Skip to main content

Vendor/product archive

google / chrome CVEs

Beta · best-effort

5,477 CVEs tagged to google / chrome443 Critical, 2,725 High, 2,240 Medium, 69 Low, 0 Unrated.

CVE-2011-3880

Published Oct 25, 2011

Google Chrome before 15.0.874.102 does not prevent use of an unspecified special character as a delimiter in HTTP headers, which has unknown impact and remote attack vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-3879

Published Oct 25, 2011

Google Chrome before 15.0.874.102 does not prevent redirects to chrome: URLs, which has unspecified impact and remote attack vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-3878

Published Oct 25, 2011

Race condition in Google Chrome before 15.0.874.102 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to worker pr…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3877

Published Oct 25, 2011

Cross-site scripting (XSS) vulnerability in the appcache internals page in Google Chrome before 15.0.874.102 allows remote attackers to inject arbitrary web script or HTML via uns…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3876

Published Oct 25, 2011

Google Chrome before 15.0.874.102 does not properly handle downloading files that have whitespace characters at the end of a filename, which has unspecified impact and user-assist…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3875

Published Oct 25, 2011

Google Chrome before 15.0.874.102 does not properly handle drag and drop operations on URL strings, which allows user-assisted remote attackers to spoof the URL bar via unspecifie…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3873

Published Oct 4, 2011

Google Chrome before 14.0.835.202 does not properly implement shader translation, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corr…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2881

Published Oct 4, 2011

Google Chrome before 14.0.835.202 does not properly handle Google V8 hidden objects, which allows remote attackers to cause a denial of service (memory corruption) or possibly hav…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2880

Published Oct 4, 2011

Use-after-free vulnerability in Google Chrome before 14.0.835.202 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors relate…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2879

Published Oct 4, 2011

Google Chrome before 14.0.835.202 does not properly consider object lifetimes and thread safety during the handling of audio nodes, which allows remote attackers to cause a denial…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2878

Published Oct 4, 2011

Google Chrome before 14.0.835.202 does not properly restrict access to the window prototype, which allows remote attackers to bypass the Same Origin Policy via unspecified vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-2876

Published Oct 4, 2011

Use-after-free vulnerability in Google Chrome before 14.0.835.202 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involv…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2875

Published Sep 19, 2011

Google V8, as used in Google Chrome before 14.0.835.163, does not properly perform object sealing, which allows remote attackers to cause a denial of service or possibly have unsp…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2874

Published Sep 19, 2011

Google Chrome before 14.0.835.163 does not perform an expected pin operation for a self-signed certificate during a session, which has unspecified impact and remote attack vectors.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2864

Published Sep 19, 2011

Google Chrome before 14.0.835.163 does not properly handle Tibetan characters, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vect…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2862

Published Sep 19, 2011

Google V8, as used in Google Chrome before 14.0.835.163, does not properly restrict access to built-in objects, which has unspecified impact and remote attack vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-2861

Published Sep 19, 2011

Google Chrome before 14.0.835.163 does not properly handle strings in PDF documents, which allows remote attackers to have an unspecified impact via a crafted document that trigge…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2859

Published Sep 19, 2011

Google Chrome before 14.0.835.163 uses incorrect permissions for non-gallery pages, which has unspecified impact and attack vectors.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2858

Published Sep 19, 2011

Google Chrome before 14.0.835.163 does not properly handle triangle arrays, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2856

Published Sep 19, 2011

Google V8, as used in Google Chrome before 14.0.835.163, allows remote attackers to bypass the Same Origin Policy via unspecified vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 5,051-5,075 of 5,477 CVEsPage 203 of 220