cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2

Vulnerabilities

Page 279 of 292
CVE-2011-1815P4MEDIUMCVSS 4.3fixed in 12.0.742.912011-06-09
CVE-2011-1815 [MEDIUM] CWE-79 CVE-2011-1815: Google Chrome before 12.0.742.91 allows remote attackers to inject script into a tab page via vector Google Chrome before 12.0.742.91 allows remote attackers to inject script into a tab page via vectors related to extensions.
nvd
CVE-2018-17473P4MEDIUMCVSS 4.3fixed in 70.0.3538.67≥ unspecified, < 70.0.3538.672018-11-14
CVE-2018-17473 [MEDIUM] CVE-2018-17473: Incorrect handling of confusable characters in Omnibox in Google Chrome prior to 70.0.3538.67 allowe Incorrect handling of confusable characters in Omnibox in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.
nvd
CVE-2017-5118P4MEDIUMCVSS 4.3fixed in 61.0.3163.79fixed in 61.0.3163.812017-10-27
CVE-2017-5118 [MEDIUM] CWE-732 CVE-2017-5118: Blink in Google Chrome prior to 61.0.3163.79 for Mac, Windows, and Linux, and 61.0.3163.81 for Andro Blink in Google Chrome prior to 61.0.3163.79 for Mac, Windows, and Linux, and 61.0.3163.81 for Android, failed to correctly propagate CSP restrictions to javascript scheme pages, which allowed a remote attacker to bypass content security policy via a crafted HTML page.
nvd
CVE-2017-5083P4MEDIUMCVSS 4.3fixed in 59.0.3071.86fixed in 59.0.3071.922017-10-27
CVE-2017-5083 [MEDIUM] CWE-20 CVE-2017-5083: Inappropriate implementation in Blink in Google Chrome prior to 59.0.3071.86 for Mac, Windows, and L Inappropriate implementation in Blink in Google Chrome prior to 59.0.3071.86 for Mac, Windows, and Linux, and 59.0.3071.92 for Android, allowed a remote attacker to display UI on a non attacker controlled tab via a crafted HTML page.
nvd
CVE-2018-18348P4MEDIUMCVSS 4.3fixed in 71.0.3578.80≥ unspecified, < 71.0.3578.802018-12-11
CVE-2018-18348 [MEDIUM] CVE-2018-18348: Incorrect handling of bidirectional domain names with RTL characters in Omnibox in Google Chrome pri Incorrect handling of bidirectional domain names with RTL characters in Omnibox in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.
nvd
CVE-2016-5225P4MEDIUMCVSS 4.3≤ 54.0.2840.992017-01-19
CVE-2016-5225 [MEDIUM] CWE-19 CVE-2016-5225: Blink in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Androi Blink in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android incorrectly handled form actions, which allowed a remote attacker to bypass Content Security Policy via a crafted HTML page.
nvd
CVE-2016-5224P4MEDIUMCVSS 4.3≤ 54.0.2840.992017-01-19
CVE-2016-5224 [MEDIUM] CWE-189 CVE-2016-5224: A timing attack on denormalized floating point arithmetic in SVG filters in Blink in Google Chrome p A timing attack on denormalized floating point arithmetic in SVG filters in Blink in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to bypass the Same Origin Policy via a crafted HTML page.
nvd
CVE-2016-9650P4MEDIUMCVSS 4.3≤ 54.0.2840.992017-01-19
CVE-2016-9650 [MEDIUM] CWE-19 CVE-2016-9650: Blink in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Androi Blink in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android incorrectly handled iframes, which allowed a remote attacker to bypass a no-referrer policy via a crafted HTML page.
nvd
CVE-2021-21184P4MEDIUMCVSS 4.3fixed in 89.0.4389.72≥ unspecified, < 89.0.4389.722021-03-09
CVE-2021-21184 [MEDIUM] CWE-346 CVE-2021-21184: Inappropriate implementation in performance APIs in Google Chrome prior to 89.0.4389.72 allowed a re Inappropriate implementation in performance APIs in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2010-0556P4MEDIUMCVSS 4.3≤ 4.0.249.78v0.2.149.27+45 more2010-02-18
CVE-2010-0556 [MEDIUM] CWE-255 CVE-2010-0556: browser/login/login_prompt.cc in Google Chrome before 4.0.249.89 populates an authentication dialog browser/login/login_prompt.cc in Google Chrome before 4.0.249.89 populates an authentication dialog with credentials that were stored by Password Manager for a different web site, which allows user-assisted remote HTTP servers to obtain sensitive information via a URL that requires authentication, as demonstrated by a URL in the SRC attribute of an IMG
nvd
CVE-2021-21183P4MEDIUMCVSS 4.3fixed in 89.0.4389.72≥ unspecified, < 89.0.4389.722021-03-09
CVE-2021-21183 [MEDIUM] CWE-346 CVE-2021-21183: Inappropriate implementation in performance APIs in Google Chrome prior to 89.0.4389.72 allowed a re Inappropriate implementation in performance APIs in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2016-1614P4MEDIUMCVSS 4.3≤ 47.0.2526.1062016-01-25
CVE-2016-1614 [MEDIUM] CWE-200 CVE-2016-1614: The UnacceleratedImageBufferSurface class in WebKit/Source/platform/graphics/UnacceleratedImageBuffe The UnacceleratedImageBufferSurface class in WebKit/Source/platform/graphics/UnacceleratedImageBufferSurface.cpp in Blink, as used in Google Chrome before 48.0.2564.82, mishandles the initialization mode, which allows remote attackers to obtain sensitive information from process memory via a crafted web site.
nvd
CVE-2011-2785P4MEDIUMCVSS 4.3fixed in 13.0.782.1072011-08-03
CVE-2011-2785 [MEDIUM] CWE-20 CVE-2011-2785: The extensions implementation in Google Chrome before 13.0.782.107 does not properly validate the UR The extensions implementation in Google Chrome before 13.0.782.107 does not properly validate the URL for the home page, which allows remote attackers to have an unspecified impact via a crafted extension.
nvd
CVE-2019-5833P4MEDIUMCVSS 4.3fixed in 75.0.3770.80≥ unspecified, < 75.0.3770.802019-06-27
CVE-2019-5833 [MEDIUM] CVE-2019-5833: Incorrect dialog box scoping in browser in Google Chrome on Android prior to 75.0.3770.80 allowed a Incorrect dialog box scoping in browser in Google Chrome on Android prior to 75.0.3770.80 allowed a remote attacker to display misleading security UI via a crafted HTML page.
nvd
CVE-2018-16087P4MEDIUMCVSS 4.3fixed in 69.0.3497.81≥ unspecified, < 69.0.3497.812019-01-09
CVE-2018-16087 [MEDIUM] CWE-732 CVE-2018-16087: Lack of proper state tracking in Permissions in Google Chrome prior to 69.0.3497.81 allowed a remote Lack of proper state tracking in Permissions in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
nvd
CVE-2016-5188P4MEDIUMCVSS 4.3≤ 53.0.2785.1432016-12-18
CVE-2016-5188 [MEDIUM] CWE-20 CVE-2016-5188: Multiple issues in Blink in Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux allow a Multiple issues in Blink in Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux allow a remote attacker to spoof various parts of browser UI via crafted HTML pages.
nvd
CVE-2019-13716P4MEDIUMCVSS 4.3fixed in 78.0.3904.70≥ unspecified, < 78.0.3904.702019-11-25
CVE-2019-13716 [MEDIUM] CWE-863 CVE-2019-13716: Insufficient policy enforcement in service workers in Google Chrome prior to 78.0.3904.70 allowed a Insufficient policy enforcement in service workers in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
nvd
CVE-2019-13703P4MEDIUMCVSS 4.3fixed in 78.0.3904.70≥ unspecified, < 78.0.3904.702019-11-25
CVE-2019-13703 [MEDIUM] CWE-290 CVE-2019-13703: Insufficient policy enforcement in the Omnibox in Google Chrome on Android prior to 78.0.3904.70 all Insufficient policy enforcement in the Omnibox in Google Chrome on Android prior to 78.0.3904.70 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd
CVE-2019-13701P4MEDIUMCVSS 4.3fixed in 78.0.3904.70≥ unspecified, < 78.0.3904.702019-11-25
CVE-2019-13701 [MEDIUM] CWE-290 CVE-2019-13701: Incorrect implementation in navigation in Google Chrome prior to 78.0.3904.70 allowed a remote attac Incorrect implementation in navigation in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd
CVE-2011-3907P4MEDIUMCVSS 4.3fixed in 16.0.912.632011-12-13
CVE-2011-3907 [MEDIUM] CWE-20 CVE-2011-3907: The view-source feature in Google Chrome before 16.0.912.63 allows remote attackers to spoof the URL The view-source feature in Google Chrome before 16.0.912.63 allows remote attackers to spoof the URL bar via unspecified vectors.
nvd
Google Chrome vulnerabilities | cvebase