Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2
Vulnerabilities
Page 277 of 292
CVE-2011-2850P4MEDIUMCVSS 5.0fixed in 14.0.835.1632011-09-19
CVE-2011-2850 [MEDIUM] CWE-125 CVE-2011-2850: Google Chrome before 14.0.835.163 does not properly handle Khmer characters, which allows remote att
Google Chrome before 14.0.835.163 does not properly handle Khmer characters, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2011-2858P4MEDIUMCVSS 5.0fixed in 14.0.835.1632011-09-19
CVE-2011-2858 [MEDIUM] CWE-125 CVE-2011-2858: Google Chrome before 14.0.835.163 does not properly handle triangle arrays, which allows remote atta
Google Chrome before 14.0.835.163 does not properly handle triangle arrays, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2013-2848P4MEDIUMCVSS 5.0≤ 27.0.1453.91v27.0.1453.0+69 more2013-05-22
CVE-2013-2848 [MEDIUM] CWE-200 CVE-2013-2848: The XSS Auditor in Google Chrome before 27.0.1453.93 might allow remote attackers to obtain sensitiv
The XSS Auditor in Google Chrome before 27.0.1453.93 might allow remote attackers to obtain sensitive information via unspecified vectors.
nvd
CVE-2011-2843P4MEDIUMCVSS 5.0fixed in 14.0.835.1632011-09-19
CVE-2011-2843 [MEDIUM] CWE-125 CVE-2011-2843: Google Chrome before 14.0.835.163 does not properly handle media buffers, which allows remote attack
Google Chrome before 14.0.835.163 does not properly handle media buffers, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2011-3972P4MEDIUMCVSS 5.0fixed in 17.0.963.462012-02-09
CVE-2011-3972 [MEDIUM] CWE-787 CVE-2011-3972: The shader translator implementation in Google Chrome before 17.0.963.46 allows remote attackers to
The shader translator implementation in Google Chrome before 17.0.963.46 allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2009-0276P4MEDIUMCVSS 5.0≤ 1.0.154.43v0.2.152.1+10 more2009-02-03
CVE-2009-0276 [MEDIUM] CVE-2009-0276: Cross-domain vulnerability in the V8 JavaScript engine in Google Chrome before 1.0.154.46 allows rem
Cross-domain vulnerability in the V8 JavaScript engine in Google Chrome before 1.0.154.46 allows remote attackers to bypass the Same Origin Policy via a crafted script that accesses another frame and reads its full URL and possibly other sensitive information, or modifies the URL of this frame.
nvd
CVE-2011-3906P4MEDIUMCVSS 5.0fixed in 16.0.912.632011-12-13
CVE-2011-3906 [MEDIUM] CWE-125 CVE-2011-3906: The PDF parser in Google Chrome before 16.0.912.63 allows remote attackers to cause a denial of serv
The PDF parser in Google Chrome before 16.0.912.63 allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2013-2878P4MEDIUMCVSS 5.0≤ 28.0.1500.70v28.0.1500.0+61 more2013-07-10
CVE-2013-2878 [MEDIUM] CWE-119 CVE-2013-2878: Google Chrome before 28.0.1500.71 allows remote attackers to cause a denial of service (out-of-bound
Google Chrome before 28.0.1500.71 allows remote attackers to cause a denial of service (out-of-bounds read) via vectors related to the handling of text.
nvd
CVE-2013-0917P4MEDIUMCVSS 5.0≤ 26.0.1410.42v26.0.1410.0+40 more2013-03-28
CVE-2013-0917 [MEDIUM] CWE-119 CVE-2013-0917: The URL loader in Google Chrome before 26.0.1410.43 allows remote attackers to cause a denial of ser
The URL loader in Google Chrome before 26.0.1410.43 allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2013-0833P4MEDIUMCVSS 5.0≤ 24.0.1312.51v24.0.1272.0+119 more2013-01-15
CVE-2013-0833 [MEDIUM] CWE-119 CVE-2013-0833: Google Chrome before 24.0.1312.52 allows remote attackers to cause a denial of service (out-of-bound
Google Chrome before 24.0.1312.52 allows remote attackers to cause a denial of service (out-of-bounds read) via vectors related to printing.
