cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2

Vulnerabilities

Page 256 of 292
CVE-2017-5103P4MEDIUMCVSS 4.3≤ 60.0.3112.782017-10-27
CVE-2017-5103 [MEDIUM] CWE-908 CVE-2017-5103: Use of an uninitialized value in Skia in Google Chrome prior to 60.0.3112.78 for Linux, Windows, and Use of an uninitialized value in Skia in Google Chrome prior to 60.0.3112.78 for Linux, Windows, and Mac allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
nvd
CVE-2017-5102P4MEDIUMCVSS 4.3≤ 60.0.3112.782017-10-27
CVE-2017-5102 [MEDIUM] CWE-908 CVE-2017-5102: Use of an uninitialized value in Skia in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux Use of an uninitialized value in Skia in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
nvd
CVE-2015-1278P4MEDIUMCVSS 4.3≤ 43.0.2357.1342015-07-23
CVE-2015-1278 [MEDIUM] CWE-254 CVE-2015-1278: content/browser/web_contents/web_contents_impl.cc in Google Chrome before 44.0.2403.89 does not ensu content/browser/web_contents/web_contents_impl.cc in Google Chrome before 44.0.2403.89 does not ensure that a PDF document's modal dialog is closed upon navigation to an interstitial page, which allows remote attackers to spoof URLs via a crafted document, as demonstrated by the alert_dialog.pdf document.
nvd
CVE-2017-5119P4MEDIUMCVSS 4.3fixed in 61.0.3163.1002017-10-27
CVE-2017-5119 [MEDIUM] CWE-119 CVE-2017-5119: Use of an uninitialized value in Skia in Google Chrome prior to 61.0.3163.79 for Mac, Windows, and L Use of an uninitialized value in Skia in Google Chrome prior to 61.0.3163.79 for Mac, Windows, and Linux, and 61.0.3163.81 for Android, allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
nvd
CVE-2011-3881P4MEDIUMCVSS 4.3fixed in 15.0.874.1022011-10-25
CVE-2011-3881 [MEDIUM] CWE-79 CVE-2011-3881: WebKit, as used in Google Chrome before 15.0.874.102 and Android before 4.4, allows remote attackers WebKit, as used in Google Chrome before 15.0.874.102 and Android before 4.4, allows remote attackers to bypass the Same Origin Policy and conduct Universal XSS (UXSS) attacks via vectors related to (1) the DOMWindow::clear function and use of a selection object, (2) the Object::GetRealNamedPropertyInPrototypeChain function and use of an __proto__ prope
nvd
CVE-2011-3040P4MEDIUMCVSS 4.3fixed in 17.0.963.652012-03-05
CVE-2011-3040 [MEDIUM] CWE-125 CVE-2011-3040: Google Chrome before 17.0.963.65 does not properly handle text, which allows remote attackers to cau Google Chrome before 17.0.963.65 does not properly handle text, which allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted document.
nvd
CVE-2020-6489P4MEDIUMCVSS 4.3fixed in 83.0.4103.61≥ unspecified, < 83.0.4103.612020-05-21
CVE-2020-6489 [MEDIUM] CWE-200 CVE-2020-6489: Inappropriate implementation in developer tools in Google Chrome prior to 83.0.4103.61 allowed a rem Inappropriate implementation in developer tools in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had convinced the user to take certain actions in developer tools to obtain potentially sensitive information from disk via a crafted HTML page.
nvd
CVE-2018-6112P4MEDIUMCVSS 4.3fixed in 66.0.3359.117≥ unspecified, < 66.0.3359.1172019-01-09
CVE-2018-6112 [MEDIUM] CWE-706 CVE-2018-6112: Making URLs clickable and allowing them to be styled in DevTools in Google Chrome prior to 66.0.3359 Making URLs clickable and allowing them to be styled in DevTools in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
nvd
CVE-2020-6531P4MEDIUMCVSS 4.3fixed in 84.0.4147.89≥ unspecified, < 84.0.4147.892020-07-22
CVE-2020-6531 [MEDIUM] CWE-203 CVE-2020-6531: Side-channel information leakage in scroll to text in Google Chrome prior to 84.0.4147.89 allowed a Side-channel information leakage in scroll to text in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2014-3166P4MEDIUMCVSS 4.3fixed in 36.0.1985.143fixed in 36.0.1985.135+1 more2014-08-13
CVE-2014-3166 [MEDIUM] CVE-2014-3166: The Public Key Pinning (PKP) implementation in Google Chrome before 36.0.1985.143 on Windows, OS X, The Public Key Pinning (PKP) implementation in Google Chrome before 36.0.1985.143 on Windows, OS X, and Linux, and before 36.0.1985.135 on Android, does not correctly consider the properties of SPDY connections, which allows remote attackers to obtain sensitive information by leveraging the use of multiple domain names.
