cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2

Vulnerabilities

Page 236 of 292
CVE-2017-1000460P4MEDIUMCVSS 6.5≤ 56.0.29242018-01-03
CVE-2017-1000460 [MEDIUM] CWE-476 CVE-2017-1000460: In line libavcodec/h264dec.c:500 in libav(v13_dev0), ffmpeg(n3.4), chromium(56 prior Feb 13, 2017), In line libavcodec/h264dec.c:500 in libav(v13_dev0), ffmpeg(n3.4), chromium(56 prior Feb 13, 2017), the return value of init_get_bits is ignored and get_ue_golomb(&gb) is called on an uninitialized get_bits context, which causes a NULL deref exception.
nvd
CVE-2026-7964P4MEDIUMCVSS 4.2fixed in 148.0.7778.96≥ 148.0.7778.96, < 148.0.7778.962026-05-06
CVE-2026-7964 [MEDIUM] CWE-20 CVE-2026-7964: Insufficient validation of untrusted input in FileSystem in Google Chrome prior to 148.0.7778.96 all Insufficient validation of untrusted input in FileSystem in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: Medium)
cvelistv5nvd
CVE-2026-7943P4MEDIUMCVSS 4.2fixed in 148.0.7778.96≥ 148.0.7778.96, < 148.0.7778.962026-05-06
CVE-2026-7943 [MEDIUM] CWE-20 CVE-2026-7943: Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 148.0.7778.96 allowed Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-7989P4MEDIUMCVSS 4.2fixed in 148.0.7778.96≥ 148.0.7778.96, < 148.0.7778.962026-05-06
CVE-2026-7989 [MEDIUM] CWE-20 CVE-2026-7989: Insufficient data validation in DataTransfer in Google Chrome prior to 148.0.7778.96 allowed a remot Insufficient data validation in DataTransfer in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2017-5008P4MEDIUMCVSS 6.1≤ 55.0.2883.872017-02-17
CVE-2017-5008 [MEDIUM] CWE-79 CVE-2017-5008: Blink in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Androi Blink in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, allowed attacker controlled JavaScript to be run during the invocation of a private script method, which allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page.
nvd
CVE-2016-5208P4MEDIUMCVSS 6.1≤ 54.0.2840.992017-01-19
CVE-2016-5208 [MEDIUM] CWE-79 CVE-2016-5208: Blink in Google Chrome prior to 55.0.2883.75 for Linux and Windows, and 55.0.2883.84 for Android all Blink in Google Chrome prior to 55.0.2883.75 for Linux and Windows, and 55.0.2883.84 for Android allowed possible corruption of the DOM tree during synchronous event handling, which allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page.
nvd
CVE-2017-15427P4MEDIUMCVSS 6.1fixed in 63.0.3239.842018-08-28
CVE-2017-15427 [MEDIUM] CWE-79 CVE-2017-15427: Insufficient policy enforcement in Omnibox in Google Chrome prior to 63.0.3239.84 allowed a socially Insufficient policy enforcement in Omnibox in Google Chrome prior to 63.0.3239.84 allowed a socially engineered user to XSS themselves by dragging and dropping a javascript: URL into the URL bar.
nvd
CVE-2008-7294P4MEDIUMCVSS 5.8≤ 3.0.195.38v0.1.38.1+57 more2011-08-09
CVE-2008-7294 [MEDIUM] CWE-264 CVE-2008-7294: Google Chrome before 4.0.211.0 cannot properly restrict modifications to cookies established in HTTP Google Chrome before 4.0.211.0 cannot properly restrict modifications to cookies established in HTTPS sessions, which allows man-in-the-middle attackers to overwrite or delete arbitrary cookies via a Set-Cookie header in an HTTP response, related to lack of the HTTP Strict Transport Security (HSTS) includeSubDomains feature, aka a "cookie forcing" iss
nvd
CVE-2011-1452P4MEDIUMCVSS 5.8fixed in 11.0.696.572011-05-03
CVE-2011-1452 [MEDIUM] CWE-20 CVE-2011-1452: Google Chrome before 11.0.696.57 allows user-assisted remote attackers to spoof the URL bar via vect Google Chrome before 11.0.696.57 allows user-assisted remote attackers to spoof the URL bar via vectors involving a redirect and a manual reload.
nvd
CVE-2011-3061P4MEDIUMCVSS 5.8fixed in 18.0.1025.1422012-03-30
CVE-2011-3061 [MEDIUM] CWE-295 CVE-2011-3061: Google Chrome before 18.0.1025.142 does not properly check X.509 certificates before use of a SPDY p Google Chrome before 18.0.1025.142 does not properly check X.509 certificates before use of a SPDY proxy, which might allow man-in-the-middle attackers to spoof servers or obtain sensitive information via a crafted certificate.
