← Back

Chrome

chrome

Vendor: Google • 5,445 CVEs

CVEs (5,445)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Google
Opensuse
2Chrome
Opensuse
Apr 29, 2026
Nov 28, 2012
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Google Chrome before 23.0.1271.91 does not properly perform a cast of an unspecified variable during handling of the INPUT element, which allows remote attackers to cause a denial of service or possibly have unknown othe...Show more
Google Chrome before 23.0.1271.91 does not properly perform a cast of an unspecified variable during handling of the INPUT element, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted HTML document.Show less
2Google
Opensuse
2Chrome
Opensuse
Apr 29, 2026
Nov 28, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
Use-after-free vulnerability in Google Chrome before 23.0.1271.91 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to printing.
3Apple
GoogleXmlsoft
3Chrome
Iphone OsLibxml2
Apr 29, 2026
Nov 28, 2012
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Heap-based buffer underflow in the xmlParseAttValueComplex function in parser.c in libxml2 2.9.0 and earlier, as used in Google Chrome before 23.0.1271.91 and other products, allows remote attackers to cause a denial of...Show more
Heap-based buffer underflow in the xmlParseAttValueComplex function in parser.c in libxml2 2.9.0 and earlier, as used in Google Chrome before 23.0.1271.91 and other products, allows remote attackers to cause a denial of service or possibly execute arbitrary code via crafted entities in an XML document.Show less
2Google
Opensuse
2Chrome
Opensuse
Apr 29, 2026
Nov 28, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
Use-after-free vulnerability in Google Chrome before 23.0.1271.91 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to SVG filters.
2Google
Opensuse
2Chrome
Opensuse
Apr 29, 2026
Nov 28, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Google Chrome before 23.0.1271.91 allows remote attackers to cause a denial of service (application crash) via a response with chunked transfer coding.
1Google
1Chrome
Apr 29, 2026
Nov 28, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
Google Chrome before 23.0.1271.91 on Mac OS X does not properly mitigate improper rendering behavior in the Intel GPU driver, which allows remote attackers to cause a denial of service or possibly have unspecified other...Show more
Google Chrome before 23.0.1271.91 on Mac OS X does not properly mitigate improper rendering behavior in the Intel GPU driver, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.Show less
2Google
Opensuse
2Chrome
Opensuse
Apr 29, 2026
Nov 28, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Skia, as used in Google Chrome before 23.0.1271.91, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
2Apple
Google
3Chrome
SafariWebkit
Apr 29, 2026
Nov 15, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
html/parser/XSSAuditor.cpp in WebCore in WebKit, as used in Google Chrome through 22 and Safari 5.1.7, does not consider all possible output contexts of reflected data, which makes it easier for remote attackers to bypas...Show more
html/parser/XSSAuditor.cpp in WebCore in WebKit, as used in Google Chrome through 22 and Safari 5.1.7, does not consider all possible output contexts of reflected data, which makes it easier for remote attackers to bypass a cross-site scripting (XSS) protection mechanism via a crafted string, aka rdar problem 12019108.Show less
1Google
2Chrome
V8
Apr 29, 2026
Nov 7, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
Google V8 before 3.13.7.5, as used in Google Chrome before 23.0.1271.64, does not properly perform write operations, which allows remote attackers to cause a denial of service or possibly have unspecified other impact vi...Show more
Google V8 before 3.13.7.5, as used in Google Chrome before 23.0.1271.64, does not properly perform write operations, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.Show less
1Google
1Chrome
Apr 29, 2026
Nov 7, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
Integer overflow in Google Chrome before 23.0.1271.64 allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted WebP image.
1Google
1Chrome
Apr 29, 2026
Nov 7, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
Use-after-free vulnerability in Google Chrome before 23.0.1271.64 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of plug-in placeholders...Show more
Use-after-free vulnerability in Google Chrome before 23.0.1271.64 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of plug-in placeholders.Show less
1Google
1Chrome
Apr 29, 2026
Nov 7, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
Use-after-free vulnerability in Google Chrome before 23.0.1271.64 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of extension tabs.
1Google
1Chrome
Apr 29, 2026
Nov 7, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
Google Chrome before 23.0.1271.64 does not properly handle textures, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
1Google
1Chrome
Apr 29, 2026
Nov 7, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Skia, as used in Google Chrome before 23.0.1271.64, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
1Google
1Chrome
Apr 29, 2026
Nov 7, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
Google Chrome before 23.0.1271.64 does not properly perform a cast of an unspecified variable during handling of input, which allows remote attackers to cause a denial of service or possibly have other impact via unknown...Show more
Google Chrome before 23.0.1271.64 does not properly perform a cast of an unspecified variable during handling of input, which allows remote attackers to cause a denial of service or possibly have other impact via unknown vectors.Show less
1Google
1Chrome
Apr 29, 2026
Nov 7, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
Use-after-free vulnerability in Google Chrome before 23.0.1271.64 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to video layout.
1Google
2Chrome
V8
Apr 29, 2026
Nov 7, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
Google V8 before 3.13.7.5, as used in Google Chrome before 23.0.1271.64, on 64-bit Linux platforms allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript cod...Show more
Google V8 before 3.13.7.5, as used in Google Chrome before 23.0.1271.64, on 64-bit Linux platforms allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that triggers an out-of-bounds access to an array.Show less
1Google
1Chrome
Apr 29, 2026
Nov 7, 2012
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Race condition in Pepper, as used in Google Chrome before 23.0.1271.64, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to buffers.
1Google
1Chrome
Apr 29, 2026
Nov 7, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
Google Chrome before 23.0.1271.64 on Mac OS X does not properly validate an integer value during the handling of GPU command buffers, which allows remote attackers to cause a denial of service or possibly have unspecifie...Show more
Google Chrome before 23.0.1271.64 on Mac OS X does not properly validate an integer value during the handling of GPU command buffers, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.Show less
1Google
1Chrome
Apr 29, 2026
Nov 7, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
Google Chrome before 23.0.1271.64 does not properly restrict the loading of an SVG subresource in the context of an IMG element, which has unspecified impact and remote attack vectors.