Skip to main content

Vendor/product archive

google / chrome CVEs

Beta · best-effort

5,454 CVEs tagged to google / chrome438 Critical, 2,709 High, 2,239 Medium, 68 Low, 0 Unrated.

CVE-2011-2791

Published Aug 3, 2011

The International Components for Unicode (ICU) functionality in Google Chrome before 13.0.782.107 allows remote attackers to cause a denial of service or possibly have unspecified…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2789

Published Aug 3, 2011

Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors relate…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2787

Published Aug 3, 2011

Google Chrome before 13.0.782.107 does not properly address re-entrancy issues associated with the GPU lock, which allows remote attackers to cause a denial of service (applicatio…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2786

Published Aug 3, 2011

Google Chrome before 13.0.782.107 does not ensure that the speech-input bubble is shown on the product's screen, which might make it easier for remote attackers to make audio reco…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2785

Published Aug 3, 2011

The extensions implementation in Google Chrome before 13.0.782.107 does not properly validate the URL for the home page, which allows remote attackers to have an unspecified impac…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2784

Published Aug 3, 2011

Google Chrome before 13.0.782.107 allows remote attackers to obtain sensitive information via a request for the GL program log, which reveals a local path in an unspecified log en…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2011-2783

Published Aug 3, 2011

Google Chrome before 13.0.782.107 does not ensure that developer-mode NPAPI extension installations are confirmed by a browser dialog, which makes it easier for remote attackers t…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2782

Published Aug 3, 2011

The drag-and-drop implementation in Google Chrome before 13.0.782.107 on Linux does not properly enforce permissions for files, which allows user-assisted remote attackers to bypa…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2361

Published Aug 3, 2011

The Basic Authentication dialog implementation in Google Chrome before 13.0.782.107 does not properly handle strings, which might make it easier for remote attackers to capture cr…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2360

Published Aug 3, 2011

Google Chrome before 13.0.782.107 does not ensure that the user is prompted before download of a dangerous file, which makes it easier for remote attackers to bypass intended cont…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2358

Published Aug 3, 2011

Google Chrome before 13.0.782.107 does not ensure that extension installations are confirmed by a browser dialog, which makes it easier for remote attackers to modify the product'…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2761

Published Jul 18, 2011

Google Chrome 14.0.794.0 does not properly handle a reload of a page generated in response to a POST, which allows user-assisted remote attackers to cause a denial of service (app…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2599

Published Jun 30, 2011

Google Chrome 11 does not block use of a cross-domain image as a WebGL texture, which allows remote attackers to obtain approximate copies of arbitrary images via a timing attack…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2350

Published Jun 29, 2011

The HTML parser in Google Chrome before 12.0.742.112 does not properly address "lifetime and re-entrancy issues," which allows remote attackers to cause a denial of service or pos…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2349

Published Jun 29, 2011

Use-after-free vulnerability in Google Chrome before 12.0.742.112 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors relate…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2348

Published Jun 29, 2011

Google V8, as used in Google Chrome before 12.0.742.112, performs an incorrect bounds check, which allows remote attackers to cause a denial of service or possibly have unspecifie…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2347

Published Jun 29, 2011

Google Chrome before 12.0.742.112 does not properly handle Cascading Style Sheets (CSS) token sequences, which allows remote attackers to cause a denial of service (memory corrupt…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2346

Published Jun 29, 2011

Use-after-free vulnerability in Google Chrome before 12.0.742.112 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involv…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2345

Published Jun 29, 2011

The NPAPI implementation in Google Chrome before 12.0.742.112 does not properly handle strings, which allows remote attackers to cause a denial of service (out-of-bounds read) via…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2342

Published Jun 9, 2011

The DOM implementation in Google Chrome before 12.0.742.91 allows remote attackers to bypass the Same Origin Policy via unspecified vectors.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 5,101-5,125 of 5,454 CVEsPage 205 of 219