Google

Chrome

3771 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 2.87%
  • Veröffentlicht 23.07.2015 00:59:01
  • Zuletzt bearbeitet 12.04.2025 10:46:40

PDFium, as used in Google Chrome before 44.0.2403.89, does not properly handle certain out-of-memory conditions, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a c...

  • EPSS 1.19%
  • Veröffentlicht 23.07.2015 00:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The ucnv_io_getConverterName function in common/ucnv_io.cpp in International Components for Unicode (ICU), as used in Google Chrome before 44.0.2403.89, mishandles converter names with initial x- substrings, which allows remote attackers to cause a d...

  • EPSS 0.83%
  • Veröffentlicht 26.06.2015 14:59:03
  • Zuletzt bearbeitet 12.04.2025 10:46:40

bindings/scripts/v8_types.py in Blink, as used in Google Chrome before 43.0.2357.130, does not properly select a creation context for a return value's DOM wrapper, which allows remote attackers to bypass the Same Origin Policy via crafted JavaScript ...

  • EPSS 0.92%
  • Veröffentlicht 26.06.2015 14:59:03
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The DecodeHSTSPreloadRaw function in net/http/transport_security_state.cc in Google Chrome before 43.0.2357.130 does not properly canonicalize DNS hostnames before making comparisons to HSTS or HPKP preload entries, which allows remote attackers to b...

  • EPSS 0.93%
  • Veröffentlicht 26.06.2015 14:59:01
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Blink, as used in Google Chrome before 43.0.2357.130, does not properly restrict the creation context during creation of a DOM wrapper, which allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code that uses a Blink publi...

  • EPSS 0.91%
  • Veröffentlicht 26.06.2015 14:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

content/browser/webui/content_web_ui_controller_factory.cc in Google Chrome before 43.0.2357.130 does not properly consider the scheme in determining whether a URL is associated with a WebUI SiteInstance, which allows remote attackers to bypass inten...

  • EPSS 93.9%
  • Veröffentlicht 21.05.2015 00:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a Clie...

  • EPSS 0.26%
  • Veröffentlicht 20.05.2015 10:59:19
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Multiple unspecified vulnerabilities in Google V8 before 4.3.61.21, as used in Google Chrome before 43.0.2357.65, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

  • EPSS 7.57%
  • Veröffentlicht 20.05.2015 10:59:17
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Multiple unspecified vulnerabilities in Google Chrome before 43.0.2357.65 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

  • EPSS 0.49%
  • Veröffentlicht 20.05.2015 10:59:16
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Cross-site scripting (XSS) vulnerability in Google Chrome before 43.0.2357.65 allows user-assisted remote attackers to inject arbitrary web script or HTML via crafted data that is improperly handled by the Bookmarks feature.