Vulnerability index

Browse CVEs

1,055 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Chrome HIGH 7.5
CVE-2015-1284

The LocalFrame::isURLAllowed function in core/frame/LocalFrame.cpp in Blink, as used in Google Chrome before 44.0.2403.89, does not properly check fo…

Fix: after 43.0.2357.134
Fix from $1,950 2015-07-23
Chrome HIGH 7.5
CVE-2011-1798

rendering/svg/RenderSVGText.cpp in WebCore in WebKit in Google Chrome before 11.0.696.65 does not properly perform a cast of an unspecified variable …

Fix: after 11.0.696.64
Fix from $1,950 2014-12-26
Chrome HIGH 7.5
CVE-2011-1793

rendering/svg/RenderSVGResourceFilter.cpp in WebCore in WebKit in Google Chrome before 11.0.696.65 allows remote attackers to cause a denial of servi…

Fix: after 11.0.696.65
Fix from $1,950 2014-12-26
Chrome MEDIUM 5.0
CVE-2014-7899

Google Chrome before 38.0.2125.101 allows remote attackers to spoof the address bar by placing a blob: substring at the beginning of the URL, followe…

Fix: after 38.0.2125.7
Fix from $1,600 2014-11-19
Chrome MEDIUM 6.4
CVE-2014-3159

The WebContentsDelegateAndroid::OpenURLFromTab function in components/web_contents_delegate_android/web_contents_delegate_android.cc in Google Chrome…

Fix: after 36.0.1985.106
Fix from $1,600 2014-07-20
Chrome HIGH 7.5
CVE-2014-1733

The PointerCompare function in codegen.cc in Seccomp-BPF, as used in Google Chrome before 34.0.1847.131 on Windows and OS X and before 34.0.1847.132 …

Fix: 34.0.1847.131 / 34.0.1847.132+
Fix from $1,950 2014-04-26
Chrome MEDIUM 5.0
CVE-2014-1725

The base64DecodeInternal function in wtf/text/Base64.cpp in Blink, as used in Google Chrome before 34.0.1847.116, does not properly handle string dat…

Fix: after 34.0.1847.115
Fix from $1,600 2014-04-09
Chrome HIGH 7.5
CVE-2014-1723

The UnescapeURLWithOffsetsImpl function in net/base/escape.cc in Google Chrome before 34.0.1847.116 does not properly handle bidirectional Internatio…

Fix: after 34.0.1847.115
Fix from $1,950 2014-04-09
Chrome HIGH 7.5
CVE-2014-1714

The ScopedClipboardWriter::WritePickledData function in ui/base/clipboard/scoped_clipboard_writer.cc in Google Chrome before 33.0.1750.152 on OS X an…

Fix: 33.0.1750.152 / 33.0.1750.154+
Fix from $1,950 2014-03-16
Android HIGH 9.3
CVE-2013-4710EPSS 43%

Android 3.0 through 4.1.x on Disney Mobile, eAccess, KDDI, NTT DOCOMO, SoftBank, and other devices does not properly implement the WebView class, whi…

Mitigation only
Fix from $1,950 2014-03-03
Chrome HIGH 7.5
CVE-2013-6654

The SVGAnimateElement::calculateAnimatedValue function in core/svg/SVGAnimateElement.cpp in Blink, as used in Google Chrome before 33.0.1750.117, doe…

Fix: after 33.0.1750.116
Fix from $1,950 2014-02-24
Chrome HIGH 7.5
CVE-2013-2871

Use-after-free vulnerability in Google Chrome before 28.0.1500.71 allows remote attackers to cause a denial of service or possibly have unspecified o…

Fix: after 28.0.1500.70
Fix from $1,950 2013-07-10
Chrome MEDIUM 6.8
CVE-2013-0926

Google Chrome before 26.0.1410.43 does not properly handle active content in an EMBED element during a copy-and-paste operation, which allows user-as…

Fix: after 26.0.1410.42
Fix from $1,600 2013-03-28
Chrome HIGH 7.5
CVE-2013-0841

Array index error in the content-blocking functionality in Google Chrome before 24.0.1312.56 allows remote attackers to cause a denial of service or …

