cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2

Vulnerabilities

Page 278 of 292
CVE-2015-3336P4MEDIUMCVSS 4.3≤ 42.0.2311.602015-04-19
CVE-2015-3336 [MEDIUM] CWE-264 CVE-2015-3336: Google Chrome before 42.0.2311.90 does not always ask the user before proceeding with CONTENT_SETTIN Google Chrome before 42.0.2311.90 does not always ask the user before proceeding with CONTENT_SETTINGS_TYPE_FULLSCREEN and CONTENT_SETTINGS_TYPE_MOUSELOCK changes, which allows user-assisted remote attackers to cause a denial of service (UI disruption) by constructing a crafted HTML document containing JavaScript code with requestFullScreen and reques
nvd
CVE-2013-6623P4MEDIUMCVSS 4.3≤ 31.0.1650.47v31.0.1650.0+42 more2013-11-13
CVE-2013-6623 [MEDIUM] CWE-119 CVE-2013-6623: The SVG implementation in Blink, as used in Google Chrome before 31.0.1650.48, allows remote attacke The SVG implementation in Blink, as used in Google Chrome before 31.0.1650.48, allows remote attackers to cause a denial of service (out-of-bounds read) by leveraging the use of tree order, rather than transitive dependency order, for layout.
nvd
CVE-2018-6047P4MEDIUMCVSS 4.3fixed in 64.0.3282.119≥ unspecified, < 64.0.3282.1192018-09-25
CVE-2018-6047 [MEDIUM] CWE-20 CVE-2018-6047: Insufficient policy enforcement in WebGL in Google Chrome prior to 64.0.3282.119 allowed a remote at Insufficient policy enforcement in WebGL in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially leak user redirect URL via a crafted HTML page.
nvd
CVE-2011-1107P4MEDIUMCVSS 4.3fixed in 9.0.597.1072011-03-01
CVE-2011-1107 [MEDIUM] CVE-2011-1107: Unspecified vulnerability in Google Chrome before 9.0.597.107 allows remote attackers to spoof the U Unspecified vulnerability in Google Chrome before 9.0.597.107 allows remote attackers to spoof the URL bar via unknown vectors.
nvd
CVE-2012-2886P4MEDIUMCVSS 4.3≤ 22.0.1229.78v22.0.1229.0+51 more2012-09-26
CVE-2012-2886 [MEDIUM] CWE-79 CVE-2012-2886: Cross-site scripting (XSS) vulnerability in Google Chrome before 22.0.1229.79 allows remote attacker Cross-site scripting (XSS) vulnerability in Google Chrome before 22.0.1229.79 allows remote attackers to inject arbitrary web script or HTML via vectors related to the Google V8 bindings, aka "Universal XSS (UXSS)."
nvd
CVE-2009-3263P4MEDIUMCVSS 4.3v2.0.156.1v2.0.157.0+19 more2009-09-18
CVE-2009-3263 [MEDIUM] CWE-79 CVE-2009-3263: Cross-site scripting (XSS) vulnerability in Google Chrome 2.x and 3.x before 3.0.195.21 allows remot Cross-site scripting (XSS) vulnerability in Google Chrome 2.x and 3.x before 3.0.195.21 allows remote attackers to inject arbitrary web script or HTML via a (1) RSS or (2) Atom feed, related to the rendering of the application/rss+xml content type as XML "active content."
nvd
CVE-2015-6583P4MEDIUMCVSS 4.3≤ 44.0.24032015-09-03
CVE-2015-6583 [MEDIUM] CWE-254 CVE-2015-6583: Google Chrome before 45.0.2454.85 does not display a location bar for a hosted app's window after na Google Chrome before 45.0.2454.85 does not display a location bar for a hosted app's window after navigation away from the installation site, which might make it easier for remote attackers to spoof content via a crafted app, related to browser.cc and hosted_app_browser_controller.cc.
nvd
CVE-2010-4493P4MEDIUMCVSS 4.3fixed in 8.0.552.2152010-12-07
CVE-2010-4493 [MEDIUM] CWE-416 CVE-2010-4493: Use-after-free vulnerability in Google Chrome before 8.0.552.215 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 8.0.552.215 allows remote attackers to cause a denial of service via vectors related to the handling of mouse dragging events.
nvd
CVE-2018-6052P4MEDIUMCVSS 4.3fixed in 64.0.3282.119≥ unspecified, < 64.0.3282.1192018-09-25
CVE-2018-6052 [MEDIUM] CWE-200 CVE-2018-6052: Lack of support for a non standard no-referrer policy value in Blink in Google Chrome prior to 64.0. Lack of support for a non standard no-referrer policy value in Blink in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to obtain referrer details from a web page that had thought it had opted out of sending referrer data.
nvd
CVE-2017-5046P4MEDIUMCVSS 4.3≤ 57.0.2987.75≤ 57.0.2987.1002017-04-24
CVE-2017-5046 [MEDIUM] CVE-2017-5046: V8 in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android V8 in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android had insufficient policy enforcement, which allowed a remote attacker to spoof the location object via a crafted HTML page, related to Blink information disclosure.
