Total
3392 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2011-3088 | 1 Google | 1 Chrome | 2017-12-29 | 5.0 MEDIUM | N/A |
Google Chrome before 19.0.1084.46 does not properly draw hairlines, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors. | |||||
CVE-2011-3087 | 1 Google | 1 Chrome | 2017-12-29 | 10.0 HIGH | N/A |
Google Chrome before 19.0.1084.46 does not properly perform window navigation, which has unspecified impact and remote attack vectors. | |||||
CVE-2011-3086 | 1 Google | 1 Chrome | 2017-12-29 | 10.0 HIGH | N/A |
Use-after-free vulnerability in Google Chrome before 19.0.1084.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving a STYLE element. | |||||
CVE-2011-3085 | 1 Google | 1 Chrome | 2017-12-29 | 5.0 MEDIUM | N/A |
The Autofill feature in Google Chrome before 19.0.1084.46 does not properly restrict field values, which allows remote attackers to cause a denial of service (UI corruption) and possibly conduct spoofing attacks via vectors involving long values. | |||||
CVE-2011-3084 | 1 Google | 1 Chrome | 2017-12-29 | 7.5 HIGH | N/A |
Google Chrome before 19.0.1084.46 does not use a dedicated process for the loading of links found on an internal page, which might allow attackers to bypass intended sandbox restrictions via a crafted page. | |||||
CVE-2011-3083 | 1 Google | 1 Chrome | 2017-12-29 | 5.0 MEDIUM | N/A |
browser/profiles/profile_impl_io_data.cc in Google Chrome before 19.0.1084.46 does not properly handle a malformed ftp URL in the SRC attribute of a VIDEO element, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted web page. | |||||
CVE-2011-3099 | 1 Google | 1 Chrome | 2017-12-05 | 10.0 HIGH | N/A |
Use-after-free vulnerability in the PDF functionality in Google Chrome before 19.0.1084.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving a malformed name for the font encoding. | |||||
CVE-2011-3097 | 1 Google | 1 Chrome | 2017-12-05 | 10.0 HIGH | N/A |
The PDF functionality in Google Chrome before 19.0.1084.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging an out-of-bounds write error in the implementation of sampled functions. | |||||
CVE-2009-1514 | 1 Google | 1 Chrome | 2017-09-29 | 5.0 MEDIUM | N/A |
Google Chrome 1.0.154.53 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a throw statement with a long exception value. | |||||
CVE-2008-6998 | 1 Google | 1 Chrome | 2017-09-29 | 9.3 HIGH | N/A |
Stack-based buffer overflow in chrome/common/gfx/url_elider.cc in Google Chrome 0.2.149.27 and other versions before 0.2.149.29 might allow user-assisted remote attackers to execute arbitrary code via a link target (href attribute) with a large number of path elements, which triggers the overflow when the status bar is updated after the user hovers over the link. | |||||
CVE-2008-6997 | 1 Google | 1 Chrome | 2017-09-29 | 4.3 MEDIUM | N/A |
Google Chrome 0.2.149.27 allows user-assisted remote attackers to cause a denial of service (browser crash) via an IMG tag with a long src attribute, which triggers the crash when the victim performs an "Inspect Element" action. | |||||
CVE-2008-6995 | 1 Google | 1 Chrome | 2017-09-29 | 4.3 MEDIUM | N/A |
Integer underflow in net/base/escape.cc in chrome.dll in Google Chrome 0.2.149.27 allows remote attackers to cause a denial of service (browser crash) via a URI with an invalid handler followed by a "%" (percent) character, which triggers a buffer over-read, as demonstrated using an "about:%" URI. | |||||
CVE-2013-6628 | 1 Google | 1 Chrome | 2017-09-19 | 4.3 MEDIUM | N/A |
net/socket/ssl_client_socket_nss.cc in the TLS implementation in Google Chrome before 31.0.1650.48 does not ensure that a server's X.509 certificate is the same during renegotiation as it was before renegotiation, which might allow remote web servers to interfere with trust relationships by renegotiating a session. | |||||
CVE-2013-6627 | 1 Google | 1 Chrome | 2017-09-19 | 5.0 MEDIUM | N/A |
net/http/http_stream_parser.cc in Google Chrome before 31.0.1650.48 does not properly process HTTP Informational (aka 1xx) status codes, which allows remote web servers to cause a denial of service (out-of-bounds read) via a crafted response. | |||||
CVE-2013-6626 | 1 Google | 1 Chrome | 2017-09-19 | 4.3 MEDIUM | N/A |
The WebContentsImpl::AttachInterstitialPage function in content/browser/web_contents/web_contents_impl.cc in Google Chrome before 31.0.1650.48 does not cancel JavaScript dialogs upon generating an interstitial warning, which allows remote attackers to spoof the address bar via a crafted web site. | |||||
CVE-2013-6625 | 1 Google | 1 Chrome | 2017-09-19 | 6.8 MEDIUM | N/A |
Use-after-free vulnerability in core/dom/ContainerNode.cpp in Blink, as used in Google Chrome before 31.0.1650.48, allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging improper handling of DOM range objects in circumstances that require child node removal after a (1) mutation or (2) blur event. | |||||
CVE-2013-6624 | 1 Google | 1 Chrome | 2017-09-19 | 7.5 HIGH | N/A |
Use-after-free vulnerability in Google Chrome before 31.0.1650.48 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving the string values of id attributes. | |||||
CVE-2013-6623 | 1 Google | 1 Chrome | 2017-09-19 | 4.3 MEDIUM | N/A |
The SVG implementation in Blink, as used in Google Chrome before 31.0.1650.48, allows remote attackers to cause a denial of service (out-of-bounds read) by leveraging the use of tree order, rather than transitive dependency order, for layout. | |||||
CVE-2013-6622 | 1 Google | 1 Chrome | 2017-09-19 | 6.8 MEDIUM | N/A |
Use-after-free vulnerability in the HTMLMediaElement::didMoveToNewDocument function in core/html/HTMLMediaElement.cpp in Blink, as used in Google Chrome before 31.0.1650.48, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving the movement of a media element between documents. | |||||
CVE-2013-2268 | 4 Apple, Google, Linux and 1 more | 4 Mac Os X, Chrome, Linux Kernel and 1 more | 2017-09-19 | 7.5 HIGH | N/A |
Unspecified vulnerability in the MathML implementation in WebKit in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, has unknown impact and remote attack vectors, related to a "high severity security issue." |