cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2

Vulnerabilities

Page 233 of 292
CVE-2016-5205P4MEDIUMCVSS 6.1≤ 54.0.2840.992017-01-19
CVE-2016-5205 [MEDIUM] CWE-79 CVE-2016-5205: Blink in Google Chrome prior to 55.0.2883.75 for Linux, Windows and Mac, incorrectly handles deferre Blink in Google Chrome prior to 55.0.2883.75 for Linux, Windows and Mac, incorrectly handles deferred page loads, which allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page.
nvd
CVE-2018-6081P4MEDIUMCVSS 6.1fixed in 65.0.3325.146≥ unspecified, < 65.0.3325.1462018-11-14
CVE-2018-6081 [MEDIUM] CWE-79 CVE-2018-6081: XSS vulnerabilities in Interstitials in Google Chrome prior to 65.0.3325.146 allowed an attacker who XSS vulnerabilities in Interstitials in Google Chrome prior to 65.0.3325.146 allowed an attacker who convinced a user to install a malicious extension or open Developer Console to inject arbitrary scripts or HTML via a crafted HTML page.
nvd
CVE-2011-1446P4MEDIUMCVSS 5.8fixed in 11.0.696.572011-05-03
CVE-2011-1446 [MEDIUM] CVE-2011-1446: Google Chrome before 11.0.696.57 allows remote attackers to spoof the URL bar via vectors involving Google Chrome before 11.0.696.57 allows remote attackers to spoof the URL bar via vectors involving (1) a navigation error or (2) an interrupted load.
nvd
CVE-2009-2060P4MEDIUMCVSS 5.8≤ 1.0.154.52v0.2.149.29+14 more2009-06-15
CVE-2009-2060 [MEDIUM] CWE-287 CVE-2009-2060: src/net/http/http_transaction_winhttp.cc in Google Chrome before 1.0.154.53 uses the HTTP Host heade src/net/http/http_transaction_winhttp.cc in Google Chrome before 1.0.154.53 uses the HTTP Host header to determine the context of a document provided in a (1) 4xx or (2) 5xx CONNECT response from a proxy server, which allows man-in-the-middle attackers to execute arbitrary web script by modifying this CONNECT response, aka an "SSL tampering" attack.
nvd
CVE-2021-21218P4MEDIUMCVSS 5.5fixed in 90.0.4430.72≥ unspecified, < 90.0.4430.722021-04-26
CVE-2021-21218 [MEDIUM] CWE-908 CVE-2021-21218: Uninitialized data in PDFium in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to obt Uninitialized data in PDFium in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted PDF file.
nvd
CVE-2021-21219P4MEDIUMCVSS 5.5fixed in 90.0.4430.72≥ unspecified, < 90.0.4430.722021-04-26
CVE-2021-21219 [MEDIUM] CWE-252 CVE-2021-21219: Uninitialized data in PDFium in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to obt Uninitialized data in PDFium in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted PDF file.
nvd
CVE-2018-6110P4MEDIUMCVSS 5.4fixed in 66.0.3359.117≥ unspecified, < 66.0.3359.1172019-01-09
CVE-2018-6110 [MEDIUM] CWE-20 CVE-2018-6110: Parsing documents as HTML in Downloads in Google Chrome prior to 66.0.3359.117 allowed a remote atta Parsing documents as HTML in Downloads in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to cause Chrome to execute scripts via a local non-HTML page.
nvd
CVE-2013-6630P4MEDIUMCVSS 5.0≤ 31.0.1650.47v31.0.1650.0+42 more2013-11-19
CVE-2013-6630 [MEDIUM] CWE-189 CVE-2013-6630: The get_dht function in jdmarker.c in libjpeg-turbo through 1.3.0, as used in Google Chrome before 3 The get_dht function in jdmarker.c in libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48 and other products, does not set all elements of a certain Huffman value array during the reading of segments that follow Define Huffman Table (DHT) JPEG markers, which allows remote attackers to obtain sensitive information from uninitializ
nvd
CVE-2019-5823P4MEDIUMCVSS 5.4fixed in 74.0.3729.108≥ unspecified, < 74.0.3729.1082019-06-27
CVE-2019-5823 [MEDIUM] CWE-601 CVE-2019-5823: Insufficient policy enforcement in service workers in Google Chrome prior to 74.0.3729.108 allowed a Insufficient policy enforcement in service workers in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
nvd
CVE-2021-37958P4MEDIUMCVSS 5.4fixed in 94.0.4606.54≥ unspecified, < 94.0.4606.542021-10-08
CVE-2021-37958 [MEDIUM] CVE-2021-37958: Inappropriate implementation in Navigation in Google Chrome on Windows prior to 94.0.4606.54 allowed Inappropriate implementation in Navigation in Google Chrome on Windows prior to 94.0.4606.54 allowed a remote attacker to inject scripts or HTML into a privileged page via a crafted HTML page.
