Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2
Vulnerabilities
Page 268 of 292
CVE-2009-3264P4MEDIUMCVSS 4.3≤ 3.0.193.2v0.2.149.27+40 more2009-09-18
CVE-2009-3264 [MEDIUM] CWE-264 CVE-2009-3264: The getSVGDocument method in Google Chrome before 3.0.195.21 omits an unspecified "access check," wh
The getSVGDocument method in Google Chrome before 3.0.195.21 omits an unspecified "access check," which allows remote web servers to bypass the Same Origin Policy and conduct cross-site scripting attacks via unknown vectors, related to a user's visit to a different web server that hosts an SVG document.
nvd
CVE-2011-3905P4MEDIUMCVSS 5.0fixed in 16.0.912.632011-12-13
CVE-2011-3905 [MEDIUM] CWE-125 CVE-2011-3905: libxml2, as used in Google Chrome before 16.0.912.63, allows remote attackers to cause a denial of s
libxml2, as used in Google Chrome before 16.0.912.63, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2013-2838P4MEDIUMCVSS 5.0≤ 27.0.1453.91v27.0.1453.0+69 more2013-05-22
CVE-2013-2838 [MEDIUM] CWE-119 CVE-2013-2838: Google V8, as used in Google Chrome before 27.0.1453.93, allows remote attackers to cause a denial o
Google V8, as used in Google Chrome before 27.0.1453.93, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2011-1122P4MEDIUMCVSS 5.0fixed in 9.0.597.1072011-03-01
CVE-2011-1122 [MEDIUM] CWE-125 CVE-2011-1122: The WebGL implementation in Google Chrome before 9.0.597.107 allows remote attackers to cause a deni
The WebGL implementation in Google Chrome before 9.0.597.107 allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors, aka Issue 71960.
nvd
CVE-2011-1120P4MEDIUMCVSS 5.0fixed in 9.0.597.1072011-03-01
CVE-2011-1120 [MEDIUM] CWE-125 CVE-2011-1120: The WebGL implementation in Google Chrome before 9.0.597.107 allows remote attackers to cause a deni
The WebGL implementation in Google Chrome before 9.0.597.107 allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors, aka Issue 71717.
nvd
CVE-2015-5605P4MEDIUMCVSS 5.0≤ 43.0.2357.1342015-07-23
CVE-2015-5605 [MEDIUM] CWE-17 CVE-2015-5605: The regular-expression implementation in Google V8, as used in Google Chrome before 44.0.2403.89, mi
The regular-expression implementation in Google V8, as used in Google Chrome before 44.0.2403.89, mishandles interrupts, which allows remote attackers to cause a denial of service (application crash) via crafted JavaScript code, as demonstrated by an error in garbage collection during allocation of a stack-overflow exception message.
nvd
CVE-2010-0664P4MEDIUMCVSS 5.0≤ 4.0.249.0v0.2.149.27+45 more2010-02-18
CVE-2010-0664 [MEDIUM] CWE-399 CVE-2010-0664: Stack consumption vulnerability in the ChildProcessSecurityPolicy::CanRequestURL function in browser
Stack consumption vulnerability in the ChildProcessSecurityPolicy::CanRequestURL function in browser/child_process_security_policy.cc in Google Chrome before 4.0.249.78 allows remote attackers to cause a denial of service (memory consumption and application crash) via a URL that specifies multiple protocols, as demonstrated by a URL that begins with m
nvd
CVE-2012-5130P4MEDIUMCVSS 5.0≤ 23.0.1271.89v23.0.1271.0+60 more2012-11-28
CVE-2012-5130 [MEDIUM] CWE-125 CVE-2012-5130: Skia, as used in Google Chrome before 23.0.1271.91, allows remote attackers to cause a denial of ser
Skia, as used in Google Chrome before 23.0.1271.91, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2011-3104P4MEDIUMCVSS 5.0≤ 19.0.1084.51v19.0.1028.0+130 more2012-05-24
CVE-2011-3104 [MEDIUM] CWE-119 CVE-2011-3104: Skia, as used in Google Chrome before 19.0.1084.52, allows remote attackers to cause a denial of ser
Skia, as used in Google Chrome before 19.0.1084.52, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2013-2907P4MEDIUMCVSS 5.0≤ 30.0.1599.65v30.0.1599.0+57 more2013-10-02
CVE-2013-2907 [MEDIUM] CWE-119 CVE-2013-2907: The Window.prototype object implementation in Google Chrome before 30.0.1599.66 allows remote attack
The Window.prototype object implementation in Google Chrome before 30.0.1599.66 allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2011-2844P4MEDIUMCVSS 5.0fixed in 14.0.835.1632011-09-19
CVE-2011-2844 [MEDIUM] CWE-125 CVE-2011-2844: Google Chrome before 14.0.835.163 does not properly process MP3 files, which allows remote attackers
Google Chrome before 14.0.835.163 does not properly process MP3 files, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2012-5109P4MEDIUMCVSS 5.0≤ 22.0.1229.91v22.0.1229.0+54 more2012-10-09
CVE-2012-5109 [MEDIUM] CWE-125 CVE-2012-5109: The International Components for Unicode (ICU) functionality in Google Chrome before 22.0.1229.92 al
The International Components for Unicode (ICU) functionality in Google Chrome before 22.0.1229.92 allows remote attackers to cause a denial of service (out-of-bounds read) via vectors related to a regular expression.
nvd
CVE-2013-0883P4MEDIUMCVSS 5.0fixed in 25.0.1364.97fixed in 25.0.1364.992013-02-23
CVE-2013-0883 [MEDIUM] CWE-787 CVE-2013-0883: Skia, as used in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on
Skia, as used in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allows remote attackers to cause a denial of service (incorrect read operation) via unspecified vectors.
nvd
CVE-2013-0881P4MEDIUMCVSS 5.0fixed in 25.0.1364.97fixed in 25.0.1364.992013-02-23
CVE-2013-0881 [MEDIUM] CWE-787 CVE-2013-0881: Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allows
Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allows remote attackers to cause a denial of service (incorrect read operation) via crafted data in the Matroska container format.
nvd
CVE-2011-3963P4MEDIUMCVSS 5.0fixed in 17.0.963.462012-02-09
CVE-2011-3963 [MEDIUM] CWE-125 CVE-2011-3963: Google Chrome before 17.0.963.46 does not properly handle PDF FAX images, which allows remote attack
Google Chrome before 17.0.963.46 does not properly handle PDF FAX images, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2013-6656P4MEDIUMCVSS 5.0≤ 33.0.1750.116v33.0.1750.0+95 more2014-02-24
CVE-2013-6656 [MEDIUM] CWE-200 CVE-2013-6656: The XSSAuditor::init function in core/html/parser/XSSAuditor.cpp in the XSS auditor in Blink, as use
The XSSAuditor::init function in core/html/parser/XSSAuditor.cpp in the XSS auditor in Blink, as used in Google Chrome before 33.0.1750.117, processes POST requests by using the body of a redirecting page instead of the body of a redirect target, which allows remote attackers to obtain sensitive information via unspecified vectors.
nvd
CVE-2011-3916P4MEDIUMCVSS 5.0fixed in 16.0.912.632011-12-13
CVE-2011-3916 [MEDIUM] CWE-125 CVE-2011-3916: Google Chrome before 16.0.912.63 does not properly handle PDF cross references, which allows remote
Google Chrome before 16.0.912.63 does not properly handle PDF cross references, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2012-2820P4MEDIUMCVSS 5.0≤ 20.0.1132.42v20.0.1132.0+41 more2012-06-27
CVE-2012-2820 [MEDIUM] CWE-20 CVE-2012-2820: Google Chrome before 20.0.1132.43 does not properly implement SVG filters, which allows remote attac
Google Chrome before 20.0.1132.43 does not properly implement SVG filters, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2012-2826P4MEDIUMCVSS 5.0≤ 20.0.1132.42v20.0.1132.0+41 more2012-06-27
CVE-2012-2826 [MEDIUM] CVE-2012-2826: Google Chrome before 20.0.1132.43 does not properly implement texture conversion, which allows remot
Google Chrome before 20.0.1132.43 does not properly implement texture conversion, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2011-3911P4MEDIUMCVSS 5.0fixed in 16.0.912.632011-12-13
CVE-2011-3911 [MEDIUM] CWE-125 CVE-2011-3911: Google Chrome before 16.0.912.63 does not properly handle PDF documents, which allows remote attacke
Google Chrome before 16.0.912.63 does not properly handle PDF documents, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd