Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2
Vulnerabilities
Page 285 of 292
CVE-2011-2786P4MEDIUMCVSS 4.3fixed in 13.0.782.1072011-08-03
CVE-2011-2786 [MEDIUM] CWE-20 CVE-2011-2786: Google Chrome before 13.0.782.107 does not ensure that the speech-input bubble is shown on the produ
Google Chrome before 13.0.782.107 does not ensure that the speech-input bubble is shown on the product's screen, which might make it easier for remote attackers to make audio recordings via a crafted web page containing an INPUT element.
nvd
CVE-2010-1851P4MEDIUMCVSS 4.3v0.1.38.1v0.1.38.2+250 more2010-05-07
CVE-2010-1851 [MEDIUM] CWE-200 CVE-2010-1851: Google Chrome, when the Invisible Hand extension is enabled, uses cookies during background HTTP req
Google Chrome, when the Invisible Hand extension is enabled, uses cookies during background HTTP requests in a possibly unexpected manner, which might allow remote web servers to identify specific persons and their product searches via HTTP request logging, related to a "cross-site data leakage" issue.
nvd
CVE-2010-1992P4MEDIUMCVSS 5.0v1.0.154.482010-05-20
CVE-2010-1992 [MEDIUM] CWE-399 CVE-2010-1992: Google Chrome 1.0.154.48 executes a mail application in situations where an IFRAME element has a mai
Google Chrome 1.0.154.48 executes a mail application in situations where an IFRAME element has a mailto: URL in its SRC attribute, which allows remote attackers to cause a denial of service (excessive application launches) via an HTML document with many IFRAME elements.
nvd
CVE-2010-3413P4MEDIUMCVSS 5.0fixed in 6.0.472.592010-09-16
CVE-2010-3413 [MEDIUM] CVE-2010-3413: Unspecified vulnerability in the pop-up blocking functionality in Google Chrome before 6.0.472.59 al
Unspecified vulnerability in the pop-up blocking functionality in Google Chrome before 6.0.472.59 allows remote attackers to cause a denial of service (application crash) via unknown vectors.
nvd
CVE-2011-1436P4MEDIUMCVSS 5.0fixed in 11.0.696.572011-05-03
CVE-2011-1436 [MEDIUM] CWE-20 CVE-2011-1436: Google Chrome before 11.0.696.57 on Linux does not properly interact with the X Window System, which
Google Chrome before 11.0.696.57 on Linux does not properly interact with the X Window System, which allows remote attackers to cause a denial of service (application crash) via unspecified vectors.
nvd
CVE-2011-3967P4MEDIUMCVSS 5.0fixed in 17.0.963.462012-02-09
CVE-2011-3967 [MEDIUM] CVE-2011-3967: Unspecified vulnerability in Google Chrome before 17.0.963.46 allows remote attackers to cause a den
Unspecified vulnerability in Google Chrome before 17.0.963.46 allows remote attackers to cause a denial of service (application crash) via a crafted certificate.
nvd
CVE-2011-3965P4MEDIUMCVSS 5.0fixed in 17.0.963.462012-02-09
CVE-2011-3965 [MEDIUM] CWE-347 CVE-2011-3965: Google Chrome before 17.0.963.46 does not properly check signatures, which allows remote attackers t
Google Chrome before 17.0.963.46 does not properly check signatures, which allows remote attackers to cause a denial of service (application crash) via unspecified vectors.
nvd
CVE-2011-1059P4MEDIUMCVSS 4.3fixed in 11.0.672.22011-02-22
CVE-2011-1059 [MEDIUM] CWE-416 CVE-2011-1059: Use-after-free vulnerability in WebCore in WebKit before r77705, as used in Google Chrome before 11.
Use-after-free vulnerability in WebCore in WebKit before r77705, as used in Google Chrome before 11.0.672.2 and other products, allows user-assisted remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via vectors that entice a user to resubmit a form, related to improper handling of provisional i
nvd
CVE-2010-2301P4MEDIUMCVSS 4.3fixed in 5.0.375.702010-06-15
CVE-2010-2301 [MEDIUM] CVE-2010-2301: Cross-site scripting (XSS) vulnerability in editing/markup.cpp in WebCore in WebKit in Google Chrome
Cross-site scripting (XSS) vulnerability in editing/markup.cpp in WebCore in WebKit in Google Chrome before 5.0.375.70 allows remote attackers to inject arbitrary web script or HTML via vectors related to the node.innerHTML property of a TEXTAREA element. NOTE: this might overlap CVE-2010-1762.
nvd
CVE-2011-2849P4MEDIUMCVSS 4.3fixed in 14.0.835.1632011-09-19
CVE-2011-2849 [MEDIUM] CWE-476 CVE-2011-2849: The WebSockets implementation in Google Chrome before 14.0.835.163 allows remote attackers to cause
The WebSockets implementation in Google Chrome before 14.0.835.163 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via unspecified vectors.
