Google Chrome Os vulnerabilities
65 known vulnerabilities affecting google/chrome_os.
Total CVEs
65
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL28HIGH22MEDIUM14LOW1
Vulnerabilities
Page 4 of 4
CVE-2011-0470P4MEDIUMCVSS 5.0fixed in 8.0.552.3442011-01-14
CVE-2011-0470 [MEDIUM] CVE-2011-0470: Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly handle extensions
Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly handle extensions notification, which allows remote attackers to cause a denial of service (application crash) via unspecified vectors.
nvd
CVE-2011-1042P4MEDIUMCVSS 4.3≤ 0.9.126.0v8.0.552.342+2 more2011-02-18
CVE-2011-1042 [MEDIUM] CWE-399 CVE-2011-1042: Use-after-free vulnerability in flimflamd in flimflam in Google Chrome OS before 0.9.130.14 Beta all
Use-after-free vulnerability in flimflamd in flimflam in Google Chrome OS before 0.9.130.14 Beta allows user-assisted remote attackers to cause a denial of service (daemon crash) by providing the name of a hidden WiFi network that does not respond to connection attempts.
nvd
CVE-2010-4575P4MEDIUMCVSS 4.3fixed in 8.0.552.3432010-12-22
CVE-2010-4575 [MEDIUM] CWE-20 CVE-2010-4575: The ThemeInstalledInfoBarDelegate::Observe function in browser/extensions/theme_installed_infobar_de
The ThemeInstalledInfoBarDelegate::Observe function in browser/extensions/theme_installed_infobar_delegate.cc in Google Chrome before 8.0.552.224 and Chrome OS before 8.0.552.343 does not properly handle incorrect tab interaction by an extension, which allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted
nvd
CVE-2011-2170P4MEDIUMCVSS 4.4≤ 0.12.433.35v0.9.126.0+29 more2011-05-24
CVE-2011-2170 [MEDIUM] CWE-20 CVE-2011-2170: Google Chrome OS before R12 0.12.433.38 Beta, when Guest mode is enabled, does not prevent changes o
Google Chrome OS before R12 0.12.433.38 Beta, when Guest mode is enabled, does not prevent changes on the about:flags page, which has unspecified impact and local attack vectors.
nvd
CVE-2017-5084P4LOWCVSS 3.3fixed in 59.0.3071.922017-10-27
CVE-2017-5084 [LOW] CWE-269 CVE-2017-5084: Inappropriate implementation in image-burner in Google Chrome OS prior to 59.0.3071.92 allowed a loc
Inappropriate implementation in image-burner in Google Chrome OS prior to 59.0.3071.92 allowed a local attacker to read local files via dbus-send commands to a BurnImage D-Bus endpoint.
nvd
← Previous4 / 4