Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2
Vulnerabilities
Page 255 of 292
CVE-2013-0899P4MEDIUMCVSS 5.0fixed in 25.0.1364.97fixed in 25.0.1364.992013-02-23
CVE-2013-0899 [MEDIUM] CWE-190 CVE-2013-0899: Integer overflow in the padding implementation in the opus_packet_parse_impl function in src/opus_de
Integer overflow in the padding implementation in the opus_packet_parse_impl function in src/opus_decoder.c in Opus before 1.0.2, as used in Google Chrome before 25.0.1364.97 on Windows and Linux and before 25.0.1364.99 on Mac OS X and other products, allows remote attackers to cause a denial of service (out-of-bounds read) via a long packet.
nvd
CVE-2011-3100P4MEDIUMCVSS 5.0≤ 19.0.1084.452012-05-16
CVE-2011-3100 [MEDIUM] CVE-2011-3100: Google Chrome before 19.0.1084.46 does not properly draw dash paths, which allows remote attackers t
Google Chrome before 19.0.1084.46 does not properly draw dash paths, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2011-3093P4MEDIUMCVSS 5.0≤ 19.0.1084.452012-05-16
CVE-2011-3093 [MEDIUM] CWE-20 CVE-2011-3093: Google Chrome before 19.0.1084.46 does not properly handle glyphs, which allows remote attackers to
Google Chrome before 19.0.1084.46 does not properly handle glyphs, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2011-3094P4MEDIUMCVSS 5.0≤ 19.0.1084.452012-05-16
CVE-2011-3094 [MEDIUM] CWE-20 CVE-2011-3094: Google Chrome before 19.0.1084.46 does not properly handle Tibetan text, which allows remote attacke
Google Chrome before 19.0.1084.46 does not properly handle Tibetan text, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2011-3112P4MEDIUMCVSS 5.0≤ 19.0.1084.51v19.0.1028.0+130 more2012-05-24
CVE-2011-3112 [MEDIUM] CWE-399 CVE-2011-3112: Use-after-free vulnerability in the PDF functionality in Google Chrome before 19.0.1084.52 allows re
Use-after-free vulnerability in the PDF functionality in Google Chrome before 19.0.1084.52 allows remote attackers to cause a denial of service or possibly have unspecified other impact via an invalid encrypted document.
nvd
CVE-2015-1247P4MEDIUMCVSS 5.0≤ 42.0.2311.602015-04-19
CVE-2015-1247 [MEDIUM] CWE-200 CVE-2015-1247: The SearchEngineTabHelper::OnPageHasOSDD function in browser/ui/search_engines/search_engine_tab_hel
The SearchEngineTabHelper::OnPageHasOSDD function in browser/ui/search_engines/search_engine_tab_helper.cc in Google Chrome before 42.0.2311.90 does not prevent use of a file: URL for an OpenSearch descriptor XML document, which might allow remote attackers to obtain sensitive information from local files via a crafted (1) http or (2) https web site.
nvd
CVE-2015-1285P4MEDIUMCVSS 5.0≤ 43.0.2357.1342015-07-23
CVE-2015-1285 [MEDIUM] CWE-200 CVE-2015-1285: The XSSAuditor::canonicalize function in core/html/parser/XSSAuditor.cpp in the XSS auditor in Blink
The XSSAuditor::canonicalize function in core/html/parser/XSSAuditor.cpp in the XSS auditor in Blink, as used in Google Chrome before 44.0.2403.89, does not properly choose a truncation point, which makes it easier for remote attackers to obtain sensitive information via an unspecified linear-time attack.
nvd
CVE-2013-0923P4MEDIUMCVSS 5.0≤ 26.0.1410.42v26.0.1410.0+40 more2013-03-28
CVE-2013-0923 [MEDIUM] CWE-119 CVE-2013-0923: The USB Apps API in Google Chrome before 26.0.1410.43 allows remote attackers to cause a denial of s
The USB Apps API in Google Chrome before 26.0.1410.43 allows remote attackers to cause a denial of service (memory corruption) via unspecified vectors.
nvd
CVE-2015-1225P4MEDIUMCVSS 5.0≤ 40.0.2214.1152015-03-09
CVE-2015-1225 [MEDIUM] CWE-119 CVE-2015-1225: PDFium, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause a denial of s
PDFium, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2013-2876P4MEDIUMCVSS 5.0≤ 28.0.1500.70v28.0.1500.0+61 more2013-07-10
CVE-2013-2876 [MEDIUM] CWE-264 CVE-2013-2876: browser/extensions/api/tabs/tabs_api.cc in Google Chrome before 28.0.1500.71 does not properly enfor
browser/extensions/api/tabs/tabs_api.cc in Google Chrome before 28.0.1500.71 does not properly enforce restrictions on the capture of screenshots by extensions, which allows remote attackers to obtain sensitive information about the content of a previous page via vectors involving an interstitial page.
nvd
CVE-2010-0663P4MEDIUMCVSS 5.0≤ 4.0.249.0v0.2.149.27+45 more2010-02-18
CVE-2010-0663 [MEDIUM] CWE-200 CVE-2010-0663: The ParamTraits<SkBitmap>::Read function in common/common_param_traits.cc in Google Chrome before 4.