nvd
CVE-2012-5110P4MEDIUMCVSS 5.0≤ 22.0.1229.91v22.0.1229.0+54 more2012-10-09
CVE-2012-5110 [MEDIUM] CWE-125 CVE-2012-5110: The compositor in Google Chrome before 22.0.1229.92 allows remote attackers to cause a denial of ser
The compositor in Google Chrome before 22.0.1229.92 allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2012-2884P4MEDIUMCVSS 5.0≤ 22.0.1229.78v22.0.1229.0+51 more2012-09-26
CVE-2012-2884 [MEDIUM] CWE-119 CVE-2012-2884: Skia, as used in Google Chrome before 22.0.1229.79, allows remote attackers to cause a denial of ser
Skia, as used in Google Chrome before 22.0.1229.79, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2012-5152P4MEDIUMCVSS 5.0≤ 24.0.1312.51v24.0.1272.0+119 more2013-01-15
CVE-2012-5152 [MEDIUM] CWE-119 CVE-2012-5152: Google Chrome before 24.0.1312.52 allows remote attackers to cause a denial of service (out-of-bound
Google Chrome before 24.0.1312.52 allows remote attackers to cause a denial of service (out-of-bounds read) via vectors involving seek operations on video data.
nvd
CVE-2014-3162P4MEDIUMCVSS 5.0v36.0.1985.1v36.0.1985.2+101 more2014-07-20
CVE-2014-3162 [MEDIUM] CVE-2014-3162: Multiple unspecified vulnerabilities in Google Chrome before 36.0.1985.125 allow attackers to cause
Multiple unspecified vulnerabilities in Google Chrome before 36.0.1985.125 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2010-3118P4MEDIUMCVSS 5.0fixed in 5.0.375.1272010-08-24
CVE-2010-3118 [MEDIUM] CWE-200 CVE-2010-3118: The autosuggest feature in the Omnibox implementation in Google Chrome before 5.0.375.127 does not a
The autosuggest feature in the Omnibox implementation in Google Chrome before 5.0.375.127 does not anticipate entry of passwords, which might allow remote attackers to obtain sensitive information by reading the network traffic generated by this feature.
nvd
CVE-2012-2846P4MEDIUMCVSS 5.0≤ 21.0.1180.56v21.0.1180.0+22 more2012-08-06
CVE-2012-2846 [MEDIUM] CVE-2012-2846: Google Chrome before 21.0.1180.57 on Linux does not properly isolate renderer processes, which allow
Google Chrome before 21.0.1180.57 on Linux does not properly isolate renderer processes, which allows remote attackers to cause a denial of service (cross-process interference) via unspecified vectors.
nvd
CVE-2012-2822P4MEDIUMCVSS 5.0≤ 20.0.1132.42v20.0.1132.0+41 more2012-06-27
CVE-2012-2822 [MEDIUM] CVE-2012-2822: The PDF functionality in Google Chrome before 20.0.1132.43 allows remote attackers to cause a denial
The PDF functionality in Google Chrome before 20.0.1132.43 allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2012-4903P4MEDIUMCVSS 5.0≤ 18.0.10253062012-09-13
CVE-2012-4903 [MEDIUM] CWE-264 CVE-2012-4903: Google Chrome before 18.0.1025308 on Android does not properly restrict access to file: URLs, which
Google Chrome before 18.0.1025308 on Android does not properly restrict access to file: URLs, which allows remote attackers to obtain sensitive information via unspecified vectors, as demonstrated by obtaining credential data, a different vulnerability than CVE-2012-4906.
nvd
CVE-2010-0651P4MEDIUMCVSS 4.3≤ 4.0.249.782010-02-18
CVE-2010-0651 [MEDIUM] CWE-200 CVE-2010-0651: WebKit before r52784, as used in Google Chrome before 4.0.249.78 and Apple Safari before 4.0.5, perm
WebKit before r52784, as used in Google Chrome before 4.0.249.78 and Apple Safari before 4.0.5, permits cross-origin loading of CSS stylesheets even when the stylesheet download has an incorrect MIME type and the stylesheet document is malformed, which allows remote attackers to obtain sensitive information via a crafted document.
nvd
CVE-2011-3960P4MEDIUMCVSS 4.3fixed in 17.0.963.462012-02-09
CVE-2011-3960 [MEDIUM] CWE-125 CVE-2011-3960: Google Chrome before 17.0.963.46 does not properly decode audio data, which allows remote attackers
Google Chrome before 17.0.963.46 does not properly decode audio data, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd