Vulnerability index

Browse CVEs

617 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Memory Buffer Bounds ErrorCWE-119 × clear
Chrome MEDIUM 5.0
CVE-2011-3088

Google Chrome before 19.0.1084.46 does not properly draw hairlines, which allows remote attackers to cause a denial of service (out-of-bounds read) v…

Fix: after 19.0.1084.45
Fix from $1,600 2012-05-16
Chrome MEDIUM 5.0
CVE-2011-3083

browser/profiles/profile_impl_io_data.cc in Google Chrome before 19.0.1084.46 does not properly handle a malformed ftp URL in the SRC attribute of a …

Fix: after 19.0.1084.45
Fix from $1,600 2012-05-16
Chrome MEDIUM 5.0
CVE-2011-3085

The Autofill feature in Google Chrome before 19.0.1084.46 does not properly restrict field values, which allows remote attackers to cause a denial of…

Fix: after 19.0.1084.45
Fix from $1,600 2012-05-16
Chrome HIGH 9.3
CVE-2012-0724

Adobe Flash Player before 11.2.202.229 in Google Chrome before 18.0.1025.151 allow attackers to cause a denial of service (memory corruption) or poss…

Fix: 3.2.0.2070 / 11.1.111.8+
Fix from $1,950 2012-04-06
Chrome HIGH 9.3
CVE-2012-0725

Adobe Flash Player before 11.2.202.229 in Google Chrome before 18.0.1025.151 allow attackers to cause a denial of service (memory corruption) or poss…

Fix: 3.2.0.2070 / 11.1.111.8+
Fix from $1,950 2012-04-06
Chrome MEDIUM 6.8
CVE-2011-3052

The WebGL implementation in Google Chrome before 17.0.963.83 does not properly handle CANVAS elements, which allows remote attackers to cause a denia…

Fix: 18.0.1025.142+
Fix from $1,600 2012-03-22
Chrome HIGH 9.3
CVE-2011-3047

The GPU process in Google Chrome before 17.0.963.79 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption…

Fix: 17.0.963.79+
Fix from $1,950 2012-03-10
Android HIGH 9.3
CVE-2011-3874EPSS 12%

Stack-based buffer overflow in libsysutils in Android 2.2.x through 2.2.2 and 2.3.x through 2.3.6 allows user-assisted remote attackers to execute ar…

Mitigation only
Fix from $1,950 2012-01-27
Chrome MEDIUM 5.0
CVE-2011-3909

The Cascading Style Sheets (CSS) implementation in Google Chrome before 16.0.912.63 on 64-bit platforms does not properly manage property arrays, whi…

Fix: 5.1 / 5.1.4+
Fix from $1,600 2011-12-13
Chrome HIGH 7.5
CVE-2011-3894

Google Chrome before 15.0.874.120 does not properly perform VP8 decoding, which allows remote attackers to cause a denial of service (memory corrupti…

Fix: 15.0.874.120+
Fix from $1,950 2011-11-11
Chrome MEDIUM 6.8
CVE-2011-2881

Google Chrome before 14.0.835.202 does not properly handle Google V8 hidden objects, which allows remote attackers to cause a denial of service (memo…

Fix: 14.0.835.202+
Fix from $1,600 2011-10-04
Chrome MEDIUM 6.8
CVE-2011-3873

Google Chrome before 14.0.835.202 does not properly implement shader translation, which allows remote attackers to execute arbitrary code or cause a …

Fix: 14.0.835.202+
Fix from $1,600 2011-10-04
Chrome HIGH 10.0
CVE-2011-2806

Google Chrome before 13.0.782.215 on Windows does not properly handle vertex data, which allows remote attackers to execute arbitrary code or cause a…

Fix: 13.0.782.215+
Fix from $1,950 2011-08-29
Chrome MEDIUM 6.8
CVE-2011-2347

Google Chrome before 12.0.742.112 does not properly handle Cascading Style Sheets (CSS) token sequences, which allows remote attackers to cause a den…

Fix: 12.0.742.112+
Fix from $1,600 2011-06-29
Chrome MEDIUM 6.8
CVE-2011-2348

Google V8, as used in Google Chrome before 12.0.742.112, performs an incorrect bounds check, which allows remote attackers to cause a denial of servi…