nvd
CVE-2018-6171P4MEDIUMCVSS 5.7fixed in 68.0.3440.75≥ unspecified, < 68.0.3440.752019-06-27
CVE-2018-6171 [MEDIUM] CWE-416 CVE-2018-6171: Use after free in Bluetooth in Google Chrome prior to 68.0.3440.75 allowed an attacker who convinced Use after free in Bluetooth in Google Chrome prior to 68.0.3440.75 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from process memory via a crafted Chrome Extension.
nvd
CVE-2011-1190P4MEDIUMCVSS 5.0fixed in 10.0.648.1272011-03-11
CVE-2011-1190 [MEDIUM] CWE-200 CVE-2011-1190: The Web Workers implementation in Google Chrome before 10.0.648.127 allows remote attackers to bypas The Web Workers implementation in Google Chrome before 10.0.648.127 allows remote attackers to bypass the Same Origin Policy via unspecified vectors, related to an "error message leak."
nvd
CVE-2021-37996P4MEDIUMCVSS 5.5fixed in 95.0.4638.54≥ unspecified, < 95.0.4638.542021-11-02
CVE-2021-37996 [MEDIUM] CWE-20 CVE-2021-37996: Insufficient validation of untrusted input Downloads in Google Chrome prior to 95.0.4638.54 allowed Insufficient validation of untrusted input Downloads in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to bypass navigation restrictions via a malicious file.
nvd
CVE-2010-3115P4MEDIUMCVSS 5.0fixed in 5.0.375.1272010-08-24
CVE-2010-3115 [MEDIUM] CVE-2010-3115: Google Chrome before 5.0.375.127, and webkitgtk before 1.2.6, does not properly implement the histor Google Chrome before 5.0.375.127, and webkitgtk before 1.2.6, does not properly implement the history feature, which might allow remote attackers to spoof the address bar via unspecified vectors.
nvd
CVE-2014-7945P4MEDIUMCVSS 5.0≤ 40.0.2214.852015-01-22
CVE-2014-7945 [MEDIUM] CWE-119 CVE-2014-7945: OpenJPEG before r2908, as used in PDFium in Google Chrome before 40.0.2214.91, allows remote attacke OpenJPEG before r2908, as used in PDFium in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PDF document, related to j2k.c, jp2.c, and t2.c.
nvd
CVE-2014-7947P4MEDIUMCVSS 5.0≤ 40.0.2214.852015-01-22
CVE-2014-7947 [MEDIUM] CWE-119 CVE-2014-7947: OpenJPEG before r2944, as used in PDFium in Google Chrome before 40.0.2214.91, allows remote attacke OpenJPEG before r2944, as used in PDFium in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PDF document, related to j2k.c, jp2.c, pi.c, t1.c, t2.c, and tcd.c.
nvd
CVE-2011-1187P4MEDIUMCVSS 5.0fixed in 10.0.648.1272011-03-11
CVE-2011-1187 [MEDIUM] CWE-200 CVE-2011-1187: Google Chrome before 10.0.648.127 allows remote attackers to bypass the Same Origin Policy via unspe Google Chrome before 10.0.648.127 allows remote attackers to bypass the Same Origin Policy via unspecified vectors, related to an "error message leak."
nvd
CVE-2014-7946P4MEDIUMCVSS 5.0≤ 40.0.2214.852015-01-22
CVE-2014-7946 [MEDIUM] CWE-119 CVE-2014-7946: The RenderTable::simplifiedNormalFlowLayout function in core/rendering/RenderTable.cpp in Blink, as The RenderTable::simplifiedNormalFlowLayout function in core/rendering/RenderTable.cpp in Blink, as used in Google Chrome before 40.0.2214.91, skips captions during table layout in certain situations, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors related to the Fonts implementation.
nvd
CVE-2014-7941P4MEDIUMCVSS 5.0≤ 40.0.2214.852015-01-22
CVE-2014-7941 [MEDIUM] CWE-119 CVE-2014-7941: The SelectionOwner::ProcessTarget function in ui/base/x/selection_owner.cc in the UI implementation The SelectionOwner::ProcessTarget function in ui/base/x/selection_owner.cc in the UI implementation in Google Chrome before 40.0.2214.91 uses an incorrect data type for a certain length value, which allows remote attackers to cause a denial of service (out-of-bounds read) via crafted X11 data.
nvd
CVE-2014-3173P4MEDIUMCVSS 5.0≤ 37.0.2062.93v37.0.2062.0+80 more2014-08-27
CVE-2014-3173 [MEDIUM] CWE-119 CVE-2014-3173: The WebGL implementation in Google Chrome before 37.0.2062.94 does not ensure that clear calls inter The WebGL implementation in Google Chrome before 37.0.2062.94 does not ensure that clear calls interact properly with the state of a draw buffer, which allows remote attackers to cause a denial of service (read of uninitialized memory) via a crafted CANVAS element, related to gpu/command_buffer/service/framebuffer_manager.cc and gpu/command_buffer/ser
nvd
Google Chrome vulnerabilities | cvebase