nvd
CVE-2016-1626P4MEDIUMCVSS 4.3v48.0.2564.1032016-02-14
CVE-2016-1626 [MEDIUM] CWE-119 CVE-2016-1626: The opj_pi_update_decode_poc function in pi.c in OpenJPEG, as used in PDFium in Google Chrome before The opj_pi_update_decode_poc function in pi.c in OpenJPEG, as used in PDFium in Google Chrome before 48.0.2564.109, miscalculates a certain layer index value, which allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PDF document.
nvd
CVE-2012-5157P4MEDIUMCVSS 4.3≤ 24.0.1312.51v24.0.1272.0+110 more2013-01-15
CVE-2012-5157 [MEDIUM] CWE-119 CVE-2012-5157: Google Chrome before 24.0.1312.52 does not properly handle image data in PDF documents, which allows Google Chrome before 24.0.1312.52 does not properly handle image data in PDF documents, which allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted document.
nvd
CVE-2012-2889P4MEDIUMCVSS 4.3≤ 22.0.1229.78v22.0.1229.0+51 more2012-09-26
CVE-2012-2889 [MEDIUM] CWE-79 CVE-2012-2889: Cross-site scripting (XSS) vulnerability in Google Chrome before 22.0.1229.79 allows remote attacker Cross-site scripting (XSS) vulnerability in Google Chrome before 22.0.1229.79 allows remote attackers to inject arbitrary web script or HTML via vectors involving frames, aka "Universal XSS (UXSS)."
nvd
CVE-2018-6051P4MEDIUMCVSS 4.3fixed in 64.0.3282.119≥ unspecified, < 64.0.3282.1192018-09-25
CVE-2018-6051 [MEDIUM] CWE-79 CVE-2018-6051: XSS Auditor in Google Chrome prior to 64.0.3282.119, did not ensure the reporting URL was in the sam XSS Auditor in Google Chrome prior to 64.0.3282.119, did not ensure the reporting URL was in the same origin as the page it was on, which allowed a remote attacker to obtain referrer details via a crafted HTML page.
nvd
CVE-2018-6048P4MEDIUMCVSS 4.3fixed in 64.0.3282.119≥ unspecified, < 64.0.3282.1192018-09-25
CVE-2018-6048 [MEDIUM] CWE-20 CVE-2018-6048: Insufficient policy enforcement in Blink in Google Chrome prior to 64.0.3282.119 allowed a remote at Insufficient policy enforcement in Blink in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially leak referrer information via a crafted HTML page.
nvd
CVE-2016-1617P4MEDIUMCVSS 4.3≤ 47.0.2526.1062016-01-25
CVE-2016-1617 [MEDIUM] CWE-200 CVE-2016-1617: The CSPSource::schemeMatches function in WebKit/Source/core/frame/csp/CSPSource.cpp in the Content S The CSPSource::schemeMatches function in WebKit/Source/core/frame/csp/CSPSource.cpp in the Content Security Policy (CSP) implementation in Blink, as used in Google Chrome before 48.0.2564.82, does not apply http policies to https URLs and does not apply ws policies to wss URLs, which makes it easier for remote attackers to determine whether a specific
nvd
CVE-2015-1264P4MEDIUMCVSS 4.3≤ 42.0.2311.1522015-05-20
CVE-2015-1264 [MEDIUM] CWE-79 CVE-2015-1264: Cross-site scripting (XSS) vulnerability in Google Chrome before 43.0.2357.65 allows user-assisted r Cross-site scripting (XSS) vulnerability in Google Chrome before 43.0.2357.65 allows user-assisted remote attackers to inject arbitrary web script or HTML via crafted data that is improperly handled by the Bookmarks feature.
nvd
CVE-2015-2239P4MEDIUMCVSS 4.3≤ 40.0.2214.1152015-03-09
CVE-2015-2239 [MEDIUM] CVE-2015-2239: Google Chrome before 41.0.2272.76, when Instant Extended mode is used, does not properly consider th Google Chrome before 41.0.2272.76, when Instant Extended mode is used, does not properly consider the interaction between the "1993 search" features and restore-from-disk RELOAD transitions, which makes it easier for remote attackers to spoof the address bar for a search-results page by leveraging (1) a compromised search engine or (2) an XSS vulnerability in
nvd
CVE-2017-5075P4MEDIUMCVSS 4.3fixed in 59.0.3071.86fixed in 59.0.3071.922017-10-27
CVE-2017-5075 [MEDIUM] CWE-200 CVE-2017-5075: Inappropriate implementation in CSP reporting in Blink in Google Chrome prior to 59.0.3071.86 for Li Inappropriate implementation in CSP reporting in Blink in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac, and 59.0.3071.92 for Android, allowed a remote attacker to obtain the value of url fragments via a crafted HTML page.
nvd
CVE-2011-2845P4MEDIUMCVSS 4.3fixed in 15.0.874.1022011-10-25
CVE-2011-2845 [MEDIUM] CWE-20 CVE-2011-2845: Google Chrome before 15.0.874.102 does not properly handle history data, which allows user-assisted Google Chrome before 15.0.874.102 does not properly handle history data, which allows user-assisted remote attackers to spoof the URL bar via unspecified vectors.
nvd
Google Chrome vulnerabilities | cvebase