cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2

Vulnerabilities

Page 270 of 292
CVE-2017-5023P4MEDIUMCVSS 4.3≤ 55.0.2883.872017-02-17
CVE-2017-5023 [MEDIUM] CWE-476 CVE-2017-5023: Type confusion in Histogram in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 5 Type confusion in Histogram in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, allowed a remote attacker to potentially exploit a near null dereference via a crafted HTML page.
nvd
CVE-2018-17471P4MEDIUMCVSS 4.3fixed in 70.0.3538.67≥ unspecified, < 70.0.3538.672018-11-14
CVE-2018-17471 [MEDIUM] CVE-2018-17471: Incorrect dialog placement in WebContents in Google Chrome prior to 70.0.3538.67 allowed a remote at Incorrect dialog placement in WebContents in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to obscure the full screen warning via a crafted HTML page.
nvd
CVE-2017-5079P4MEDIUMCVSS 4.3fixed in 59.0.3071.86fixed in 59.0.3071.922017-10-27
CVE-2017-5079 [MEDIUM] CWE-20 CVE-2017-5079: Inappropriate implementation in Blink in Google Chrome prior to 59.0.3071.86 for Mac, Windows, and L Inappropriate implementation in Blink in Google Chrome prior to 59.0.3071.86 for Mac, Windows, and Linux, and 59.0.3071.92 for Android, allowed a remote attacker to display UI on a non attacker controlled tab via a crafted HTML page.
nvd
CVE-2018-17476P4MEDIUMCVSS 4.3fixed in 70.0.3538.67≥ unspecified, < 70.0.3538.672018-11-14
CVE-2018-17476 [MEDIUM] CVE-2018-17476: Incorrect dialog placement in Cast UI in Google Chrome prior to 70.0.3538.67 allowed a remote attack Incorrect dialog placement in Cast UI in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to obscure the full screen warning via a crafted HTML page.
nvd
CVE-2018-17464P4MEDIUMCVSS 4.3fixed in 70.0.3538.67≥ unspecified, < 70.0.3538.672018-11-14
CVE-2018-17464 [MEDIUM] CVE-2018-17464: Incorrect handling of history on iOS in Navigation in Google Chrome prior to 70.0.3538.67 allowed a Incorrect handling of history on iOS in Navigation in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd
CVE-2017-5096P4MEDIUMCVSS 4.3fixed in 60.0.3112.782017-10-27
CVE-2017-5096 [MEDIUM] CWE-200 CVE-2017-5096: Insufficient policy enforcement during navigation between different schemes in Google Chrome prior t Insufficient policy enforcement during navigation between different schemes in Google Chrome prior to 60.0.3112.78 for Android allowed a remote attacker to perform cross origin content download via a crafted HTML page, related to intents.
nvd
CVE-2020-6438P4MEDIUMCVSS 4.3fixed in 81.0.4044.92≥ unspecified, < 81.0.4044.922020-04-13
CVE-2020-6438 [MEDIUM] CWE-209 CVE-2020-6438: Insufficient policy enforcement in extensions in Google Chrome prior to 81.0.4044.92 allowed an atta Insufficient policy enforcement in extensions in Google Chrome prior to 81.0.4044.92 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from process memory via a crafted Chrome Extension.
nvd
CVE-2017-5017P4MEDIUMCVSS 4.3≤ 55.0.2883.872017-02-17
CVE-2017-5017 [MEDIUM] CWE-200 CVE-2017-5017: Interactions with the OS in Google Chrome prior to 56.0.2924.76 for Mac insufficiently cleared video Interactions with the OS in Google Chrome prior to 56.0.2924.76 for Mac insufficiently cleared video memory, which allowed a remote attacker to possibly extract image fragments on systems with GeForce 8600M graphics chips via a crafted HTML page.
nvd
CVE-2017-5109P4MEDIUMCVSS 4.3fixed in 60.0.3112.782017-10-27
CVE-2017-5109 [MEDIUM] CWE-20 CVE-2017-5109: Inappropriate implementation of unload handler handling in permission prompts in Google Chrome prior Inappropriate implementation of unload handler handling in permission prompts in Google Chrome prior to 60.0.3112.78 for Linux, Windows, and Mac allowed a remote attacker to display UI on a non attacker controlled tab via a crafted HTML page.
nvd
CVE-2020-15959P4MEDIUMCVSS 4.3fixed in 85.0.4183.102≥ unspecified, < 85.0.4183.1022020-09-21
CVE-2020-15959 [MEDIUM] CVE-2020-15959: Insufficient policy enforcement in networking in Google Chrome prior to 85.0.4183.102 allowed an att Insufficient policy enforcement in networking in Google Chrome prior to 85.0.4183.102 allowed an attacker who convinced the user to enable logging to obtain potentially sensitive information from process memory via social engineering.
