cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2

Vulnerabilities

Page 282 of 292
CVE-2010-3417P4MEDIUMCVSS 5.0fixed in 6.0.472.592010-09-16
CVE-2010-3417 [MEDIUM] CWE-200 CVE-2010-3417: Google Chrome before 6.0.472.59 does not prompt the user before granting access to the extension his Google Chrome before 6.0.472.59 does not prompt the user before granting access to the extension history, which allows attackers to obtain potentially sensitive information via unspecified vectors.
nvd
CVE-2011-0482P4MEDIUMCVSS 4.3fixed in 8.0.552.2372011-01-14
CVE-2011-0482 [MEDIUM] CWE-704 CVE-2011-0482: Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly perform a cast of Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly perform a cast of an unspecified variable during handling of anchors, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted HTML document.
nvd
CVE-2011-3970P4MEDIUMCVSS 4.3fixed in 17.0.963.462012-02-09
CVE-2011-3970 [MEDIUM] CWE-125 CVE-2011-3970: libxslt, as used in Google Chrome before 17.0.963.46, allows remote attackers to cause a denial of s libxslt, as used in Google Chrome before 17.0.963.46, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2026-11290P4MEDIUMCVSS 5.0fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-05
CVE-2026-11290 [MEDIUM] CWE-472 CVE-2026-11290: Integer overflow in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a local attac Integer overflow in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a local attacker to cause a denial of service via a malicious file. (Chromium security severity: Low)
nvd
CVE-2011-3057P4MEDIUMCVSS 4.3fixed in 17.0.963.832012-03-22
CVE-2011-3057 [MEDIUM] CWE-125 CVE-2011-3057: Google V8, as used in Google Chrome before 17.0.963.83, allows remote attackers to cause a denial of Google V8, as used in Google Chrome before 17.0.963.83, allows remote attackers to cause a denial of service via vectors that trigger an invalid read operation.
nvd
CVE-2011-3058P4MEDIUMCVSS 4.3fixed in 18.0.1025.1422012-03-30
CVE-2011-3058 [MEDIUM] CWE-79 CVE-2011-3058: Google Chrome before 18.0.1025.142 does not properly handle the EUC-JP encoding system, which might Google Chrome before 18.0.1025.142 does not properly handle the EUC-JP encoding system, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors.
nvd
CVE-2013-0897P4MEDIUMCVSS 4.3fixed in 25.0.1364.97fixed in 25.0.1364.992013-02-23
CVE-2013-0897 [MEDIUM] CWE-193 CVE-2013-0897: Off-by-one error in the PDF functionality in Google Chrome before 25.0.1364.97 on Windows and Linux, Off-by-one error in the PDF functionality in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allows remote attackers to cause a denial of service via a crafted document.
nvd
CVE-2010-1236P4MEDIUMCVSS 4.3≤ 4.1.249.1035v0.1.38.1+221 more2010-04-01
CVE-2010-1236 [MEDIUM] CWE-79 CVE-2010-1236: The protocolIs function in platform/KURLGoogle.cpp in WebCore in WebKit before r55822, as used in Go The protocolIs function in platform/KURLGoogle.cpp in WebCore in WebKit before r55822, as used in Google Chrome before 4.1.249.1036 and Flock Browser 3.x before 3.0.0.4112, does not properly handle whitespace at the beginning of a URL, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted javascript: URL, as demonstr
nvd
CVE-2013-2849P4MEDIUMCVSS 4.3≤ 27.0.1453.91v27.0.1453.0+69 more2013-05-22
CVE-2013-2849 [MEDIUM] CWE-79 CVE-2013-2849: Multiple cross-site scripting (XSS) vulnerabilities in Google Chrome before 27.0.1453.93 allow user- Multiple cross-site scripting (XSS) vulnerabilities in Google Chrome before 27.0.1453.93 allow user-assisted remote attackers to inject arbitrary web script or HTML via vectors involving a (1) drag-and-drop or (2) copy-and-paste operation.
nvd
CVE-2012-2849P4MEDIUMCVSS 4.3≤ 21.0.1180.56v21.0.1180.0+25 more2012-08-06
CVE-2012-2849 [MEDIUM] CWE-189 CVE-2012-2849: Off-by-one error in the GIF decoder in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and Off-by-one error in the GIF decoder in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted image.
nvd
CVE-2011-2795P4MEDIUMCVSS 4.3fixed in 13.0.782.1072011-08-03
CVE-2011-2795 [MEDIUM] CVE-2011-2795: Google Chrome before 13.0.782.107 does not prevent calls to functions in other frames, which allows Google Chrome before 13.0.782.107 does not prevent calls to functions in other frames, which allows remote attackers to bypass intended access restrictions via a crafted web site, related to a "cross-frame function leak."
nvd
CVE-2015-6782P4MEDIUMCVSS 4.3≤ 46.0.2490.862015-12-06
CVE-2015-6782 [MEDIUM] CWE-20 CVE-2015-6782: The Document::open function in WebKit/Source/core/dom/Document.cpp in Google Chrome before 47.0.2526 The Document::open function in WebKit/Source/core/dom/Document.cpp in Google Chrome before 47.0.2526.73 does not ensure that page-dismissal event handling is compatible with modal-dialog blocking, which makes it easier for remote attackers to spoof Omnibox content via a crafted web site.
nvd
CVE-2012-2865P4MEDIUMCVSS 4.3≤ 21.0.1180.88v21.0.1180.0+50 more2012-08-31
CVE-2012-2865 [MEDIUM] CWE-119 CVE-2012-2865: Google Chrome before 21.0.1180.89 does not properly perform line breaking, which allows remote attac Google Chrome before 21.0.1180.89 does not properly perform line breaking, which allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted document.
nvd
CVE-2013-6626P4MEDIUMCVSS 4.3≤ 31.0.1650.47v31.0.1650.0+42 more2013-11-13
CVE-2013-6626 [MEDIUM] CVE-2013-6626: The WebContentsImpl::AttachInterstitialPage function in content/browser/web_contents/web_contents_im The WebContentsImpl::AttachInterstitialPage function in content/browser/web_contents/web_contents_impl.cc in Google Chrome before 31.0.1650.48 does not cancel JavaScript dialogs upon generating an interstitial warning, which allows remote attackers to spoof the address bar via a crafted web site.
nvd
CVE-2011-1810P4MEDIUMCVSS 4.3fixed in 12.0.742.912011-06-09
CVE-2011-1810 [MEDIUM] CWE-200 CVE-2011-1810: The Cascading Style Sheets (CSS) implementation in Google Chrome before 12.0.742.91 does not properl The Cascading Style Sheets (CSS) implementation in Google Chrome before 12.0.742.91 does not properly restrict access to the visit history, which allows remote attackers to obtain sensitive information via unspecified vectors.
nvd
CVE-2013-6628P4MEDIUMCVSS 4.3≤ 31.0.1650.47v31.0.1650.0+42 more2013-11-13
CVE-2013-6628 [MEDIUM] CVE-2013-6628: net/socket/ssl_client_socket_nss.cc in the TLS implementation in Google Chrome before 31.0.1650.48 d net/socket/ssl_client_socket_nss.cc in the TLS implementation in Google Chrome before 31.0.1650.48 does not ensure that a server's X.509 certificate is the same during renegotiation as it was before renegotiation, which might allow remote web servers to interfere with trust relationships by renegotiating a session.
nvd
CVE-2010-0643P4MEDIUMCVSS 4.3≤ 4.0.249.78v0.2.149.27+45 more2010-02-18
CVE-2010-0643 [MEDIUM] CWE-200 CVE-2010-0643: Google Chrome before 4.0.249.89 attempts to make direct connections to web sites when all configured Google Chrome before 4.0.249.89 attempts to make direct connections to web sites when all configured proxy servers are unavailable, which allows remote HTTP servers to obtain potentially sensitive information about the identity of a client user via standard HTTP logging, as demonstrated by a proxy server that was configured for the purpose of anonymit
nvd
CVE-2022-3312P4MEDIUMCVSS 4.6fixed in 106.0.5249.62≥ unspecified, < 106.0.5249.622022-11-01
CVE-2022-3312 [MEDIUM] CWE-306 CVE-2022-3312: Insufficient validation of untrusted input in VPN in Google Chrome on ChromeOS prior to 106.0.5249.6 Insufficient validation of untrusted input in VPN in Google Chrome on ChromeOS prior to 106.0.5249.62 allowed a local attacker to bypass managed device restrictions via physical access to the device. (Chromium security severity: Medium)
nvd
CVE-2018-6068P4MEDIUMCVSS 4.3fixed in 65.0.3325.146≥ unspecified, < 65.0.3325.1462018-11-14
CVE-2018-6068 [MEDIUM] CWE-20 CVE-2018-6068: Object lifecycle issue in Chrome Custom Tab in Google Chrome prior to 65.0.3325.146 allowed a remote Object lifecycle issue in Chrome Custom Tab in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd
CVE-2013-2869P4MEDIUMCVSS 4.3≤ 28.0.1500.70v28.0.1500.0+61 more2013-07-10
CVE-2013-2869 [MEDIUM] CWE-119 CVE-2013-2869: Google Chrome before 28.0.1500.71 allows remote attackers to cause a denial of service (out-of-bound Google Chrome before 28.0.1500.71 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted JPEG2000 image.
nvd