Vulnerability index

Browse CVEs

90 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
MEDIUM 6.1 CVE-2017-18352 Error reporting within Rendertron 1.0.0 allows reflected Cross Site Scripting (XSS) from invalid URLs. Rendertron Patch available Fix from $1,6002018-12-17 MEDIUM 6.1 CVE-2018-6081 XSS vulnerabilities in Interstitials in Google Chrome prior to 65.0.3325.146 allowed an attacker who convinced a user to install a malicious extensio… Chrome 65.0.3325.146+ Fix from $1,6002018-11-14 MEDIUM 6.1 CVE-2018-6070 Lack of CSP enforcement on WebUI pages in Bink in Google Chrome prior to 65.0.3325.146 allowed an attacker who convinced a user to install a maliciou… Chrome 65.0.3325.146+ Fix from $1,6002018-11-14 MEDIUM 6.1 CVE-2018-6076 Insufficient encoding of URL fragment identifiers in Blink in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to perform a DOM based X… Chrome 65.0.3325.146+ Fix from $1,6002018-11-14 MEDIUM 6.1 CVE-2017-15429 Inappropriate implementation in V8 WebAssembly JS bindings in Google Chrome prior to 63.0.3239.108 allowed a remote attacker to inject arbitrary scri… Chrome 63.0.3239.108+ Fix from $1,6002018-08-28 MEDIUM 6.1 CVE-2017-15427 Insufficient policy enforcement in Omnibox in Google Chrome prior to 63.0.3239.84 allowed a socially engineered user to XSS themselves by dragging an… Chrome 63.0.3239.84+ Fix from $1,6002018-08-28 MEDIUM 6.1 CVE-2017-5124EPSS 5% Incorrect application of sandboxing in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to inject arbitrary scripts or HTML (UX… Chrome 62.0.3202.62+ Fix from $1,6002018-02-07 MEDIUM 6.1 CVE-2017-5085 Inappropriate implementation in Bookmarks in Google Chrome prior to 59 for iOS allowed a remote attacker who convinced the user to perform certain op… Chrome Mitigation only Fix from $1,6002017-10-27 MEDIUM 6.1 CVE-2017-5069 Incorrect MIME type of XSS-Protection reports in Blink in Google Chrome prior to 58.0.3029.81 for Linux, Windows, and Mac, and 58.0.3029.83 for Andro… Chrome 58.0.3029.81 / 58.0.3029.83+ Fix from $1,6002017-10-27 MEDIUM 6.1 CVE-2017-5045 XSS Auditor in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed detection of a blocked iframe lo… Chrome after 57.0.2987.100 Fix from $1,6002017-04-24 MEDIUM 6.1 CVE-2017-5006 Blink in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, incorrectly handled object owner relationships… Chrome after 55.0.2883.87 Fix from $1,6002017-02-17 MEDIUM 6.1 CVE-2017-5007 Blink in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, incorrectly handled the sequence of events whe… Chrome after 55.0.2883.87 Fix from $1,6002017-02-17 MEDIUM 6.1 CVE-2017-5008 Blink in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, allowed attacker controlled JavaScript to be r… Chrome after 55.0.2883.87 Fix from $1,6002017-02-17 MEDIUM 6.1 CVE-2017-5010 Blink in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, resolved promises in an inappropriate context,… Chrome after 55.0.2883.87 Fix from $1,6002017-02-17 MEDIUM 6.1 CVE-2017-5018 Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, had an insufficiently strict content security policy on… Chrome after 55.0.2883.87 Fix from $1,6002017-02-17 MEDIUM 6.1 CVE-2017-5020 Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, failed to require a user gesture for powerful download … Chrome after 55.0.2883.87 Fix from $1,6002017-02-17 MEDIUM 6.1 CVE-2016-5226 Blink in Google Chrome prior to 55.0.2883.75 for Linux, Windows and Mac executed javascript: URLs entered in the URL bar in the context of the curren… Chrome after 54.0.2840.99 Fix from $1,6002017-01-19 MEDIUM 6.1 CVE-2016-5204 Leaking of an SVG shadow tree leading to corruption of the DOM tree in Blink in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 5… Chrome after 54.0.2840.99 Fix from $1,6002017-01-19 MEDIUM 6.1 CVE-2016-5205 Blink in Google Chrome prior to 55.0.2883.75 for Linux, Windows and Mac, incorrectly handles deferred page loads, which allowed a remote attacker to … Chrome after 54.0.2840.99 Fix from $1,6002017-01-19 MEDIUM 6.1 CVE-2016-5207 In Blink in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android, corruption of the DOM tree could occur duri… Chrome after 54.0.2840.99 Fix from $1,6002017-01-19 MEDIUM 6.1 CVE-2016-5208 Blink in Google Chrome prior to 55.0.2883.75 for Linux and Windows, and 55.0.2883.84 for Android allowed possible corruption of the DOM tree during s… Chrome after 54.0.2840.99 Fix from $1,6002017-01-19 MEDIUM 6.1 CVE-2016-5181 Blink in Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android permitted execution of v8 microtasks while the DOM… Chrome after 53.0.2785.143 Fix from $1,6002016-12-18 MEDIUM 6.1 CVE-2016-5191 Bookmark handling in Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android had insufficient validation of supplie… Chrome after 53.0.2785.143 Fix from $1,6002016-12-18 MEDIUM 6.1 CVE-2016-5165 Cross-site scripting (XSS) vulnerability in the Developer Tools (aka DevTools) subsystem in Google Chrome before 53.0.2785.89 on Windows and OS X and… Chrome after 52.0.2743.116 Fix from $1,6002016-09-11 MEDIUM 6.1 CVE-2016-5164 Cross-site scripting (XSS) vulnerability in WebKit/Source/platform/v8_inspector/V8Debugger.cpp in Blink, as used in Google Chrome before 53.0.2785.89… Chrome after 52.0.2743.116 Fix from $1,6002016-09-11 MEDIUM 6.1 CVE-2016-5148 Cross-site scripting (XSS) vulnerability in Blink, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux,… Chrome after 52.0.2743.116 Fix from $1,6002016-09-11 MEDIUM 6.1 CVE-2016-5147 Blink, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, mishandles deferred page loads, which allow… Chrome after 52.0.2743.116 Fix from $1,6002016-09-11 MEDIUM 6.8 CVE-2014-3187 Google Chrome before 37.0.2062.60 and 38.x before 38.0.2125.59 on iOS does not properly restrict processing of (1) facetime:// and (2) facetime-audio… Chrome after 37.0.2062.59 Fix from $1,6002014-10-08 HIGH 10.0 CVE-2011-3046 The extension subsystem in Google Chrome before 17.0.963.78 does not properly handle history navigation, which allows remote attackers to execute arb… Chrome 5.1.1 / 5.1.7+ Fix from $1,9502012-03-09 MEDIUM 6.1 CVE-2007-3484 Cross-site scripting (XSS) vulnerability in search.php in Google Custom Search Engine allows remote attackers to inject arbitrary web script or HTML … Custom Search Engine Mitigation only Fix from $1,6002007-06-28