Vulnerability index

Browse CVEs

1,055 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Chrome HIGH 10.0
CVE-2011-3092

The regex implementation in Google V8, as used in Google Chrome before 19.0.1084.46, allows remote attackers to cause a denial of service (invalid wr…

Fix: after 19.0.1084.45
Fix from $1,950 2012-05-16
Chrome HIGH 10.0
CVE-2011-3095

The OGG container in Google Chrome before 19.0.1084.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact…

Fix: after 19.0.1084.45
Fix from $1,950 2012-05-16
Chrome MEDIUM 5.0
CVE-2011-3093

Google Chrome before 19.0.1084.46 does not properly handle glyphs, which allows remote attackers to cause a denial of service (out-of-bounds read) vi…

Fix: after 19.0.1084.45
Fix from $1,600 2012-05-16
Chrome MEDIUM 5.0
CVE-2011-3094

Google Chrome before 19.0.1084.46 does not properly handle Tibetan text, which allows remote attackers to cause a denial of service (out-of-bounds re…

Fix: after 19.0.1084.45
Fix from $1,600 2012-05-16
Chrome MEDIUM 5.8
CVE-2011-3964

Google Chrome before 17.0.963.46 does not properly implement the drag-and-drop feature, which makes it easier for remote attackers to spoof the URL b…

Fix: 17.0.963.46+
Fix from $1,600 2012-02-09
V8 MEDIUM 5.0
CVE-2011-5037

Google V8 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attack…

Mitigation only
Fix from $1,600 2011-12-30
Idapython HIGH 9.3
CVE-2011-4783

The IDAPython plugin before 1.5.2.3 in IDA Pro allows user-assisted remote attackers to execute arbitrary code via a crafted IDB file, related to imp…

Fix: after 1.5.2
Fix from $1,950 2011-12-27
Chrome HIGH 7.5
CVE-2011-3880

Google Chrome before 15.0.874.102 does not prevent use of an unspecified special character as a delimiter in HTTP headers, which has unknown impact a…

Fix: 15.0.874.102+
Fix from $1,950 2011-10-25
Chrome MEDIUM 6.8
CVE-2011-3884

Google Chrome before 15.0.874.102 does not properly address timing issues during DOM traversal, which allows remote attackers to cause a denial of se…

Fix: 15.0.874.102+
Fix from $1,600 2011-10-25
V8 MEDIUM 6.8
CVE-2011-3886

Google V8, as used in Google Chrome before 15.0.874.102, allows remote attackers to cause a denial of service or possibly have unspecified other impa…

Mitigation only
Fix from $1,600 2011-10-25
Chrome MEDIUM 6.8
CVE-2011-2861

Google Chrome before 14.0.835.163 does not properly handle strings in PDF documents, which allows remote attackers to have an unspecified impact via …

Fix: 14.0.835.163+
Fix from $1,600 2011-09-19
Chrome HIGH 7.5
CVE-2011-2838

Google Chrome before 14.0.835.163 does not properly consider the MIME type during the loading of a plug-in, which has unspecified impact and remote a…

Fix: 14.0.835.163+
Fix from $1,950 2011-09-19
Chrome HIGH 7.5
CVE-2011-2842

The installer in Google Chrome before 14.0.835.163 on Mac OS X does not properly handle lock files, which has unspecified impact and attack vectors.

Fix: 14.0.835.163+
Fix from $1,950 2011-09-19
Chrome MEDIUM 6.8
CVE-2011-2841

Google Chrome before 14.0.835.163 does not properly perform garbage collection during the processing of PDF documents, which allows remote attackers …

Fix: 14.0.835.163+
Fix from $1,600 2011-09-19
Chrome HIGH 10.0
CVE-2011-2822

Google Chrome before 13.0.782.215 on Windows does not properly parse URLs located on the command line, which has unspecified impact and attack vector…

Fix: 13.0.782.215+
Fix from $1,950 2011-08-29
Chrome HIGH 7.5
CVE-2011-2839

The PDF implementation in Google Chrome before 13.0.782.215 on Linux does not properly use the memset library function, which allows remote attackers…

