cbcvebase.

Google Chrome vulnerabilities

5,463 known vulnerabilities affecting google/chrome.

Total CVEs
5,463
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL440HIGH2725MEDIUM2233LOW65

Vulnerabilities

Page 5 of 274
CVE-2020-6453P2HIGHCVSS 8.8Exploitedfixed in 80.0.3987.162≥ unspecified, < 80.0.3987.1622020-06-03
CVE-2020-6453 [HIGH] CWE-787 CVE-2020-6453: Inappropriate implementation in V8 in Google Chrome prior to 80.0.3987.162 allowed a remote attacker Inappropriate implementation in V8 in Google Chrome prior to 80.0.3987.162 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2016-5165P2MEDIUMCVSS 6.1Exploited≤ 52.0.2743.1162016-09-11
CVE-2016-5165 [MEDIUM] CWE-79 CVE-2016-5165: Cross-site scripting (XSS) vulnerability in the Developer Tools (aka DevTools) subsystem in Google C Cross-site scripting (XSS) vulnerability in the Developer Tools (aka DevTools) subsystem in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux allows remote attackers to inject arbitrary web script or HTML via the settings parameter in a chrome-devtools-frontend.appspot.com URL's query string.
nvd
CVE-2022-0456P2HIGHCVSS 8.8Exploitedfixed in 98.0.4758.80≥ unspecified, < 98.0.4758.802022-04-05
CVE-2022-0456 [HIGH] CWE-416 CVE-2022-0456: Use after free in Web Search in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to pot Use after free in Web Search in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to potentially exploit heap corruption via profile destruction.
nvd
CVE-2021-30538P2MEDIUMCVSS 4.3Exploitedfixed in 91.0.4472.77≥ unspecified, < 91.0.4472.772021-06-07
CVE-2021-30538 [MEDIUM] CWE-863 CVE-2021-30538: Insufficient policy enforcement in content security policy in Google Chrome prior to 91.0.4472.77 al Insufficient policy enforcement in content security policy in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass content security policy via a crafted HTML page.
nvd
CVE-2019-5840P2MEDIUMCVSS 4.3Exploitedfixed in 75.0.3770.80≥ unspecified, < 75.0.3770.802019-06-27
CVE-2019-5840 [MEDIUM] CWE-362 CVE-2019-5840: Incorrect security UI in popup blocker in Google Chrome on iOS prior to 75.0.3770.80 allowed a remot Incorrect security UI in popup blocker in Google Chrome on iOS prior to 75.0.3770.80 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
nvd
CVE-2018-6055P2HIGHCVSS 8.8Exploitedfixed in 64.0.3282.119≥ unspecified, < 64.0.3282.1192018-09-25
CVE-2018-6055 [HIGH] CWE-20 CVE-2018-6055: Insufficient policy enforcement in Catalog Service in Google Chrome prior to 64.0.3282.119 allowed a Insufficient policy enforcement in Catalog Service in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially run arbitrary code outside sandbox via a crafted HTML page.
nvd
CVE-2013-2912P2HIGHCVSS 7.5Exploited≤ 30.0.1599.65v30.0.1599.0+57 more2013-10-02
CVE-2013-2912 [HIGH] CWE-399 CVE-2013-2912: Use-after-free vulnerability in the PepperInProcessRouter::SendToHost function in content/renderer/p Use-after-free vulnerability in the PepperInProcessRouter::SendToHost function in content/renderer/pepper/pepper_in_process_router.cc in the Pepper Plug-in API (PPAPI) in Google Chrome before 30.0.1599.66 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving a resource-destruction message.
nvd
CVE-2010-1205P2CRITICALCVSS 9.8PoCfixed in 5.0.375.992010-06-30
CVE-2010-1205 [CRITICAL] CWE-120 CVE-2010-1205: Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive applications, might allow remote attackers to execute arbitrary code via a PNG image that triggers an additional data row.
nvd
CVE-2010-1663P2CRITICALCVSS 10.0PoC≤ 4.1.249.1063v0.2.149.27+106 more2010-05-03
CVE-2010-1663 [CRITICAL] CWE-264 CVE-2010-1663: The Google URL Parsing Library (aka google-url or GURL) in Google Chrome before 4.1.249.1064 allows The Google URL Parsing Library (aka google-url or GURL) in Google Chrome before 4.1.249.1064 allows remote attackers to bypass the Same Origin Policy via unspecified vectors.
nvd
CVE-2020-6507P2HIGHCVSS 8.8PoCfixed in 83.0.4103.106≥ unspecified, < 83.0.4103.1062020-07-22
CVE-2020-6507 [HIGH] CWE-20 CVE-2020-6507: Out of bounds write in V8 in Google Chrome prior to 83.0.4103.106 allowed a remote attacker to poten Out of bounds write in V8 in Google Chrome prior to 83.0.4103.106 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2016-9651P2HIGHCVSS 8.8PoCfixed in 55.0.2883.75≥ unspecified, < 55.0.2883.752019-01-09
CVE-2016-9651 [HIGH] CWE-94 CVE-2016-9651: A missing check for whether a property of a JS object is private in V8 in Google Chrome prior to 55. A missing check for whether a property of a JS object is private in V8 in Google Chrome prior to 55.0.2883.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
nvd
CVE-2018-6092P2HIGHCVSS 8.8PoCfixed in 66.0.3359.117≥ unspecified, < 66.0.3359.1172018-12-04
CVE-2018-6092 [HIGH] CWE-190 CVE-2018-6092: An integer overflow on 32-bit systems in WebAssembly in Google Chrome prior to 66.0.3359.117 allowed An integer overflow on 32-bit systems in WebAssembly in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
nvd
CVE-2019-5789P2HIGHCVSS 8.8PoCfixed in 73.0.3683.75vprior to 73.0.3683.752019-05-23
CVE-2019-5789 [HIGH] CWE-190 CVE-2019-5789: An integer overflow that leads to a use-after-free in WebMIDI in Google Chrome on Windows prior to 7 An integer overflow that leads to a use-after-free in WebMIDI in Google Chrome on Windows prior to 73.0.3683.75 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page.
nvd
CVE-2019-5788P2HIGHCVSS 8.8PoCfixed in 73.0.3683.75vprior to 73.0.3683.752019-05-23
CVE-2019-5788 [HIGH] CWE-190 CVE-2019-5788: An integer overflow that leads to a use-after-free in Blink Storage in Google Chrome on Linux prior An integer overflow that leads to a use-after-free in Blink Storage in Google Chrome on Linux prior to 73.0.3683.75 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page.
nvd
CVE-2022-0306P2HIGHCVSS 8.8fixed in 97.0.4692.99≥ unspecified, < 97.0.4692.992022-02-12
CVE-2022-0306 [HIGH] CWE-787 CVE-2022-0306: Heap buffer overflow in PDFium in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to p Heap buffer overflow in PDFium in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2018-6126P2HIGHCVSS 8.8PoCfixed in 67.0.3396.62≥ unspecified, < 67.0.3396.622019-01-09
CVE-2018-6126 [HIGH] CWE-787 CVE-2018-6126: A precision error in Skia in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to perfor A precision error in Skia in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page.
nvd
CVE-2018-6064P2HIGHCVSS 8.8PoCfixed in 65.0.3325.146≥ unspecified, < 65.0.3325.1462018-11-14
CVE-2018-6064 [HIGH] CWE-704 CVE-2018-6064: Type Confusion in the implementation of __defineGetter__ in V8 in Google Chrome prior to 65.0.3325.1 Type Confusion in the implementation of __defineGetter__ in V8 in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2018-16071P3HIGHCVSS 8.8PoCfixed in 69.0.3497.81≥ unspecified, < 69.0.3497.812019-01-09
CVE-2018-16071 [HIGH] CWE-416 CVE-2018-16071: A use after free in WebRTC in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to poten A use after free in WebRTC in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially exploit heap corruption via a crafted video file.
nvd
CVE-2023-3420P2HIGHCVSS 8.8fixed in 114.0.5735.198≥ 114.0.5735.198, < 114.0.5735.1982023-06-26
CVE-2023-3420 [HIGH] CWE-843 CVE-2023-3420: Type Confusion in V8 in Google Chrome prior to 114.0.5735.198 allowed a remote attacker to potential Type Confusion in V8 in Google Chrome prior to 114.0.5735.198 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2018-16083P3HIGHCVSS 8.8PoCfixed in 69.0.3497.81≥ unspecified, < 69.0.3497.812019-01-09
CVE-2018-16083 [HIGH] CWE-125 CVE-2018-16083: An out of bounds read in forward error correction code in WebRTC in Google Chrome prior to 69.0.3497 An out of bounds read in forward error correction code in WebRTC in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
nvd
Google Chrome vulnerabilities | cvebase