cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2

Vulnerabilities

Page 269 of 292
CVE-2011-3903P4MEDIUMCVSS 5.0fixed in 16.0.912.632011-12-13
CVE-2011-3903 [MEDIUM] CWE-697 CVE-2011-3903: Google Chrome before 16.0.912.63 does not properly perform regex matching, which allows remote attac Google Chrome before 16.0.912.63 does not properly perform regex matching, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2011-4691P4MEDIUMCVSS 5.0≤ 15.0.874.1212011-12-07
CVE-2011-4691 [MEDIUM] CWE-264 CVE-2011-4691: Google Chrome 15.0.874.121 and earlier does not prevent capture of data about the times of Same Orig Google Chrome 15.0.874.121 and earlier does not prevent capture of data about the times of Same Origin Policy violations during IFRAME loading attempts, which makes it easier for remote attackers to determine whether a document exists in the browser cache via crafted JavaScript code.
nvd
CVE-2011-3910P4MEDIUMCVSS 5.0fixed in 16.0.912.632011-12-13
CVE-2011-3910 [MEDIUM] CWE-125 CVE-2011-3910: Google Chrome before 16.0.912.63 does not properly handle YUV video frames, which allows remote atta Google Chrome before 16.0.912.63 does not properly handle YUV video frames, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2012-2854P4MEDIUMCVSS 5.0≤ 21.0.1180.56v21.0.1180.0+25 more2012-08-06
CVE-2012-2854 [MEDIUM] CWE-200 CVE-2012-2854: Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chro Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, allows remote attackers to obtain potentially sensitive information about pointer values by leveraging access to a WebUI renderer process.
nvd
CVE-2011-0776P4MEDIUMCVSS 5.0fixed in 9.0.597.842011-02-04
CVE-2011-0776 [MEDIUM] CWE-200 CVE-2011-0776: The sandbox implementation in Google Chrome before 9.0.597.84 on Mac OS X might allow remote attacke The sandbox implementation in Google Chrome before 9.0.597.84 on Mac OS X might allow remote attackers to obtain potentially sensitive information about local files via vectors related to the stat system call.
nvd
CVE-2010-3250P4MEDIUMCVSS 5.0fixed in 6.0.472.532010-09-07
CVE-2010-3250 [MEDIUM] CVE-2010-3250: Unspecified vulnerability in Google Chrome before 6.0.472.53 allows remote attackers to enumerate th Unspecified vulnerability in Google Chrome before 6.0.472.53 allows remote attackers to enumerate the set of installed extensions via unknown vectors.
nvd
CVE-2012-2891P4MEDIUMCVSS 5.0≤ 22.0.1229.78v22.0.1229.0+51 more2012-09-26
CVE-2012-2891 [MEDIUM] CWE-200 CVE-2012-2891: The IPC implementation in Google Chrome before 22.0.1229.79 allows attackers to obtain potentially s The IPC implementation in Google Chrome before 22.0.1229.79 allows attackers to obtain potentially sensitive information about memory addresses via unspecified vectors.
nvd
CVE-2010-5073P4MEDIUMCVSS 5.0v4.0.212.0v4.0.212.1+222 more2011-12-07
CVE-2010-5073 [MEDIUM] CVE-2010-5073: The JavaScript implementation in Google Chrome 4 does not properly restrict the set of values contai The JavaScript implementation in Google Chrome 4 does not properly restrict the set of values contained in the object returned by the getComputedStyle method, which allows remote attackers to obtain sensitive information about visited web pages by calling this method. NOTE: this may overlap CVE-2010-5070.
nvd
CVE-2010-0660P4MEDIUMCVSS 5.0≤ 4.0.249.0v0.2.149.27+45 more2010-02-18
CVE-2010-0660 [MEDIUM] CWE-200 CVE-2010-0660: Google Chrome before 4.0.249.78 sends an https URL in the Referer header of an http request in certa Google Chrome before 4.0.249.78 sends an https URL in the Referer header of an http request in certain circumstances involving https to http redirection, which allows remote HTTP servers to obtain potentially sensitive information via standard HTTP logging.
nvd
CVE-2015-6784P4MEDIUMCVSS 4.3≤ 46.0.2490.862015-12-06
CVE-2015-6784 [MEDIUM] CWE-20 CVE-2015-6784: The page serializer in Google Chrome before 47.0.2526.73 mishandles Mark of the Web (MOTW) comments The page serializer in Google Chrome before 47.0.2526.73 mishandles Mark of the Web (MOTW) comments for URLs containing a "--" sequence, which might allow remote attackers to inject HTML via a crafted URL, as demonstrated by an initial http://example.com?-- substring.
nvd
CVE-2011-3055P4MEDIUMCVSS 4.3fixed in 17.0.963.832012-03-22
CVE-2011-3055 [MEDIUM] CWE-306 CVE-2011-3055: The browser native UI in Google Chrome before 17.0.963.83 does not require user confirmation before The browser native UI in Google Chrome before 17.0.963.83 does not require user confirmation before an unpacked extension installation, which allows user-assisted remote attackers to have an unspecified impact via a crafted extension.
nvd
CVE-2017-15418P4MEDIUMCVSS 4.3fixed in 63.0.3239.842018-08-28
CVE-2017-15418 [MEDIUM] CWE-119 CVE-2017-15418: Use of uninitialized memory in Skia in Google Chrome prior to 63.0.3239.84 allowed a remote attacker Use of uninitialized memory in Skia in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
nvd
CVE-2010-3259P4MEDIUMCVSS 4.3fixed in 6.0.472.532010-09-07
CVE-2010-3259 [MEDIUM] CWE-200 CVE-2010-3259: WebKit, as used in Apple Safari before 4.1.3 and 5.0.x before 5.0.3, Google Chrome before 6.0.472.53 WebKit, as used in Apple Safari before 4.1.3 and 5.0.x before 5.0.3, Google Chrome before 6.0.472.53, and webkitgtk before 1.2.6, does not properly restrict read access to images derived from CANVAS elements, which allows remote attackers to bypass the Same Origin Policy and obtain potentially sensitive image data via a crafted web site.
nvd
CVE-2015-1275P4MEDIUMCVSS 4.3≤ 43.0.2357.1342015-07-23
CVE-2015-1275 [MEDIUM] CWE-79 CVE-2015-1275: Cross-site scripting (XSS) vulnerability in org/chromium/chrome/browser/UrlUtilities.java in Google Cross-site scripting (XSS) vulnerability in org/chromium/chrome/browser/UrlUtilities.java in Google Chrome before 44.0.2403.89 on Android allows remote attackers to inject arbitrary web script or HTML via a crafted intent: URL, as demonstrated by a trailing alert(document.cookie);// substring, aka "Universal XSS (UXSS)."
nvd
CVE-2015-1287P4MEDIUMCVSS 4.3≤ 43.0.2357.1342015-07-23
CVE-2015-1287 [MEDIUM] CWE-17 CVE-2015-1287: Blink, as used in Google Chrome before 44.0.2403.89, enables a quirks-mode exception that limits the Blink, as used in Google Chrome before 44.0.2403.89, enables a quirks-mode exception that limits the cases in which a Cascading Style Sheets (CSS) document is required to have the text/css content type, which allows remote attackers to bypass the Same Origin Policy via a crafted web site, related to core/fetch/CSSStyleSheetResource.cpp.
nvd
CVE-2011-3968P4MEDIUMCVSS 4.3fixed in 17.0.963.462012-02-09
CVE-2011-3968 [MEDIUM] CWE-416 CVE-2011-3968: Use-after-free vulnerability in Google Chrome before 17.0.963.46 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 17.0.963.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving Cascading Style Sheets (CSS) token sequences.
nvd
CVE-2015-3334P4MEDIUMCVSS 4.3≤ 42.0.2311.602015-04-19
CVE-2015-3334 [MEDIUM] CWE-17 CVE-2015-3334: browser/ui/website_settings/website_settings.cc in Google Chrome before 42.0.2311.90 does not always browser/ui/website_settings/website_settings.cc in Google Chrome before 42.0.2311.90 does not always display "Media: Allowed by you" in a Permissions table after the user has granted camera permission to a web site, which might make it easier for user-assisted remote attackers to obtain sensitive video data from a device's physical environment via a cr
nvd
CVE-2013-2866P4MEDIUMCVSS 4.3≤ 27.0.1453.115v27.0.1453.0+85 more2013-06-19
CVE-2013-2866 [MEDIUM] CWE-264 CVE-2013-2866: The Flash plug-in in Google Chrome before 27.0.1453.116, as used on Google Chrome OS before 27.0.145 The Flash plug-in in Google Chrome before 27.0.1453.116, as used on Google Chrome OS before 27.0.1453.116 and separately, does not properly determine whether a user wishes to permit camera or microphone access by a Flash application, which allows remote attackers to obtain sensitive information from a machine's physical environment via a clickjacking
nvd
CVE-2014-7948P4MEDIUMCVSS 4.3≤ 40.0.2214.852015-01-22
CVE-2014-7948 [MEDIUM] CWE-310 CVE-2014-7948: The AppCacheUpdateJob::URLFetcher::OnResponseStarted function in content/browser/appcache/appcache_u The AppCacheUpdateJob::URLFetcher::OnResponseStarted function in content/browser/appcache/appcache_update_job.cc in Google Chrome before 40.0.2214.91 proceeds with AppCache caching for SSL sessions even if there is an X.509 certificate error, which allows man-in-the-middle attackers to spoof HTML5 application content via a crafted certificate.
nvd
CVE-2018-17467P4MEDIUMCVSS 4.3fixed in 70.0.3538.67≥ unspecified, < 70.0.3538.672018-11-14
CVE-2018-17467 [MEDIUM] CWE-459 CVE-2018-17467: Insufficiently quick clearing of stale rendered content in Navigation in Google Chrome prior to 70.0 Insufficiently quick clearing of stale rendered content in Navigation in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd
Google Chrome vulnerabilities | cvebase