nvd
CVE-2017-5061P4MEDIUMCVSS 5.3fixed in 58.0.3029.812017-10-27
CVE-2017-5061 [MEDIUM] CWE-362 CVE-2017-5061: A race condition in navigation in Google Chrome prior to 58.0.3029.81 for Linux, Windows, and Mac al A race condition in navigation in Google Chrome prior to 58.0.3029.81 for Linux, Windows, and Mac allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd
CVE-2014-7944P4MEDIUMCVSS 5.0≤ 40.0.2214.852015-01-22
CVE-2014-7944 [MEDIUM] CWE-119 CVE-2014-7944: The sycc422_to_rgb function in fxcodec/codec/fx_codec_jpx_opj.cpp in PDFium, as used in Google Chrom The sycc422_to_rgb function in fxcodec/codec/fx_codec_jpx_opj.cpp in PDFium, as used in Google Chrome before 40.0.2214.91, does not properly handle odd values of image width, which allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PDF document.
nvd
CVE-2026-14063P4MEDIUMCVSS 5.7fixed in 150.0.7871.46≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14063 [MEDIUM] CWE-125 CVE-2026-14063: Out of bounds read in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a local attacker to Out of bounds read in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a local attacker to obtain potentially sensitive information from process memory via malicious network traffic. (Chromium security severity: Low)
nvd
CVE-2018-16079P4MEDIUMCVSS 5.3fixed in 69.0.3497.81≥ unspecified, < 69.0.3497.812019-01-09
CVE-2018-16079 [MEDIUM] CWE-362 CVE-2018-16079: A race condition between permission prompts and navigations in Prompts in Google Chrome prior to 69. A race condition between permission prompts and navigations in Prompts in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd
CVE-2015-1224P4MEDIUMCVSS 5.0≤ 40.0.2214.1152015-03-09
CVE-2015-1224 [MEDIUM] CWE-17 CVE-2015-1224: The VpxVideoDecoder::VpxDecode function in media/filters/vpx_video_decoder.cc in the vpxdecoder impl The VpxVideoDecoder::VpxDecode function in media/filters/vpx_video_decoder.cc in the vpxdecoder implementation in Google Chrome before 41.0.2272.76 does not ensure that alpha-plane dimensions are identical to image dimensions, which allows remote attackers to cause a denial of service (out-of-bounds read) via crafted VPx video data.
nvd
CVE-2016-5133P4MEDIUMCVSS 5.3≤ 51.0.2704.1062016-07-23
CVE-2016-5133 [MEDIUM] CWE-287 CVE-2016-5133: Google Chrome before 52.0.2743.82 mishandles origin information during proxy authentication, which a Google Chrome before 52.0.2743.82 mishandles origin information during proxy authentication, which allows man-in-the-middle attackers to spoof a proxy-authentication login prompt or trigger incorrect credential storage by modifying the client-server data stream.
nvd
CVE-2015-1235P4MEDIUMCVSS 5.0≤ 42.0.2311.602015-04-19
CVE-2015-1235 [MEDIUM] CWE-264 CVE-2015-1235: The ContainerNode::parserRemoveChild function in core/dom/ContainerNode.cpp in the HTML parser in Bl The ContainerNode::parserRemoveChild function in core/dom/ContainerNode.cpp in the HTML parser in Blink, as used in Google Chrome before 42.0.2311.90, allows remote attackers to bypass the Same Origin Policy via a crafted HTML document with an IFRAME element.
nvd
CVE-2019-13684P4MEDIUMCVSS 5.3fixed in 72.0.3626.81≥ unspecified, < 72.0.3626.812019-11-25
CVE-2019-13684 [MEDIUM] CWE-203 CVE-2019-13684: Inappropriate implementation in JavaScript in Google Chrome prior to 72.0.3626.81 allowed a remote a Inappropriate implementation in JavaScript in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2010-2109P4HIGHCVSS 7.5fixed in 5.0.375.552010-05-28
CVE-2010-2109 [HIGH] CVE-2010-2109: Unspecified vulnerability in Google Chrome before 5.0.375.55 allows user-assisted remote attackers t Unspecified vulnerability in Google Chrome before 5.0.375.55 allows user-assisted remote attackers to cause a denial of service (memory error) or possibly have unspecified other impact via vectors related to the "drag + drop" functionality.
nvd
CVE-2026-13914P4MEDIUMCVSS 5.5fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13914 [MEDIUM] CWE-284 CVE-2026-13914: Inappropriate implementation in Passwords in Google Chrome on Mac prior to 150.0.7871.47 allowed a l Inappropriate implementation in Passwords in Google Chrome on Mac prior to 150.0.7871.47 allowed a local attacker to obtain potentially sensitive information from process memory via a malicious file. (Chromium security severity: Medium)
nvd
Google Chrome vulnerabilities | cvebase