nvd
CVE-2018-6042P4MEDIUMCVSS 4.3fixed in 64.0.3282.119≥ unspecified, < 64.0.3282.1192018-09-25
CVE-2018-6042 [MEDIUM] CWE-20 CVE-2018-6042: Incorrect security UI in Omnibox in Google Chrome prior to 64.0.3282.119 allowed a remote attacker t Incorrect security UI in Omnibox in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd
CVE-2019-13763P4MEDIUMCVSS 4.3fixed in 79.0.3945.79≥ unspecified, < 79.0.3945.792019-12-10
CVE-2019-13763 [MEDIUM] CVE-2019-13763: Insufficient policy enforcement in payments in Google Chrome prior to 79.0.3945.79 allowed a remote Insufficient policy enforcement in payments in Google Chrome prior to 79.0.3945.79 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page.
nvd
CVE-2016-5193P4MEDIUMCVSS 4.3≤ 53.0.2785.1432016-12-18
CVE-2016-5193 [MEDIUM] CWE-20 CVE-2016-5193: Google Chrome prior to 54.0 for iOS had insufficient validation of URLs for windows open by DOM, whi Google Chrome prior to 54.0 for iOS had insufficient validation of URLs for windows open by DOM, which allowed a remote attacker to bypass restrictions on navigation to certain URL schemes via crafted HTML pages.
nvd
CVE-2018-17475P4MEDIUMCVSS 4.3fixed in 70.0.3538.67≥ unspecified, < 70.0.3538.672018-11-14
CVE-2018-17475 [MEDIUM] CVE-2018-17475: Incorrect handling of history on iOS in Navigation in Google Chrome prior to 70.0.3538.67 allowed a Incorrect handling of history on iOS in Navigation in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd
CVE-2018-6078P4MEDIUMCVSS 4.3fixed in 65.0.3325.146≥ unspecified, < 65.0.3325.1462018-11-14
CVE-2018-6078 [MEDIUM] CWE-20 CVE-2018-6078: Incorrect handling of confusable characters in Omnibox in Google Chrome prior to 65.0.3325.146 allow Incorrect handling of confusable characters in Omnibox in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.
nvd
CVE-2018-17477P4MEDIUMCVSS 4.3fixed in 70.0.3538.67≥ unspecified, < 70.0.3538.672018-11-14
CVE-2018-17477 [MEDIUM] CVE-2018-17477: Incorrect dialog placement in Extensions in Google Chrome prior to 70.0.3538.67 allowed a remote att Incorrect dialog placement in Extensions in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to spoof the contents of extension popups via a crafted HTML page.
nvd
CVE-2020-6570P4MEDIUMCVSS 4.3fixed in 85.0.4183.83≥ unspecified, < 85.0.4183.832020-09-21
CVE-2020-6570 [MEDIUM] CWE-200 CVE-2020-6570: Information leakage in WebRTC in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to ob Information leakage in WebRTC in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to obtain potentially sensitive information via a crafted WebRTC interaction.
nvd
CVE-2014-1701P4MEDIUMCVSS 4.3≤ 33.0.1750.146v33.0.1750.0+105 more2014-03-16
CVE-2014-1701 [MEDIUM] CWE-79 CVE-2014-1701: The GenerateFunction function in bindings/scripts/code_generator_v8.pm in Blink, as used in Google C The GenerateFunction function in bindings/scripts/code_generator_v8.pm in Blink, as used in Google Chrome before 33.0.1750.149, does not implement a certain cross-origin restriction for the EventTarget::dispatchEvent function, which allows remote attackers to conduct Universal XSS (UXSS) attacks via vectors involving events.
nvd
CVE-2017-5041P4MEDIUMCVSS 4.3≤ 57.0.2987.982017-04-24
CVE-2017-5041 [MEDIUM] CWE-20 CVE-2017-5041: Google Chrome prior to 57.0.2987.100 incorrectly handled back-forward navigation, which allowed a re Google Chrome prior to 57.0.2987.100 incorrectly handled back-forward navigation, which allowed a remote attacker to display incorrect information for a site via a crafted HTML page.
nvd
CVE-2020-6440P4MEDIUMCVSS 4.3fixed in 81.0.4044.92≥ unspecified, < 81.0.4044.922020-04-13
CVE-2020-6440 [MEDIUM] CVE-2020-6440: Inappropriate implementation in extensions in Google Chrome prior to 81.0.4044.92 allowed an attacke Inappropriate implementation in extensions in Google Chrome prior to 81.0.4044.92 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information via a crafted Chrome Extension.
nvd
Google Chrome vulnerabilities | cvebase