cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2

Vulnerabilities

Page 232 of 292
CVE-2013-0893P4MEDIUMCVSS 6.8fixed in 25.0.1364.97fixed in 25.0.1364.992013-02-23
CVE-2013-0893 [MEDIUM] CWE-362 CVE-2013-0893: Race condition in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Race condition in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to media.
nvd
CVE-2011-1444P4MEDIUMCVSS 6.8fixed in 11.0.696.572011-05-03
CVE-2011-1444 [MEDIUM] CWE-362 CVE-2011-1444: Race condition in the sandbox launcher implementation in Google Chrome before 11.0.696.57 on Linux a Race condition in the sandbox launcher implementation in Google Chrome before 11.0.696.57 on Linux allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2012-5119P4MEDIUMCVSS 6.8≤ 23.0.1271.62v23.0.1271.0+52 more2012-11-07
CVE-2012-5119 [MEDIUM] CWE-362 CVE-2012-5119: Race condition in Pepper, as used in Google Chrome before 23.0.1271.64, allows remote attackers to c Race condition in Pepper, as used in Google Chrome before 23.0.1271.64, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to buffers.
nvd
CVE-2012-2868P4MEDIUMCVSS 6.8≤ 21.0.1180.88v21.0.1180.0+50 more2012-08-31
CVE-2012-2868 [MEDIUM] CWE-362 CVE-2012-2868: Race condition in Google Chrome before 21.0.1180.89 allows remote attackers to cause a denial of ser Race condition in Google Chrome before 21.0.1180.89 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving improper interaction between worker processes and an XMLHttpRequest (aka XHR) object.
nvd
CVE-2011-2798P4MEDIUMCVSS 6.8fixed in 13.0.782.1072011-08-03
CVE-2011-2798 [MEDIUM] CVE-2011-2798: Google Chrome before 13.0.782.107 does not properly restrict access to internal schemes, which allow Google Chrome before 13.0.782.107 does not properly restrict access to internal schemes, which allows remote attackers to have an unspecified impact via a crafted web site.
nvd
CVE-2013-0918P4MEDIUMCVSS 6.8≤ 26.0.1410.42v26.0.1410.0+40 more2013-03-28
CVE-2013-0918 [MEDIUM] CWE-264 CVE-2013-0918: Google Chrome before 26.0.1410.43 does not prevent navigation to developer tools in response to a dr Google Chrome before 26.0.1410.43 does not prevent navigation to developer tools in response to a drag-and-drop operation, which allows user-assisted remote attackers to have an unspecified impact via a crafted web site.
nvd
CVE-2013-2847P4MEDIUMCVSS 6.8≤ 27.0.1453.91v27.0.1453.0+69 more2013-05-22
CVE-2013-2847 [MEDIUM] CWE-362 CVE-2013-2847: Race condition in the workers implementation in Google Chrome before 27.0.1453.93 allows remote atta Race condition in the workers implementation in Google Chrome before 27.0.1453.93 allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2011-1305P4MEDIUMCVSS 6.8fixed in 11.0.696.572011-05-03
CVE-2011-1305 [MEDIUM] CWE-362 CVE-2011-1305: Race condition in Google Chrome before 11.0.696.57 on Linux and Mac OS X allows remote attackers to Race condition in Google Chrome before 11.0.696.57 on Linux and Mac OS X allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to linked lists and a database.
nvd
CVE-2016-1685P4MEDIUMCVSS 6.5≤ 50.0.2661.1022016-06-05
CVE-2016-1685 [MEDIUM] CWE-119 CVE-2016-1685: core/fxge/ge/fx_ge_text.cpp in PDFium, as used in Google Chrome before 51.0.2704.63, miscalculates c core/fxge/ge/fx_ge_text.cpp in PDFium, as used in Google Chrome before 51.0.2704.63, miscalculates certain index values, which allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PDF document.
nvd
CVE-2016-1654P4MEDIUMCVSS 6.5≤ 49.0.2623.1122016-04-18
CVE-2016-1654 [MEDIUM] CWE-20 CVE-2016-1654: The media subsystem in Google Chrome before 50.0.2661.75 does not initialize an unspecified data str The media subsystem in Google Chrome before 50.0.2661.75 does not initialize an unspecified data structure, which allows remote attackers to cause a denial of service (invalid read operation) via unknown vectors.
nvd
CVE-2013-2877P4MEDIUMCVSS 5.0≤ 28.0.1500.70v28.0.1500.0+61 more2013-07-10
CVE-2013-2877 [MEDIUM] CWE-119 CVE-2013-2877: parser.c in libxml2 before 2.9.0, as used in Google Chrome before 28.0.1500.71 and other products, a parser.c in libxml2 before 2.9.0, as used in Google Chrome before 28.0.1500.71 and other products, allows remote attackers to cause a denial of service (out-of-bounds read) via a document that ends abruptly, related to the lack of certain checks for the XML_PARSER_EOF state.
nvd
CVE-2015-1207P4MEDIUMCVSS 6.5v41.0.2251.02017-06-06
CVE-2015-1207 [MEDIUM] CWE-415 CVE-2015-1207: Double-free vulnerability in libavformat/mov.c in FFMPEG in Google Chrome 41.0.2251.0 allows remote Double-free vulnerability in libavformat/mov.c in FFMPEG in Google Chrome 41.0.2251.0 allows remote attackers to cause a denial of service (memory corruption and crash) via a crafted .m4a file.
nvd
CVE-2009-2973P4MEDIUMCVSS 6.4≤ 2.0.172.37v0.2.149.27+28 more2009-08-27
CVE-2009-2973 [MEDIUM] CVE-2009-2973: Google Chrome before 2.0.172.43 does not prevent SSL connections to a site with an X.509 certificate Google Chrome before 2.0.172.43 does not prevent SSL connections to a site with an X.509 certificate signed with the (1) MD2 or (2) MD4 algorithm, which makes it easier for man-in-the-middle attackers to spoof arbitrary HTTPS servers via a crafted certificate, a related issue to CVE-2009-2409.
nvd
CVE-2017-5006P4MEDIUMCVSS 6.1≤ 55.0.2883.872017-02-17
CVE-2017-5006 [MEDIUM] CWE-79 CVE-2017-5006: Blink in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Androi Blink in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, incorrectly handled object owner relationships, which allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page.
nvd
CVE-2017-5010P4MEDIUMCVSS 6.1≤ 55.0.2883.872017-02-17
CVE-2017-5010 [MEDIUM] CWE-79 CVE-2017-5010: Blink in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Androi Blink in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, resolved promises in an inappropriate context, which allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page.
nvd
CVE-2017-5069P4MEDIUMCVSS 6.1fixed in 58.0.3029.81fixed in 58.0.3029.832017-10-27
CVE-2017-5069 [MEDIUM] CWE-79 CVE-2017-5069: Incorrect MIME type of XSS-Protection reports in Blink in Google Chrome prior to 58.0.3029.81 for Li Incorrect MIME type of XSS-Protection reports in Blink in Google Chrome prior to 58.0.3029.81 for Linux, Windows, and Mac, and 58.0.3029.83 for Android, allowed a remote attacker to circumvent Cross-Origin Resource Sharing checks via a crafted HTML page.
nvd
CVE-2017-15429P4MEDIUMCVSS 6.1fixed in 63.0.3239.1082018-08-28
CVE-2017-15429 [MEDIUM] CWE-79 CVE-2017-15429: Inappropriate implementation in V8 WebAssembly JS bindings in Google Chrome prior to 63.0.3239.108 a Inappropriate implementation in V8 WebAssembly JS bindings in Google Chrome prior to 63.0.3239.108 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page.
nvd
CVE-2016-5204P4MEDIUMCVSS 6.1≤ 54.0.2840.992017-01-19
CVE-2016-5204 [MEDIUM] CWE-79 CVE-2016-5204: Leaking of an SVG shadow tree leading to corruption of the DOM tree in Blink in Google Chrome prior Leaking of an SVG shadow tree leading to corruption of the DOM tree in Blink in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page.
nvd
CVE-2017-5018P4MEDIUMCVSS 6.1≤ 55.0.2883.872017-02-17
CVE-2017-5018 [MEDIUM] CWE-79 CVE-2017-5018: Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, had an Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, had an insufficiently strict content security policy on the Chrome app launcher page, which allowed a remote attacker to inject scripts or HTML into a privileged page via a crafted HTML page.
nvd
CVE-2016-1652P4MEDIUMCVSS 6.1≤ 49.0.2623.1122016-04-18
CVE-2016-1652 [MEDIUM] CWE-79 CVE-2016-1652: Cross-site scripting (XSS) vulnerability in the ModuleSystem::RequireForJsInner function in extensio Cross-site scripting (XSS) vulnerability in the ModuleSystem::RequireForJsInner function in extensions/renderer/module_system.cc in the Extensions subsystem in Google Chrome before 50.0.2661.75 allows remote attackers to inject arbitrary web script or HTML via a crafted web site, aka "Universal XSS (UXSS)."
nvd
Google Chrome vulnerabilities | cvebase