13,751 CVEs • 235 products
Products (235)
Click to collapseToggle
Products (235)
Click to collapse
CVEs (13,751)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Google Redhat5Chrome Enterprise Linux Desktop SupplementaryEnterprise Linux Server Supplementary+2 moreMay 6, 2026 Oct 8, 2014 N/A· v4 N/A· v3 7.5 HIGH· v2 The SessionService::GetLastSession function in browser/sessions/session_service.cc in Google Chrome before 38.0.2125.101 allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified...Show more |
3Apple GoogleRedhat9Chrome Enterprise Linux Desktop SupplementaryEnterprise Linux Server Supplementary+6 moreMay 6, 2026 Oct 8, 2014 N/A· v4 N/A· v3 7.5 HIGH· v2 Use-after-free vulnerability in the ProcessingInstruction::setXSLStyleSheet function in core/dom/ProcessingInstruction.cpp in the DOM implementation in Blink, as used in Google Chrome before 38.0.2125.101, allows remote...Show more |
2Google Redhat5Chrome Enterprise Linux Desktop SupplementaryEnterprise Linux Server Supplementary+2 moreMay 6, 2026 Oct 8, 2014 N/A· v4 N/A· v3 7.5 HIGH· v2 Use-after-free vulnerability in Blink, as used in Google Chrome before 38.0.2125.101, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that trigge...Show more |
2Google Redhat5Chrome Enterprise Linux Desktop SupplementaryEnterprise Linux Server Supplementary+2 moreMay 6, 2026 Oct 8, 2014 N/A· v4 N/A· v3 7.5 HIGH· v2 Use-after-free vulnerability in the Event::currentTarget function in core/events/Event.cpp in Blink, as used in Google Chrome before 38.0.2125.101, allows remote attackers to cause a denial of service (application crash)...Show more |
2Google Redhat5Chrome Enterprise Linux Desktop SupplementaryEnterprise Linux Server Supplementary+2 moreMay 6, 2026 Oct 8, 2014 N/A· v4 N/A· v3 7.5 HIGH· v2 The chrome_pdf::CopyImage function in pdf/draw_utils.cc in the PDFium component in Google Chrome before 38.0.2125.101 does not properly validate image-data dimensions, which allows remote attackers to cause a denial of s...Show more |
2Google Redhat6Chrome Chrome OsEnterprise Linux Desktop Supplementary+3 moreMay 6, 2026 Oct 8, 2014 N/A· v4 N/A· v3 10.0 HIGH· v2 Google Chrome before 38.0.2125.101 and Chrome OS before 38.0.2125.101 do not properly handle the interaction of IPC and Google V8, which allows remote attackers to execute arbitrary code via vectors involving JSON data,...Show more |
Google Chrome before 37.0.2062.60 and 38.x before 38.0.2125.59 on iOS does not properly restrict processing of (1) facetime:// and (2) facetime-audio:// URLs, which allows remote attackers to obtain video and audio data...Show more |
2Google Mozilla6Chrome FirefoxFirefox Esr+3 moreMay 6, 2026 Sep 25, 2014 N/A· v4 N/A· v3 7.5 HIGH· v2 Mozilla Network Security Services (NSS) before 3.16.2.1, 3.16.x before 3.16.5, and 3.17.x before 3.17.1, as used in Mozilla Firefox before 32.0.3, Mozilla Firefox ESR 24.x before 24.8.1 and 31.x before 31.1.1, Mozilla Th...Show more |
Multiple unspecified vulnerabilities in Google Chrome before 37.0.2062.120 allow attackers to cause a denial of service or possibly have other impact via unknown vectors. |
Use-after-free vulnerability in core/dom/Node.cpp in Blink, as used in Google Chrome before 37.0.2062.120, allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging impr...Show more |
The get_option function in dhcpcd 4.0.0 through 6.x before 6.4.3 allows remote DHCP servers to cause a denial of service by resetting the DHO_OPTIONSOVERLOADED option in the (1) bootfile or (2) servername section, which...Show more |
The Android WebView in Android before 4.4 allows remote attackers to bypass the Same Origin Policy via a crafted attribute containing a \u0000 character, as demonstrated by an onclick="window.open('\u0000javascript: sequ...Show more |
Google Chrome before 37.0.2062.94 does not properly handle the interaction of extensions, IPC, the sync API, and Google V8, which allows remote attackers to execute arbitrary code via unspecified vectors, a different vul...Show more |
Google Chrome before 37.0.2062.94 does not properly handle the interaction of extensions, IPC, the sync API, and Google V8, which allows remote attackers to execute arbitrary code via unspecified vectors, a different vul...Show more |
Multiple unspecified vulnerabilities in Google Chrome before 37.0.2062.94 allow attackers to cause a denial of service or possibly have other impact via unknown vectors, related to the load_truetype_glyph function in tru...Show more |
modules/webaudio/BiquadDSPKernel.cpp in the Web Audio API implementation in Blink, as used in Google Chrome before 37.0.2062.94, does not properly consider concurrent threads during attempts to update biquad filter coeff...Show more |
The WebGL implementation in Google Chrome before 37.0.2062.94 does not ensure that clear calls interact properly with the state of a draw buffer, which allows remote attackers to cause a denial of service (read of uninit...Show more |
The Debugger extension API in browser/extensions/api/debugger/debugger_api.cc in Google Chrome before 37.0.2062.94 does not validate a tab's URL before an attach operation, which allows remote attackers to bypass intende...Show more |
Use-after-free vulnerability in the V8 bindings in Blink, as used in Google Chrome before 37.0.2062.94, allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging imprope...Show more |
extensions/common/url_pattern.cc in Google Chrome before 37.0.2062.94 does not prevent use of a '\0' character in a host name, which allows remote attackers to spoof the extension permission dialog by relying on truncati...Show more |