← Back

Chrome

chrome

Vendor: Google • 6,253 CVEs

CVEs (6,253)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Google
Opensuse
2Chrome
Opensuse
Apr 29, 2026
Feb 23, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Skia, as used in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allows remote attackers to cause a denial of service (out-of-bounds read) via vectors related to a "user gestu...Show more
Skia, as used in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allows remote attackers to cause a denial of service (out-of-bounds read) via vectors related to a "user gesture check for dangerous file downloads."Show less
1Google
1Chrome
Apr 29, 2026
Feb 23, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
The developer-tools process in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, does not properly restrict privileges during interaction with a connected server, which has unsp...Show more
The developer-tools process in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, does not properly restrict privileges during interaction with a connected server, which has unspecified impact and attack vectors.Show less
2Apple
Google
2Chrome
Mac Os X
Apr 29, 2026
Feb 23, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
Google Chrome before 25.0.1364.99 on Mac OS X does not properly implement signal handling for Native Client (aka NaCl) code, which has unspecified impact and attack vectors.
2Google
Opensuse
2Chrome
Opensuse
Apr 29, 2026
Feb 23, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, does not properly restrict API privileges during interaction with the Chrome Web Store, which has unspecified impact and attack...Show more
Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, does not properly restrict API privileges during interaction with the Chrome Web Store, which has unspecified impact and attack vectors.Show less
2Google
Opensuse
2Chrome
Opensuse
Apr 29, 2026
Feb 23, 2013
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, does not properly load Native Client (aka NaCl) code, which has unspecified impact and attack vectors.
2Google
Opensuse
2Chrome
Opensuse
Apr 29, 2026
Feb 23, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Skia, as used in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allows remote attackers to cause a denial of service (incorrect read operation) via unspecified vectors.
2Google
Opensuse
2Chrome
Opensuse
Apr 29, 2026
Feb 23, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allows remote attackers to cause a denial of service (incorrect memory access) or possibly have unspecified other impact via a...Show more
Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allows remote attackers to cause a denial of service (incorrect memory access) or possibly have unspecified other impact via a large number of SVG parameters.Show less
2Google
Opensuse
2Chrome
Opensuse
Apr 29, 2026
Feb 23, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allows remote attackers to cause a denial of service (incorrect read operation) via crafted data in the Matroska container form...Show more
Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allows remote attackers to cause a denial of service (incorrect read operation) via crafted data in the Matroska container format.Show less
2Google
Opensuse
2Chrome
Opensuse
Apr 29, 2026
Feb 23, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
Use-after-free vulnerability in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allows remote attackers to cause a denial of service or possibly have unspecified other impact...Show more
Use-after-free vulnerability in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to databases.Show less
1Google
1Chrome
Apr 29, 2026
Feb 23, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, does not properly implement web audio nodes, which allows remote attackers to cause a denial of service (memory corruption) or...Show more
Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, does not properly implement web audio nodes, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.Show less
1Google
1Chrome
Apr 29, 2026
Jan 24, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
content/renderer/media/webrtc_audio_renderer.cc in Google Chrome before 24.0.1312.56 on Mac OS X does not use an appropriate buffer size for the 96 kHz sampling rate, which allows remote attackers to cause a denial of se...Show more
content/renderer/media/webrtc_audio_renderer.cc in Google Chrome before 24.0.1312.56 on Mac OS X does not use an appropriate buffer size for the 96 kHz sampling rate, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via a web site that provides WebRTC audio.Show less
1Google
1Chrome
Apr 29, 2026
Jan 24, 2013
N/A· v4
N/A· v3
10.0 HIGH· v2
Google Chrome before 24.0.1312.56 does not properly handle %00 characters in pathnames, which has unspecified impact and attack vectors.
1Google
1Chrome
Apr 29, 2026
Jan 24, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
Array index error in the content-blocking functionality in Google Chrome before 24.0.1312.56 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
1Google
1Chrome
Apr 29, 2026
Jan 24, 2013
N/A· v4
N/A· v3
10.0 HIGH· v2
Google Chrome before 24.0.1312.56 does not validate URLs during the opening of new windows, which has unspecified impact and remote attack vectors.
1Google
1Chrome
Apr 29, 2026
Jan 24, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
Use-after-free vulnerability in Google Chrome before 24.0.1312.56 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of fonts in CANVAS elem...Show more
Use-after-free vulnerability in Google Chrome before 24.0.1312.56 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of fonts in CANVAS elements.Show less
1Google
1Chrome
Apr 29, 2026
Jan 15, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
Google Chrome before 24.0.1312.52 on Linux uses weak permissions for shared memory segments, which has unspecified impact and attack vectors.
2Google
Opensuse
2Chrome
Opensuse
Apr 29, 2026
Jan 15, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
Google Chrome before 24.0.1312.52 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of extension tabs.
2Google
Opensuse
3Chrome
OpensuseV8
Apr 29, 2026
Jan 15, 2013
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Google V8 before 3.14.5.3, as used in Google Chrome before 24.0.1312.52, does not properly implement garbage collection, which allows remote attackers to cause a denial of service (application crash) or possibly have uns...Show more
Google V8 before 3.14.5.3, as used in Google Chrome before 24.0.1312.52, does not properly implement garbage collection, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted JavaScript code.Show less
2Google
Opensuse
2Chrome
Opensuse
Apr 29, 2026
Jan 15, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Unspecified vulnerability in the Geolocation implementation in Google Chrome before 24.0.1312.52 allows remote attackers to cause a denial of service (application crash) via unknown vectors.
2Google
Opensuse
2Chrome
Opensuse
Apr 29, 2026
Jan 15, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Google Chrome before 24.0.1312.52 allows remote attackers to cause a denial of service (out-of-bounds read) via vectors involving glyphs.