cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2

Vulnerabilities

Page 240 of 292
CVE-2011-5319P4MEDIUMCVSS 5.0≤ 40.0.2214.1152015-03-09
CVE-2011-5319 [MEDIUM] CWE-264 CVE-2011-5319: content/renderer/device_sensors/device_motion_event_pump.cc in Google Chrome before 41.0.2272.76 doe content/renderer/device_sensors/device_motion_event_pump.cc in Google Chrome before 41.0.2272.76 does not properly restrict access to high-rate accelerometer data, which makes it easier for remote attackers to capture keystrokes via a crafted web site that listens for ondevicemotion events, a different vulnerability than CVE-2015-1231.
nvd
CVE-2012-5146P4MEDIUMCVSS 5.0≤ 24.0.1312.51v24.0.1272.0+110 more2013-01-15
CVE-2012-5146 [MEDIUM] CWE-264 CVE-2012-5146: Google Chrome before 24.0.1312.52 allows remote attackers to bypass the Same Origin Policy via a mal Google Chrome before 24.0.1312.52 allows remote attackers to bypass the Same Origin Policy via a malformed URL.
nvd
CVE-2013-2872P4MEDIUMCVSS 5.0≤ 28.0.1500.70v28.0.1500.0+61 more2013-07-10
CVE-2013-2872 [MEDIUM] CVE-2013-2872: Google Chrome before 28.0.1500.71 on Mac OS X does not ensure a sufficient source of entropy for ren Google Chrome before 28.0.1500.71 on Mac OS X does not ensure a sufficient source of entropy for renderer processes, which might make it easier for remote attackers to defeat cryptographic protection mechanisms in third-party components via unspecified vectors.
nvd
CVE-2019-5779P4MEDIUMCVSS 4.3fixed in 72.0.3626.81≥ unspecified, < 72.0.3626.812019-02-19
CVE-2019-5779 [MEDIUM] CWE-862 CVE-2019-5779: Insufficient policy validation in ServiceWorker in Google Chrome prior to 72.0.3626.81 allowed a rem Insufficient policy validation in ServiceWorker in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
nvd
CVE-2013-6642P4MEDIUMCVSS 5.0≤ 32.0.1700.23v32.0.1651.2+142 more2014-01-16
CVE-2013-6642 [MEDIUM] CVE-2013-6642: Google Chrome through 32.0.1700.23 on Android allows remote attackers to spoof the address bar via u Google Chrome through 32.0.1700.23 on Android allows remote attackers to spoof the address bar via unspecified vectors.
nvd
CVE-2018-6082P4MEDIUMCVSS 4.7fixed in 65.0.3325.1462018-11-14
CVE-2018-6082 [MEDIUM] CWE-200 CVE-2018-6082: Including port 22 in the list of allowed FTP ports in Networking in Google Chrome prior to 65.0.3325 Including port 22 in the list of allowed FTP ports in Networking in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially enumerate internal host services via a crafted HTML page.
nvd
CVE-2017-5065P4MEDIUMCVSS 4.7fixed in 58.0.3029.812017-10-27
CVE-2017-5065 [MEDIUM] CWE-20 CVE-2017-5065: Lack of an appropriate action on page navigation in Blink in Google Chrome prior to 58.0.3029.81 for Lack of an appropriate action on page navigation in Blink in Google Chrome prior to 58.0.3029.81 for Windows and Mac allowed a remote attacker to potentially confuse a user into making an incorrect security decision via a crafted HTML page.
nvd
CVE-2015-6779P4MEDIUMCVSS 4.3≤ 46.0.2490.862015-12-06
CVE-2015-6779 [MEDIUM] CWE-264 CVE-2015-6779: PDFium, as used in Google Chrome before 47.0.2526.73, does not properly restrict use of chrome: URLs PDFium, as used in Google Chrome before 47.0.2526.73, does not properly restrict use of chrome: URLs, which allows remote attackers to bypass intended scheme restrictions via a crafted PDF document, as demonstrated by a document with a link to a chrome://settings URL.
nvd
CVE-2026-11281P4MEDIUMCVSS 5.0fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-05
CVE-2026-11281 [MEDIUM] CWE-472 CVE-2026-11281: Integer overflow in Chromoting in Google Chrome on Windows prior to 149.0.7827.53 allowed a local at Integer overflow in Chromoting in Google Chrome on Windows prior to 149.0.7827.53 allowed a local attacker to obtain potentially sensitive information from process memory via a crafted ETW event. (Chromium security severity: Low)
nvd
CVE-2011-3054P4MEDIUMCVSS 4.3fixed in 17.0.963.832012-03-22
CVE-2011-3054 [MEDIUM] CWE-269 CVE-2011-3054: The WebUI privilege implementation in Google Chrome before 17.0.963.83 does not properly perform iso The WebUI privilege implementation in Google Chrome before 17.0.963.83 does not properly perform isolation, which allows remote attackers to bypass intended access restrictions via unspecified vectors.
