] CWE-20 CVE-2011-2358: Google Chrome before 13.0.782.107 does not ensure that extension installations are confirmed by a br Google Chrome before 13.0.782.107 does not ensure that extension installations are confirmed by a browser dialog, which makes it easier for remote attackers to modify the product's functionality via a Trojan horse extension.
nvd
CVE-2009-2071P4MEDIUMCVSS 6.8≤ 1.0.154.52v0.2.149.29+14 more2009-06-15
CVE-2009-2071 [MEDIUM] CWE-287 CVE-2009-2071: Google Chrome before 1.0.154.53 displays a cached certificate for a (1) 4xx or (2) 5xx CONNECT respo Google Chrome before 1.0.154.53 displays a cached certificate for a (1) 4xx or (2) 5xx CONNECT response page returned by a proxy server, which allows man-in-the-middle attackers to spoof an arbitrary https site by letting a browser obtain a valid certificate from this site during one request, and then sending the browser a crafted 502 response page up
nvd
CVE-2012-5156P4MEDIUMCVSS 6.8≤ 24.0.1312.51v24.0.1272.0+119 more2013-01-15
CVE-2012-5156 [MEDIUM] CWE-399 CVE-2012-5156: Use-after-free vulnerability in Google Chrome before 24.0.1312.52 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 24.0.1312.52 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving PDF fields.
nvd
CVE-2015-6582P4MEDIUMCVSS 6.8≤ 44.0.24032015-09-03
CVE-2015-6582 [MEDIUM] CWE-254 CVE-2015-6582: The decompose function in platform/transforms/TransformationMatrix.cpp in Blink, as used in Google C The decompose function in platform/transforms/TransformationMatrix.cpp in Blink, as used in Google Chrome before 45.0.2454.85, does not verify that a matrix inversion succeeded, which allows remote attackers to cause a denial of service (uninitialized memory access and application crash) or possibly have unspecified other impact via a crafted web site
nvd
CVE-2012-2858P4MEDIUMCVSS 6.8≤ 21.0.1180.56v21.0.1180.0+25 more2012-08-06
CVE-2012-2858 [MEDIUM] CWE-119 CVE-2012-2858: Buffer overflow in the WebP decoder in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and Buffer overflow in the WebP decoder in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted WebP image.
nvd
Google Chrome vulnerabilities | cvebase