Fix: 13.0.782.215+
Fix from $1,950 2011-08-29
Chrome MEDIUM 6.8
CVE-2011-2802

Google V8, as used in Google Chrome before 13.0.782.107, does not properly perform const lookups, which allows remote attackers to cause a denial of …

Fix: 13.0.782.107+
Fix from $1,600 2011-08-03
Chrome MEDIUM 6.8
CVE-2011-2358

Google Chrome before 13.0.782.107 does not ensure that extension installations are confirmed by a browser dialog, which makes it easier for remote at…

Fix: 13.0.782.107+
Fix from $1,600 2011-08-03
Chrome MEDIUM 6.8
CVE-2011-2359

Google Chrome before 13.0.782.107 does not properly track line boxes during rendering, which allows remote attackers to cause a denial of service or …

Fix: 5.0 / 5.1.1+
Fix from $1,600 2011-08-03
Chrome MEDIUM 6.8
CVE-2011-2783

Google Chrome before 13.0.782.107 does not ensure that developer-mode NPAPI extension installations are confirmed by a browser dialog, which makes it…

Fix: 13.0.782.107+
Fix from $1,600 2011-08-03
Chrome HIGH 7.5
CVE-2011-2332

Google V8, as used in Google Chrome before 12.0.742.91, allows remote attackers to bypass the Same Origin Policy via unspecified vectors.

Fix: 12.0.742.91+
Fix from $1,950 2011-06-09
Chrome MEDIUM 6.8
CVE-2011-1813

Google Chrome before 12.0.742.91 does not properly implement the framework for extensions, which allows remote attackers to cause a denial of service…

Fix: 12.0.742.91+
Fix from $1,600 2011-06-09
Chrome HIGH 7.5
CVE-2011-1804

rendering/RenderBox.cpp in WebCore in WebKit before r86862, as used in Google Chrome before 11.0.696.71, does not properly render floats, which allow…

Fix: 11.0.696.71+
Fix from $1,950 2011-05-26
Chrome MEDIUM 6.8
CVE-2011-1456

Google Chrome before 11.0.696.57 does not properly handle PDF forms, which allows remote attackers to cause a denial of service or possibly have unsp…

Fix: 11.0.696.57+
Fix from $1,600 2011-05-03
Chrome HIGH 7.5
CVE-2011-1303

Google Chrome before 11.0.696.57 does not properly handle floating objects, which allows remote attackers to cause a denial of service or possibly ha…

Fix: 11.0.696.57+
Fix from $1,950 2011-05-03
Chrome HIGH 7.5
CVE-2011-1438

Google Chrome before 11.0.696.57 allows remote attackers to bypass the Same Origin Policy via vectors involving blobs.

Fix: 11.0.696.57+
Fix from $1,950 2011-05-03
Chrome HIGH 7.5
CVE-2011-1451

Google Chrome before 11.0.696.57 does not properly handle DOM id maps, which allows remote attackers to cause a denial of service or possibly have un…

Fix: 5.0 / 5.0.6+
Fix from $1,950 2011-05-03
Chrome MEDIUM 6.8
CVE-2011-1434

Google Chrome before 11.0.696.57 does not ensure thread safety during handling of MIME data, which allows remote attackers to cause a denial of servi…

Fix: 11.0.696.57+
Fix from $1,600 2011-05-03
Chrome MEDIUM 6.8
CVE-2011-1442

Google Chrome before 11.0.696.57 does not properly handle mutation events, which allows remote attackers to cause a denial of service (node tree corr…

Fix: 11.0.696.57+
Fix from $1,600 2011-05-03
Chrome MEDIUM 6.8
CVE-2011-1443

Google Chrome before 11.0.696.57 does not properly implement layering, which allows remote attackers to cause a denial of service or possibly have un…

Fix: 11.0.696.57+
Fix from $1,600 2011-05-03