nvd
CVE-2015-1236P4MEDIUMCVSS 4.3≤ 42.0.2311.602015-04-19
CVE-2015-1236 [MEDIUM] CWE-264 CVE-2015-1236: The MediaElementAudioSourceNode::process function in modules/webaudio/MediaElementAudioSourceNode.cp The MediaElementAudioSourceNode::process function in modules/webaudio/MediaElementAudioSourceNode.cpp in the Web Audio API implementation in Blink, as used in Google Chrome before 42.0.2311.90, allows remote attackers to bypass the Same Origin Policy and obtain sensitive audio sample values via a crafted web site containing a media element.
nvd
CVE-2017-5033P4MEDIUMCVSS 4.3≤ 57.0.2987.75≤ 57.0.2987.1002017-04-24
CVE-2017-5033 [MEDIUM] CWE-281 CVE-2017-5033: Blink in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Andro Blink in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android failed to correctly propagate CSP restrictions to local scheme pages, which allowed a remote attacker to bypass content security policy via a crafted HTML page, related to the unsafe-inline keyword.
nvd
CVE-2017-5026P4MEDIUMCVSS 4.3≤ 55.0.2883.872017-02-17
CVE-2017-5026 [MEDIUM] CWE-1021 CVE-2017-5026: Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, failed to prevent alerts from being Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, failed to prevent alerts from being displayed by swapped out frames, which allowed a remote attacker to show alerts on a page they don't control via a crafted HTML page.
nvd
CVE-2016-1657P4MEDIUMCVSS 4.3≤ 49.0.2623.1122016-04-18
CVE-2016-1657 [MEDIUM] CWE-254 CVE-2016-1657: The WebContentsImpl::FocusLocationBarByDefault function in content/browser/web_contents/web_contents The WebContentsImpl::FocusLocationBarByDefault function in content/browser/web_contents/web_contents_impl.cc in Google Chrome before 50.0.2661.75 mishandles focus for certain about:blank pages, which allows remote attackers to spoof the address bar via a crafted URL.
nvd
CVE-2016-1658P4MEDIUMCVSS 4.3≤ 49.0.2623.1122016-04-18
CVE-2016-1658 [MEDIUM] CWE-200 CVE-2016-1658: The Extensions subsystem in Google Chrome before 50.0.2661.75 incorrectly relies on GetOrigin method The Extensions subsystem in Google Chrome before 50.0.2661.75 incorrectly relies on GetOrigin method calls for origin comparisons, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted extension.
nvd
CVE-2015-6790P4MEDIUMCVSS 4.3≤ 47.0.2526.732015-12-14
CVE-2015-6790 [MEDIUM] CWE-20 CVE-2015-6790: The WebPageSerializerImpl::openTagToString function in WebKit/Source/web/WebPageSerializerImpl.cpp i The WebPageSerializerImpl::openTagToString function in WebKit/Source/web/WebPageSerializerImpl.cpp in the page serializer in Google Chrome before 47.0.2526.80 does not properly use HTML entities, which might allow remote attackers to inject arbitrary web script or HTML via a crafted document, as demonstrated by a double-quote character inside a single-
nvd
CVE-2016-5214P4MEDIUMCVSS 4.3≤ 54.0.2840.992017-01-19
CVE-2016-5214 [MEDIUM] CWE-19 CVE-2016-5214: Google Chrome prior to 55.0.2883.75 for Windows mishandled downloaded files, which allowed a remote Google Chrome prior to 55.0.2883.75 for Windows mishandled downloaded files, which allowed a remote attacker to prevent the downloaded file from receiving the Mark of the Web via a crafted HTML page.
nvd
CVE-2020-15966P4MEDIUMCVSS 4.3fixed in 85.0.4183.121≥ unspecified, < 85.0.4183.1212020-09-21
CVE-2020-15966 [MEDIUM] CVE-2020-15966: Insufficient policy enforcement in extensions in Google Chrome prior to 85.0.4183.121 allowed an att Insufficient policy enforcement in extensions in Google Chrome prior to 85.0.4183.121 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information via a crafted Chrome Extension.
nvd
CVE-2020-6391P4MEDIUMCVSS 4.3fixed in 80.0.3987.87≥ unspecified, < 80.0.3987.872020-02-11
CVE-2020-6391 [MEDIUM] CWE-79 CVE-2020-6391: Insufficient validation of untrusted input in Blink in Google Chrome prior to 80.0.3987.87 allowed a Insufficient validation of untrusted input in Blink in Google Chrome prior to 80.0.3987.87 allowed a local attacker to bypass content security policy via a crafted HTML page.
nvd
CVE-2018-6041P4MEDIUMCVSS 4.3fixed in 64.0.3282.119≥ unspecified, < 64.0.3282.1192018-09-25
CVE-2018-6041 [MEDIUM] CWE-20 CVE-2018-6041: Incorrect security UI in navigation in Google Chrome prior to 64.0.3282.119 allowed a remote attacke Incorrect security UI in navigation in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd
Google Chrome vulnerabilities | cvebase