The ParamTraits::Read function in common/common_param_traits.cc in Google Chrome before 4.0.249.78 does not initialize the memory locations that will hold bitmap data, which might allow remote attackers to obtain potentially sensitive information from process memory by providing insufficient data, related to use of a (1) thumbnail database or (2) HTML
nvd
CVE-2014-3197P4MEDIUMCVSS 5.0≤ 38.0.2125.72014-10-08
CVE-2014-3197 [MEDIUM] CWE-264 CVE-2014-3197: The NavigationScheduler::schedulePageBlock function in core/loader/NavigationScheduler.cpp in Blink,
The NavigationScheduler::schedulePageBlock function in core/loader/NavigationScheduler.cpp in Blink, as used in Google Chrome before 38.0.2125.101, does not properly provide substitute data for pages blocked by the XSS auditor, which allows remote attackers to obtain sensitive information via a crafted web site.
nvd
CVE-2013-2855P4MEDIUMCVSS 5.0≤ 27.0.1453.109v27.0.1453.0+79 more2013-06-05
CVE-2013-2855 [MEDIUM] CWE-119 CVE-2013-2855: The Developer Tools API in Google Chrome before 27.0.1453.110 allows remote attackers to cause a den
The Developer Tools API in Google Chrome before 27.0.1453.110 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2013-2905P4MEDIUMCVSS 5.0≤ 29.0.1547.56v29.0.1547.0+49 more2013-08-21
CVE-2013-2905 [MEDIUM] CWE-264 CVE-2013-2905: The SharedMemory::Create function in memory/shared_memory_posix.cc in Google Chrome before 29.0.1547
The SharedMemory::Create function in memory/shared_memory_posix.cc in Google Chrome before 29.0.1547.57 uses weak permissions under /dev/shm/, which allows attackers to obtain sensitive information via direct access to a POSIX shared-memory file.
nvd
CVE-2020-16012P4MEDIUMCVSS 4.3fixed in 87.0.4280.66≥ unspecified, < 87.0.4280.662021-01-08
CVE-2020-16012 [MEDIUM] CVE-2020-16012: Side-channel information leakage in graphics in Google Chrome prior to 87.0.4280.66 allowed a remote
Side-channel information leakage in graphics in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2011-3022P4MEDIUMCVSS 5.0fixed in 17.0.963.56≥ 19.0, < 19.0.1036.7+13 more2012-02-16
CVE-2011-3022 [MEDIUM] CWE-319 CVE-2011-3022: translate/translate_manager.cc in Google Chrome before 17.0.963.56 and 19.x before 19.0.1036.7 uses
translate/translate_manager.cc in Google Chrome before 17.0.963.56 and 19.x before 19.0.1036.7 uses an HTTP session to exchange data for translation, which allows remote attackers to obtain sensitive information by sniffing the network.
nvd
CVE-2012-2898P4MEDIUMCVSS 5.0≤ 21.0.1180.81v21.0.1180.0+43 more2014-01-05
CVE-2012-2898 [MEDIUM] CVE-2012-2898: Google Chrome before 21.0.1180.82 on iOS on iPad devices allows remote attackers to spoof the Omnibo
Google Chrome before 21.0.1180.82 on iOS on iPad devices allows remote attackers to spoof the Omnibox URL via vectors involving SSL error messages, a related issue to CVE-2012-0674.
nvd
CVE-2011-1202P4MEDIUMCVSS 4.3fixed in 10.0.648.1272011-03-11
CVE-2011-1202 [MEDIUM] CWE-200 CVE-2011-1202: The xsltGenerateIdFunction function in functions.c in libxslt 1.1.26 and earlier, as used in Google
The xsltGenerateIdFunction function in functions.c in libxslt 1.1.26 and earlier, as used in Google Chrome before 10.0.648.127 and other products, allows remote attackers to obtain potentially sensitive information about heap memory addresses via an XML document containing a call to the XSLT generate-id XPath function.
nvd
CVE-2015-1241P4MEDIUMCVSS 4.3fixed in 42.0.2311.902015-04-19
CVE-2015-1241 [MEDIUM] CWE-1021 CVE-2015-1241: Google Chrome before 42.0.2311.90 does not properly consider the interaction of page navigation with
Google Chrome before 42.0.2311.90 does not properly consider the interaction of page navigation with the handling of touch events and gesture events, which allows remote attackers to trigger unintended UI actions via a crafted web site that conducts a "tapjacking" attack.
nvd
CVE-2015-1286P4MEDIUMCVSS 4.3≤ 43.0.2357.1342015-07-23
CVE-2015-1286 [MEDIUM] CWE-79 CVE-2015-1286: Cross-site scripting (XSS) vulnerability in the V8ContextNativeHandler::GetModuleSystem function in
Cross-site scripting (XSS) vulnerability in the V8ContextNativeHandler::GetModuleSystem function in extensions/renderer/v8_context_native_handler.cc in Google Chrome before 44.0.2403.89 allows remote attackers to inject arbitrary web script or HTML by leveraging the lack of a certain V8 context restriction, aka a Blink "Universal XSS (UXSS)."
nvd