nvd
CVE-2010-0656P4MEDIUMCVSS 4.3≤ 4.0.249.78v0.2.149.27+46 more2010-02-18
CVE-2010-0656 [MEDIUM] CWE-200 CVE-2010-0656: WebKit before r51295, as used in Google Chrome before 4.0.249.78, presents a directory-listing page
WebKit before r51295, as used in Google Chrome before 4.0.249.78, presents a directory-listing page in response to an XMLHttpRequest for a file:/// URL that corresponds to a directory, which allows attackers to obtain sensitive information or possibly have unspecified other impact via a crafted local HTML document.
nvd
CVE-2011-2840P4MEDIUMCVSS 4.3fixed in 14.0.835.1632011-09-19
CVE-2011-2840 [MEDIUM] CWE-20 CVE-2011-2840: Google Chrome before 14.0.835.163 allows user-assisted remote attackers to spoof the URL bar via vec
Google Chrome before 14.0.835.163 allows user-assisted remote attackers to spoof the URL bar via vectors related to "unusual user interaction."
nvd
CVE-2011-2360P4MEDIUMCVSS 4.3fixed in 13.0.782.1072011-08-03
CVE-2011-2360 [MEDIUM] CVE-2011-2360: Google Chrome before 13.0.782.107 does not ensure that the user is prompted before download of a dan
Google Chrome before 13.0.782.107 does not ensure that the user is prompted before download of a dangerous file, which makes it easier for remote attackers to bypass intended content restrictions via a crafted web site.
nvd
CVE-2010-1503P4MEDIUMCVSS 4.3≤ 4.1.249.1058v1.0.154.53+232 more2010-04-23
CVE-2010-1503 [MEDIUM] CWE-79 CVE-2010-1503: Cross-site scripting (XSS) vulnerability in Google Chrome before 4.1.249.1059 allows remote attacker
Cross-site scripting (XSS) vulnerability in Google Chrome before 4.1.249.1059 allows remote attackers to inject arbitrary web script or HTML via vectors related to a chrome://net-internals URI.
nvd
CVE-2010-1504P4MEDIUMCVSS 4.3≤ 4.1.249.1058v1.0.154.53+232 more2010-04-23
CVE-2010-1504 [MEDIUM] CWE-79 CVE-2010-1504: Cross-site scripting (XSS) vulnerability in Google Chrome before 4.1.249.1059 allows remote attacker
Cross-site scripting (XSS) vulnerability in Google Chrome before 4.1.249.1059 allows remote attackers to inject arbitrary web script or HTML via vectors related to a chrome://downloads URI.
nvd
CVE-2014-9648P4MEDIUMCVSS 4.3≤ 40.0.2214.852015-01-27
CVE-2014-9648 [MEDIUM] CWE-284 CVE-2014-9648: components/navigation_interception/intercept_navigation_resource_throttle.cc in Google Chrome before
components/navigation_interception/intercept_navigation_resource_throttle.cc in Google Chrome before 40.0.2214.91 on Android does not properly restrict use of intent: URLs to open an application after navigation to a web site, which allows remote attackers to cause a denial of service (loss of browser access to that site) via crafted JavaScript code,
nvd
CVE-2010-5069P4MEDIUMCVSS 4.3v4.0.212.0v4.0.212.1+222 more2011-12-07
CVE-2010-5069 [MEDIUM] CVE-2010-5069: The Cascading Style Sheets (CSS) implementation in Google Chrome 4 does not properly handle the :vis
The Cascading Style Sheets (CSS) implementation in Google Chrome 4 does not properly handle the :visited pseudo-class, which allows remote attackers to obtain sensitive information about visited web pages via a crafted HTML document. NOTE: this may overlap CVE-2010-2264.
nvd
CVE-2012-2847P4MEDIUMCVSS 4.3≤ 21.0.1180.56v21.0.1180.0+25 more2012-08-06
CVE-2012-2847 [MEDIUM] CWE-399 CVE-2012-2847: Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chro
Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, does not request user confirmation before continuing a large series of downloads, which allows user-assisted remote attackers to cause a denial of service (resource consumption) via a crafted web site.
nvd
CVE-2008-4724P4MEDIUMCVSS 4.3v0.2.149.302008-10-23
CVE-2008-4724 [MEDIUM] CWE-79 CVE-2008-4724: Multiple cross-site scripting (XSS) vulnerabilities in Google Chrome 0.2.149.30 allow remote attacke
Multiple cross-site scripting (XSS) vulnerabilities in Google Chrome 0.2.149.30 allow remote attackers to inject arbitrary web script or HTML via an ftp:// URL for an HTML document within a (1) JPG, (2) PDF, or (3) TXT file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
nvd
CVE-2012-4904P4MEDIUMCVSS 4.3≤ 18.0.10253062012-09-13
CVE-2012-4904 [MEDIUM] CWE-79 CVE-2012-4904: Cross-application scripting vulnerability in Google Chrome before 18.0.1025308 on Android allows rem
Cross-application scripting vulnerability in Google Chrome before 18.0.1025308 on Android allows remote attackers to inject arbitrary web script via unspecified vectors, as demonstrated by "Universal XSS (UXSS)" attacks against the current tab.
nvd