Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2
Vulnerabilities
Page 284 of 292
CVE-2010-4488P4MEDIUMCVSS 5.0≤ 8.0.552.2142010-12-07
CVE-2010-4488 [MEDIUM] CWE-287 CVE-2010-4488: Google Chrome before 8.0.552.215 does not properly handle HTTP proxy authentication, which allows re
Google Chrome before 8.0.552.215 does not properly handle HTTP proxy authentication, which allows remote attackers to cause a denial of service (application crash) via unspecified vectors.
nvd
CVE-2013-0835P4MEDIUMCVSS 5.0≤ 24.0.1312.51v24.0.1272.0+110 more2013-01-15
CVE-2013-0835 [MEDIUM] CVE-2013-0835: Unspecified vulnerability in the Geolocation implementation in Google Chrome before 24.0.1312.52 all
Unspecified vulnerability in the Geolocation implementation in Google Chrome before 24.0.1312.52 allows remote attackers to cause a denial of service (application crash) via unknown vectors.
nvd
CVE-2010-1232P4MEDIUMCVSS 5.0≤ 4.1.249.1035v0.2.149.27+81 more2010-04-01
CVE-2010-1232 [MEDIUM] CWE-399 CVE-2010-1232: Google Chrome before 4.1.249.1036 allows remote attackers to cause a denial of service (memory error
Google Chrome before 4.1.249.1036 allows remote attackers to cause a denial of service (memory error) or possibly have unspecified other impact via a malformed SVG document.
nvd
CVE-2009-3268P4MEDIUMCVSS 5.0≤ 1.0.154.48v0.2.149.27+15 more2009-09-18
CVE-2009-3268 [MEDIUM] CVE-2009-3268: Google Chrome 1.0.154.48 and earlier allows remote attackers to cause a denial of service (CPU consu
Google Chrome 1.0.154.48 and earlier allows remote attackers to cause a denial of service (CPU consumption) via an automatically submitted form containing a KEYGEN element, a related issue to CVE-2009-1828.
nvd
CVE-2009-2955P4MEDIUMCVSS 5.0≤ 1.0.154.48v0.2.149.27+15 more2009-08-24
CVE-2009-2955 [MEDIUM] CVE-2009-2955: Google Chrome 1.0.154.48 and earlier allows remote attackers to cause a denial of service (CPU consu
Google Chrome 1.0.154.48 and earlier allows remote attackers to cause a denial of service (CPU consumption and application hang) via JavaScript code with a long string value for the hash property (aka location.hash), a related issue to CVE-2008-5715.
nvd
CVE-2012-2870P4MEDIUMCVSS 4.3≤ 21.0.1180.88v21.0.1180.0+50 more2012-08-31
CVE-2012-2870 [MEDIUM] CWE-399 CVE-2012-2870: libxslt 1.1.26 and earlier, as used in Google Chrome before 21.0.1180.89, does not properly manage m
libxslt 1.1.26 and earlier, as used in Google Chrome before 21.0.1180.89, does not properly manage memory, which might allow remote attackers to cause a denial of service (application crash) via a crafted XSLT expression that is not properly identified during XPath navigation, related to (1) the xsltCompileLocationPathPattern function in libxslt/patte
nvd
CVE-2011-3027P4MEDIUMCVSS 4.3fixed in 17.0.963.562012-02-16
CVE-2011-3027 [MEDIUM] CWE-704 CVE-2011-3027: Google Chrome before 17.0.963.56 does not properly perform a cast of an unspecified variable during
Google Chrome before 17.0.963.56 does not properly perform a cast of an unspecified variable during handling of columns, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted document.
nvd
CVE-2011-2800P4MEDIUMCVSS 4.3fixed in 13.0.782.1072011-08-03
CVE-2011-2800 [MEDIUM] CWE-200 CVE-2011-2800: Google Chrome before 13.0.782.107 allows remote attackers to obtain potentially sensitive informatio
Google Chrome before 13.0.782.107 allows remote attackers to obtain potentially sensitive information about client-side redirect targets via a crafted web site.
nvd
CVE-2010-2295P4MEDIUMCVSS 4.3fixed in 5.0.375.702010-06-15
CVE-2010-2295 [MEDIUM] CVE-2010-2295: page/EventHandler.cpp in WebCore in WebKit in Google Chrome before 5.0.375.70 does not properly hand
page/EventHandler.cpp in WebCore in WebKit in Google Chrome before 5.0.375.70 does not properly handle a change of the focused frame during the dispatching of keydown, which allows user-assisted remote attackers to redirect keystrokes via a crafted HTML document, aka rdar problem 7018610. NOTE: this might overlap CVE-2010-1422.
nvd
CVE-2011-3962P4MEDIUMCVSS 4.3fixed in 17.0.963.462012-02-09
CVE-2011-3962 [MEDIUM] CWE-125 CVE-2011-3962: Google Chrome before 17.0.963.46 does not properly perform path clipping, which allows remote attack
Google Chrome before 17.0.963.46 does not properly perform path clipping, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2011-3063P4MEDIUMCVSS 4.3fixed in 18.0.1025.1422012-03-30
CVE-2011-3063 [MEDIUM] CWE-20 CVE-2011-3063: Google Chrome before 18.0.1025.142 does not properly validate the renderer's navigation requests, wh
Google Chrome before 18.0.1025.142 does not properly validate the renderer's navigation requests, which has unspecified impact and remote attack vectors.
nvd
CVE-2011-2345P4MEDIUMCVSS 4.3fixed in 12.0.742.1122011-06-29
CVE-2011-2345 [MEDIUM] CWE-125 CVE-2011-2345: The NPAPI implementation in Google Chrome before 12.0.742.112 does not properly handle strings, whic
The NPAPI implementation in Google Chrome before 12.0.742.112 does not properly handle strings, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2012-2879P4MEDIUMCVSS 4.3≤ 22.0.1229.78v22.0.1229.0+51 more2012-09-26
CVE-2012-2879 [MEDIUM] CWE-119 CVE-2012-2879: Google Chrome before 22.0.1229.79 allows remote attackers to cause a denial of service (DOM topology
Google Chrome before 22.0.1229.79 allows remote attackers to cause a denial of service (DOM topology corruption) via a crafted document.
nvd
CVE-2012-2872P4MEDIUMCVSS 4.3≤ 21.0.1180.88v21.0.1180.0+50 more2012-08-31
CVE-2012-2872 [MEDIUM] CWE-79 CVE-2012-2872: Cross-site scripting (XSS) vulnerability in an SSL interstitial page in Google Chrome before 21.0.11
Cross-site scripting (XSS) vulnerability in an SSL interstitial page in Google Chrome before 21.0.1180.89 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2011-3025P4MEDIUMCVSS 4.3fixed in 17.0.963.562012-02-16
CVE-2011-3025 [MEDIUM] CWE-125 CVE-2011-3025: Google Chrome before 17.0.963.56 does not properly parse H.264 data, which allows remote attackers t
Google Chrome before 17.0.963.56 does not properly parse H.264 data, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2011-2848P4MEDIUMCVSS 4.3fixed in 14.0.835.1632011-09-19
CVE-2011-2848 [MEDIUM] CWE-20 CVE-2011-2848: Google Chrome before 14.0.835.163 allows user-assisted remote attackers to spoof the URL bar via vec
Google Chrome before 14.0.835.163 allows user-assisted remote attackers to spoof the URL bar via vectors related to the forward button.
nvd
CVE-2014-9646P4MEDIUMCVSS 4.6≤ 40.0.2214.852015-01-27
CVE-2014-9646 [MEDIUM] CWE-264 CVE-2014-9646: Unquoted Windows search path vulnerability in the GoogleChromeDistribution::DoPostUninstallOperation
Unquoted Windows search path vulnerability in the GoogleChromeDistribution::DoPostUninstallOperations function in installer/util/google_chrome_distribution.cc in the uninstall-survey feature in Google Chrome before 40.0.2214.91 allows local users to gain privileges via a Trojan horse program in the %SYSTEMDRIVE% directory, as demonstrated by program.e
nvd
CVE-2012-2848P4MEDIUMCVSS 4.3≤ 21.0.1180.56v21.0.1180.0+25 more2012-08-06
CVE-2012-2848 [MEDIUM] CWE-264 CVE-2012-2848: The drag-and-drop implementation in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and bef
The drag-and-drop implementation in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, allows user-assisted remote attackers to bypass intended file access restrictions via a crafted web site.
nvd
CVE-2010-2106P4MEDIUMCVSS 4.3fixed in 5.0.375.552010-05-28
CVE-2010-2106 [MEDIUM] CVE-2010-2106: Unspecified vulnerability in Google Chrome before 5.0.375.55 might allow remote attackers to spoof t
Unspecified vulnerability in Google Chrome before 5.0.375.55 might allow remote attackers to spoof the URL bar via vectors involving unload event handlers.
nvd
CVE-2011-3877P4MEDIUMCVSS 4.3fixed in 15.0.874.1022011-10-25
CVE-2011-3877 [MEDIUM] CWE-79 CVE-2011-3877: Cross-site scripting (XSS) vulnerability in the appcache internals page in Google Chrome before 15.0
Cross-site scripting (XSS) vulnerability in the appcache internals page in Google Chrome before 15.0.874.102 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd