Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Google Subscribe
Filtered by product Chrome
Total 3085 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-16074 1 Google 1 Chrome 2019-07-01 4.3 MEDIUM 6.5 MEDIUM
Insufficient policy enforcement in site isolation in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to bypass site isolation via a crafted HTML page.
CVE-2019-5785 1 Google 1 Chrome 2019-07-01 4.3 MEDIUM 6.5 MEDIUM
Incorrect convexity calculations in Skia in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page.
CVE-2019-5786 1 Google 1 Chrome 2019-07-01 4.3 MEDIUM 6.5 MEDIUM
Object lifetime issue in Blink in Google Chrome prior to 72.0.3626.121 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
CVE-2018-6150 1 Google 1 Chrome 2019-07-01 4.3 MEDIUM 6.5 MEDIUM
Incorrect handling of CORS in ServiceWorker in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
CVE-2018-6121 1 Google 1 Chrome 2019-07-01 6.8 MEDIUM 8.8 HIGH
Insufficient validation of input in Blink in Google Chrome prior to 66.0.3359.170 allowed a remote attacker to perform privilege escalation via a crafted HTML page.
CVE-2018-6128 2 Apple, Google 2 Iphone Os, Chrome 2019-07-01 4.3 MEDIUM 6.1 MEDIUM
Incorrect URL parsing in WebKit in Google Chrome on iOS prior to 67.0.3396.62 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
CVE-2018-6129 1 Google 1 Chrome 2019-07-01 4.3 MEDIUM 6.5 MEDIUM
Out of bounds array access in WebRTC in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
CVE-2018-6130 1 Google 1 Chrome 2019-07-01 4.3 MEDIUM 6.5 MEDIUM
Incorrect handling of object lifetimes in WebRTC in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
CVE-2018-6118 1 Google 1 Chrome 2019-06-28 6.8 MEDIUM 8.8 HIGH
A double-eviction in the Incognito mode cache that lead to a user-after-free in cache in Google Chrome prior to 66.0.3359.139 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page.
CVE-2018-16064 1 Google 1 Chrome 2019-06-28 4.3 MEDIUM 6.5 MEDIUM
Insufficient data validation in Extensions API in Google Chrome prior to 68.0.3440.75 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension.
CVE-2018-16069 1 Google 1 Chrome 2019-06-28 4.3 MEDIUM 6.5 MEDIUM
Unintended floating-point error accumulation in SwiftShader in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
CVE-2018-17460 1 Google 1 Chrome 2019-06-28 4.3 MEDIUM 6.5 MEDIUM
Insufficient data validation in filesystem URIs in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.
CVE-2018-17478 1 Google 1 Chrome 2019-06-28 6.8 MEDIUM 8.8 HIGH
Incorrect array position calculations in V8 in Google Chrome prior to 70.0.3538.102 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page.
CVE-2017-5028 1 Google 1 Chrome 2019-06-28 4.3 MEDIUM 6.5 MEDIUM
Insufficient data validation in V8 in Google Chrome prior to 56.0.2924.76 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
CVE-2018-6161 1 Google 1 Chrome 2019-06-28 6.8 MEDIUM 8.8 HIGH
Insufficient policy enforcement in Blink in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to bypass same origin policy via a crafted HTML page.
CVE-2018-6168 1 Google 1 Chrome 2019-06-28 4.3 MEDIUM 6.5 MEDIUM
Information leak in media engine in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
CVE-2018-6176 1 Google 1 Chrome 2019-06-28 4.6 MEDIUM 7.8 HIGH
Insufficient file type enforcement in Extensions API in Google Chrome prior to 68.0.3440.75 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted Chrome Extension.
CVE-2018-6177 1 Google 1 Chrome 2019-06-28 4.3 MEDIUM 4.3 MEDIUM
Information leak in media engine in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
CVE-2018-6138 1 Google 1 Chrome 2019-06-28 5.8 MEDIUM 8.1 HIGH
Insufficient policy enforcement in Extensions API in Google Chrome prior to 67.0.3396.62 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension.
CVE-2018-6142 1 Google 1 Chrome 2019-06-28 4.3 MEDIUM 6.5 MEDIUM
Array bounds check failure in V8 in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to perform an out of bounds memory read via a crafted PDF file.