Fix: after 24.0.1312.55
Fix from $1,950 2013-01-24
Chrome HIGH 7.5
CVE-2013-0837

Google Chrome before 24.0.1312.52 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related …

Fix: after 24.0.1312.51
Fix from $1,950 2013-01-15
Chrome HIGH 7.5
CVE-2012-5148

The hyphenation functionality in Google Chrome before 24.0.1312.52 does not properly validate file names, which has unspecified impact and attack vec…

Fix: after 24.0.1312.51
Fix from $1,950 2013-01-15
Chrome HIGH 7.5
CVE-2013-0830

The IPC layer in Google Chrome before 24.0.1312.52 on Windows omits a NUL character required for termination of an unspecified data structure, which …

Fix: after 24.0.1312.51
Fix from $1,950 2013-01-15
Android MEDIUM 5.0
CVE-2012-6301EPSS 6%

The Browser application in Android 4.0.3 allows remote attackers to cause a denial of service (application crash) via a crafted market: URI in the SR…

No fix yet
Fix from $1,600 2012-12-10
Chrome MEDIUM 6.8
CVE-2012-5136

Google Chrome before 23.0.1271.91 does not properly perform a cast of an unspecified variable during handling of the INPUT element, which allows remo…

Fix: after 23.0.1271.89
Fix from $1,600 2012-11-28
Chrome HIGH 7.5
CVE-2012-5118

Google Chrome before 23.0.1271.64 on Mac OS X does not properly validate an integer value during the handling of GPU command buffers, which allows re…

Fix: after 23.0.1271.62
Fix from $1,950 2012-11-07
Checkout Php MEDIUM 5.8
CVE-2011-5238

google-checkout-php-sample-code before 1.3.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subj…

Fix: after 1.3.1
Fix from $1,600 2012-11-06
Admob MEDIUM 5.8
CVE-2012-5820

The developer-account sample code in Google AdMob does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or…

No fix yet
Fix from $1,600 2012-11-04
Chrome MEDIUM 6.8
CVE-2012-2882

FFmpeg, as used in Google Chrome before 22.0.1229.79, does not properly handle OGG containers, which allows remote attackers to cause a denial of ser…

Fix: after 22.0.1229.78
Fix from $1,600 2012-09-26
Chrome MEDIUM 5.0
CVE-2012-2877

The extension system in Google Chrome before 22.0.1229.79 does not properly handle modal dialogs, which allows remote attackers to cause a denial of …

Fix: after 22.0.1229.78
Fix from $1,600 2012-09-26
Mod Pagespeed MEDIUM 5.0
CVE-2012-4001

The mod_pagespeed module before 0.10.22.6 for the Apache HTTP Server does not properly verify its host name, which allows remote attackers to trigger…

Fix: after 0.10.22.4
Fix from $1,600 2012-09-15
Tunnelblick HIGH 7.2
CVE-2012-3485

Tunnelblick 3.3beta20 and earlier relies on argv[0] to determine the name of an appropriate (1) kernel module pathname or (2) executable file pathnam…

Fix: after 3.3beta20
Fix from $1,950 2012-08-26
Chrome MEDIUM 5.0
CVE-2012-2825

The XSL implementation in Google Chrome before 20.0.1132.43 allows remote attackers to cause a denial of service (incorrect read operation) via unspe…

Fix: after 20.0.1132.42
Fix from $1,600 2012-06-27
Chrome MEDIUM 6.8
CVE-2012-2819

The texSubImage2D implementation in the WebGL subsystem in Google Chrome before 20.0.1132.43 does not properly handle uploads to floating-point textu…

Fix: after 20.0.1132.42
Fix from $1,600 2012-06-27
Chrome MEDIUM 5.0
CVE-2012-2820

Google Chrome before 20.0.1132.43 does not properly implement SVG filters, which allows remote attackers to cause a denial of service (out-of-bounds …

Fix: after 20.0.1132.42
Fix from $1,600 2012-06-27
Chrome HIGH 10.0
CVE-2011-3097

The PDF functionality in Google Chrome before 19.0.1084.46 allows remote attackers to cause a denial of service or possibly have unspecified other im…

Fix: after 19.0.1084.45
Fix from $1,950 2012-05-16