nvd
CVE-2020-6437P4MEDIUMCVSS 4.3fixed in 81.0.4044.92≥ unspecified, < 81.0.4044.922020-04-13
CVE-2020-6437 [MEDIUM] CVE-2020-6437: Inappropriate implementation in WebView in Google Chrome prior to 81.0.4044.92 allowed a remote atta Inappropriate implementation in WebView in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to spoof security UI via a crafted application.
nvd
CVE-2015-1281P4MEDIUMCVSS 4.3≤ 43.0.2357.1342015-07-23
CVE-2015-1281 [MEDIUM] CWE-254 CVE-2015-1281: core/loader/ImageLoader.cpp in Blink, as used in Google Chrome before 44.0.2403.89, does not properl core/loader/ImageLoader.cpp in Blink, as used in Google Chrome before 44.0.2403.89, does not properly determine the V8 context of a microtask, which allows remote attackers to bypass Content Security Policy (CSP) restrictions by providing an image from an unintended source.
nvd
CVE-2011-2877P4MEDIUMCVSS 6.8fixed in 14.0.835.2022011-10-04
CVE-2011-2877 [MEDIUM] CVE-2011-2877: Google Chrome before 14.0.835.202 does not properly handle SVG text, which allows remote attackers t Google Chrome before 14.0.835.202 does not properly handle SVG text, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to "stale font."
nvd
CVE-2011-1108P4MEDIUMCVSS 6.8fixed in 9.0.597.1072011-03-01
CVE-2011-1108 [MEDIUM] CVE-2011-1108: Google Chrome before 9.0.597.107 does not properly implement JavaScript dialogs, which allows remote Google Chrome before 9.0.597.107 does not properly implement JavaScript dialogs, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted HTML document.
nvd
CVE-2011-1118P4MEDIUMCVSS 6.8fixed in 9.0.597.1072011-03-01
CVE-2011-1118 [MEDIUM] CWE-20 CVE-2011-1118: Google Chrome before 9.0.597.107 does not properly handle TEXTAREA elements, which allows remote att Google Chrome before 9.0.597.107 does not properly handle TEXTAREA elements, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted HTML document.
nvd
CVE-2020-6527P4MEDIUMCVSS 4.3fixed in 84.0.4147.89≥ unspecified, < 84.0.4147.892020-07-22
CVE-2020-6527 [MEDIUM] CWE-276 CVE-2020-6527: Insufficient policy enforcement in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote attac Insufficient policy enforcement in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass content security policy via a crafted HTML page.
nvd
CVE-2021-30589P4MEDIUMCVSS 4.3fixed in 92.0.4515.107≥ unspecified, < 92.0.4515.1072021-08-03
CVE-2021-30589 [MEDIUM] CWE-20 CVE-2021-30589: Insufficient validation of untrusted input in Sharing in Google Chrome prior to 92.0.4515.107 allowe Insufficient validation of untrusted input in Sharing in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to bypass navigation restrictions via a crafted click-to-call link.
nvd
CVE-2012-2894P4MEDIUMCVSS 6.8≤ 22.0.1229.78v22.0.1229.0+51 more2012-09-26
CVE-2012-2894 [MEDIUM] CWE-399 CVE-2012-2894: Google Chrome before 22.0.1229.79 does not properly handle graphics-context data structures, which a Google Chrome before 22.0.1229.79 does not properly handle graphics-context data structures, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2011-1448P4MEDIUMCVSS 6.8fixed in 11.0.696.572011-05-03
CVE-2011-1448 [MEDIUM] CWE-20 CVE-2011-1448: Google Chrome before 11.0.696.57 does not properly perform height calculations, which allows remote Google Chrome before 11.0.696.57 does not properly perform height calculations, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."
nvd
CVE-2011-1441P4MEDIUMCVSS 6.8fixed in 11.0.696.572011-05-03
CVE-2011-1441 [MEDIUM] CWE-704 CVE-2011-1441: Google Chrome before 11.0.696.57 does not properly perform a cast of an unspecified variable during Google Chrome before 11.0.696.57 does not properly perform a cast of an unspecified variable during handling of floating select lists, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted HTML document.
nvd
Google Chrome vulnerabilities | cvebase