Vulnerability index

Browse CVEs

90 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Rendertron MEDIUM 6.1
CVE-2017-18352

Error reporting within Rendertron 1.0.0 allows reflected Cross Site Scripting (XSS) from invalid URLs.

Patch available
Fix from $1,600 2018-12-17
Chrome MEDIUM 6.1
CVE-2018-6081

XSS vulnerabilities in Interstitials in Google Chrome prior to 65.0.3325.146 allowed an attacker who convinced a user to install a malicious extensio…

Fix: 65.0.3325.146+
Fix from $1,600 2018-11-14
Chrome MEDIUM 6.1
CVE-2018-6070

Lack of CSP enforcement on WebUI pages in Bink in Google Chrome prior to 65.0.3325.146 allowed an attacker who convinced a user to install a maliciou…

Fix: 65.0.3325.146+
Fix from $1,600 2018-11-14
Chrome MEDIUM 6.1
CVE-2018-6076

Insufficient encoding of URL fragment identifiers in Blink in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to perform a DOM based X…

Fix: 65.0.3325.146+
Fix from $1,600 2018-11-14
Chrome MEDIUM 6.1
CVE-2017-15429

Inappropriate implementation in V8 WebAssembly JS bindings in Google Chrome prior to 63.0.3239.108 allowed a remote attacker to inject arbitrary scri…

Fix: 63.0.3239.108+
Fix from $1,600 2018-08-28
Chrome MEDIUM 6.1
CVE-2017-15427

Insufficient policy enforcement in Omnibox in Google Chrome prior to 63.0.3239.84 allowed a socially engineered user to XSS themselves by dragging an…

Fix: 63.0.3239.84+
Fix from $1,600 2018-08-28
Chrome MEDIUM 6.1
CVE-2017-5124EPSS 5%

Incorrect application of sandboxing in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to inject arbitrary scripts or HTML (UX…

Fix: 62.0.3202.62+
Fix from $1,600 2018-02-07
Chrome MEDIUM 6.1
CVE-2017-5085

Inappropriate implementation in Bookmarks in Google Chrome prior to 59 for iOS allowed a remote attacker who convinced the user to perform certain op…

Mitigation only
Fix from $1,600 2017-10-27
Chrome MEDIUM 6.1
CVE-2017-5069

Incorrect MIME type of XSS-Protection reports in Blink in Google Chrome prior to 58.0.3029.81 for Linux, Windows, and Mac, and 58.0.3029.83 for Andro…

Fix: 58.0.3029.81 / 58.0.3029.83+
Fix from $1,600 2017-10-27
Chrome MEDIUM 6.1
CVE-2017-5045

XSS Auditor in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed detection of a blocked iframe lo…

Fix: after 57.0.2987.100
Fix from $1,600 2017-04-24
Chrome MEDIUM 6.1
CVE-2017-5006

Blink in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, incorrectly handled object owner relationships…

Fix: after 55.0.2883.87
Fix from $1,600 2017-02-17
Chrome MEDIUM 6.1
CVE-2017-5007

Blink in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, incorrectly handled the sequence of events whe…

Fix: after 55.0.2883.87
Fix from $1,600 2017-02-17
Chrome MEDIUM 6.1
CVE-2017-5008

Blink in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, allowed attacker controlled JavaScript to be r…

Fix: after 55.0.2883.87
Fix from $1,600 2017-02-17
Chrome MEDIUM 6.1
CVE-2017-5010

Blink in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, resolved promises in an inappropriate context,…

Fix: after 55.0.2883.87
Fix from $1,600 2017-02-17
Chrome MEDIUM 6.1
CVE-2017-5018

Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, had an insufficiently strict content security policy on…

Fix: after 55.0.2883.87
Fix from $1,600 2017-02-17
Chrome MEDIUM 6.1
CVE-2017-5020

Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, failed to require a user gesture for powerful download …

Fix: after 55.0.2883.87
Fix from $1,600 2017-02-17
Chrome MEDIUM 6.1
CVE-2016-5226

Blink in Google Chrome prior to 55.0.2883.75 for Linux, Windows and Mac executed javascript: URLs entered in the URL bar in the context of the curren…

Fix: after 54.0.2840.99
Fix from $1,600 2017-01-19
Chrome MEDIUM 6.1
CVE-2016-5204

Leaking of an SVG shadow tree leading to corruption of the DOM tree in Blink in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 5…

Fix: after 54.0.2840.99
Fix from $1,600 2017-01-19
Chrome MEDIUM 6.1
CVE-2016-5205

Blink in Google Chrome prior to 55.0.2883.75 for Linux, Windows and Mac, incorrectly handles deferred page loads, which allowed a remote attacker to …

Fix: after 54.0.2840.99
Fix from $1,600 2017-01-19
Chrome MEDIUM 6.1
CVE-2016-5207

In Blink in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android, corruption of the DOM tree could occur duri…

Fix: after 54.0.2840.99
Fix from $1,600 2017-01-19
Chrome MEDIUM 6.1
CVE-2016-5208

Blink in Google Chrome prior to 55.0.2883.75 for Linux and Windows, and 55.0.2883.84 for Android allowed possible corruption of the DOM tree during s…

Fix: after 54.0.2840.99
Fix from $1,600 2017-01-19
Chrome MEDIUM 6.1
CVE-2016-5181

Blink in Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android permitted execution of v8 microtasks while the DOM…

Fix: after 53.0.2785.143
Fix from $1,600 2016-12-18
Chrome MEDIUM 6.1
CVE-2016-5191

Bookmark handling in Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android had insufficient validation of supplie…

Fix: after 53.0.2785.143
Fix from $1,600 2016-12-18
Chrome MEDIUM 6.1
CVE-2016-5165

Cross-site scripting (XSS) vulnerability in the Developer Tools (aka DevTools) subsystem in Google Chrome before 53.0.2785.89 on Windows and OS X and…

Fix: after 52.0.2743.116
Fix from $1,600 2016-09-11
Chrome MEDIUM 6.1
CVE-2016-5164

Cross-site scripting (XSS) vulnerability in WebKit/Source/platform/v8_inspector/V8Debugger.cpp in Blink, as used in Google Chrome before 53.0.2785.89…

Fix: after 52.0.2743.116
Fix from $1,600 2016-09-11
Chrome MEDIUM 6.1
CVE-2016-5148

Cross-site scripting (XSS) vulnerability in Blink, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux,…

Fix: after 52.0.2743.116
Fix from $1,600 2016-09-11
Chrome MEDIUM 6.1
CVE-2016-5147

Blink, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, mishandles deferred page loads, which allow…

Fix: after 52.0.2743.116
Fix from $1,600 2016-09-11
Chrome MEDIUM 6.8
CVE-2014-3187

Google Chrome before 37.0.2062.60 and 38.x before 38.0.2125.59 on iOS does not properly restrict processing of (1) facetime:// and (2) facetime-audio…

Fix: after 37.0.2062.59
Fix from $1,600 2014-10-08
Chrome HIGH 10.0
CVE-2011-3046

The extension subsystem in Google Chrome before 17.0.963.78 does not properly handle history navigation, which allows remote attackers to execute arb…

Fix: 5.1.1 / 5.1.7+
Fix from $1,950 2012-03-09
Custom Search Engine MEDIUM 6.1
CVE-2007-3484

Cross-site scripting (XSS) vulnerability in search.php in Google Custom Search Engine allows remote attackers to inject arbitrary web script or HTML …

Mitigation only
Fix from $1,600 2007-06-28