Fix: 12.0.742.112+
Fix from $1,600 2011-06-29
Chrome MEDIUM 6.8
CVE-2011-1817

Google Chrome before 12.0.742.91 does not properly implement history deletion, which allows remote attackers to cause a denial of service (memory cor…

Fix: 12.0.742.91+
Fix from $1,600 2011-06-09
Chrome HIGH 10.0
CVE-2011-1806

Google Chrome before 11.0.696.71 does not properly implement the GPU command buffer, which allows remote attackers to execute arbitrary code or cause…

Fix: 11.0.696.71+
Fix from $1,950 2011-05-26
Chrome HIGH 7.5
CVE-2011-1285

The regular-expression functionality in Google Chrome before 10.0.648.127 does not properly implement reentrancy, which allows remote attackers to ca…

Fix: 10.0.648.127+
Fix from $1,950 2011-03-11
Chrome HIGH 7.5
CVE-2011-1198

The video functionality in Google Chrome before 10.0.648.127 allows remote attackers to cause a denial of service or possibly have unspecified other …

Fix: 10.0.648.127+
Fix from $1,950 2011-03-11
Chrome Os HIGH 10.0
CVE-2011-0476

Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 allow remote attackers to cause a denial of service (stack memory corruption) or po…

Fix: 8.0.552.237 / 8.0.552.344+
Fix from $1,950 2011-01-14
Chrome Os HIGH 10.0
CVE-2011-0477

Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly handle a mismatch in video frame sizes, which allows remote attacke…

Fix: 8.0.552.237 / 8.0.552.344+
Fix from $1,950 2011-01-14
Chrome HIGH 10.0
CVE-2010-3414

Google Chrome before 6.0.472.59 on Mac OS X does not properly implement file dialogs, which allows attackers to cause a denial of service (memory cor…

Fix: 6.0.472.59+
Fix from $1,950 2010-09-16
Chrome HIGH 10.0
CVE-2010-3415

Google Chrome before 6.0.472.59 does not properly implement Geolocation, which allows remote attackers to cause a denial of service (memory corruptio…

Fix: 6.0.472.59+
Fix from $1,950 2010-09-16
Chrome CRITICAL 9.8
CVE-2010-3416

Google Chrome before 6.0.472.59 on Linux does not properly implement the Khmer locale, which allows remote attackers to cause a denial of service (me…

Fix: 6.0.472.59+
Fix from $2,300 2010-09-16
Chrome HIGH 10.0
CVE-2010-3253

The implementation of notification permissions in Google Chrome before 6.0.472.53 allows attackers to cause a denial of service (memory corruption) o…

Fix: 6.0.472.53+
Fix from $1,950 2010-09-07
Chrome HIGH 9.3
CVE-2010-3255

Google Chrome before 6.0.472.53 and webkitgtk before 1.2.6 do not properly handle counter nodes, which allows remote attackers to cause a denial of s…

Fix: 1.2.6 / 6.0.472.53+
Fix from $1,950 2010-09-07
Chrome HIGH 10.0
CVE-2010-3112

Google Chrome before 5.0.375.127 does not properly implement file dialogs, which allows attackers to cause a denial of service (memory corruption) or…

Fix: 5.0.375.127+
Fix from $1,950 2010-08-24
Chrome HIGH 10.0
CVE-2010-3113

Google Chrome before 5.0.375.127, and webkitgtk before 1.2.5, does not properly handle SVG documents, which allows remote attackers to cause a denial…

Fix: 1.2.5 / 5.0.375.127+
Fix from $1,950 2010-08-24
Chrome HIGH 10.0
CVE-2010-3119

Google Chrome before 5.0.375.127 and webkitgtk before 1.2.6 do not properly support the Ruby language, which allows attackers to cause a denial of se…

Fix: 1.2.6 / 5.0.375.127+
Fix from $1,950 2010-08-24
Chrome HIGH 10.0
CVE-2010-3120

Google Chrome before 5.0.375.127 does not properly implement the Geolocation feature, which allows remote attackers to cause a denial of service (mem…

Fix: 5.0.375.127+
Fix from $1,950 2010-08-24