← Back

Chrome

chrome

Vendor: Google • 6,253 CVEs

CVEs (6,253)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Google
1Chrome
Apr 29, 2026
Feb 16, 2012
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple integer overflows in the PDF codecs in Google Chrome before 17.0.963.56 allow remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
1Google
1Chrome
Apr 29, 2026
Feb 9, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The shader translator implementation in Google Chrome before 17.0.963.46 allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
2Apple
Google
4Chrome
Iphone OsItunes+1 more
Apr 29, 2026
Feb 9, 2012
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Use-after-free vulnerability in Google Chrome before 17.0.963.46 allows user-assisted remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to mousemove events.
3Google
SuseXmlsoft
5Chrome
LibxsltLinux Enterprise Desktop+2 more
Apr 29, 2026
Feb 9, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
libxslt, as used in Google Chrome before 17.0.963.46, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
2Apple
Google
4Chrome
Iphone OsItunes+1 more
Apr 29, 2026
Feb 9, 2012
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Use-after-free vulnerability in Google Chrome before 17.0.963.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to layout of SVG documents.
2Apple
Google
4Chrome
Iphone OsItunes+1 more
Apr 29, 2026
Feb 9, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Use-after-free vulnerability in Google Chrome before 17.0.963.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving Cascading Style Sheets (CSS) token seq...Show more
Use-after-free vulnerability in Google Chrome before 17.0.963.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving Cascading Style Sheets (CSS) token sequences.Show less
1Google
1Chrome
Apr 29, 2026
Feb 9, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Unspecified vulnerability in Google Chrome before 17.0.963.46 allows remote attackers to cause a denial of service (application crash) via a crafted certificate.
2Apple
Google
4Chrome
Iphone OsItunes+1 more
Apr 29, 2026
Feb 9, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
Use-after-free vulnerability in Google Chrome before 17.0.963.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to error handling for Cascading Style Sh...Show more
Use-after-free vulnerability in Google Chrome before 17.0.963.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to error handling for Cascading Style Sheets (CSS) token-sequence data.Show less
1Google
1Chrome
Apr 29, 2026
Feb 9, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Google Chrome before 17.0.963.46 does not properly check signatures, which allows remote attackers to cause a denial of service (application crash) via unspecified vectors.
1Google
1Chrome
Apr 29, 2026
Feb 9, 2012
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Google Chrome before 17.0.963.46 does not properly implement the drag-and-drop feature, which makes it easier for remote attackers to spoof the URL bar via unspecified vectors.
1Google
1Chrome
Apr 29, 2026
Feb 9, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Google Chrome before 17.0.963.46 does not properly handle PDF FAX images, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
1Google
1Chrome
Apr 29, 2026
Feb 9, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Google Chrome before 17.0.963.46 does not properly perform path clipping, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
1Google
1Chrome
Apr 29, 2026
Feb 9, 2012
N/A· v4
N/A· v3
9.3 HIGH· v2
Race condition in Google Chrome before 17.0.963.46 allows remote attackers to execute arbitrary code via vectors that trigger a crash of a utility process.
1Google
1Chrome
Apr 29, 2026
Feb 9, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Google Chrome before 17.0.963.46 does not properly decode audio data, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
1Google
1Chrome
Apr 29, 2026
Feb 9, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in the locale implementation in Google Chrome before 17.0.963.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
2Apple
Google
4Chrome
Iphone OsItunes+1 more
Apr 29, 2026
Feb 9, 2012
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Google Chrome before 17.0.963.46 does not properly perform casts of variables during handling of a column span, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a c...Show more
Google Chrome before 17.0.963.46 does not properly perform casts of variables during handling of a column span, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted document.Show less
1Google
1Chrome
Apr 29, 2026
Feb 9, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
Use-after-free vulnerability in the garbage-collection functionality in Google Chrome before 17.0.963.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involvin...Show more
Use-after-free vulnerability in the garbage-collection functionality in Google Chrome before 17.0.963.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving PDF documents.Show less
1Google
1Chrome
Apr 29, 2026
Feb 9, 2012
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The extension implementation in Google Chrome before 17.0.963.46 does not properly handle sandboxed origins, which might allow remote attackers to bypass the Same Origin Policy via a crafted extension.
1Google
1Chrome
Apr 29, 2026
Feb 9, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
Google Chrome before 17.0.963.46 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via vectors that trigger the aborting of an IndexedDB transaction.
1Google
1Chrome
Apr 29, 2026
Feb 9, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Google Chrome before 17.0.963.46 allows remote attackers to cause a denial of service (application crash) via vectors that trigger a large amount of database usage.