Chromium records
8 published records for vendor chromium.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 50%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer3
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-399 Resource Management Errors1
- CWE-416 Use After Free1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
8 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
36Monitor | CVE-2023-1531No exploit | Use after free in ANGLE in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially exploit heap corruption via a crafgoogle · chrome · CWE-416 | High8.8 | — | 3.2% | Mar 21, 2023 |
36Monitor | CVE-2017-7000No exploit | An issue was discovered in certain Apple products.apple · iphone os · CWE-119 | High8.8 | — | 2.9% | Apr 3, 2018 |
31Monitor | CVE-2015-1205No exploit | Multiple unspecified vulnerabilities in Google Chrome before 40.0.2214.91 allow attackers to cause a denial of service or possibly have othegoogle · chrome | High7.5 | — | 1.8% | Jan 22, 2015 |
30Monitor | CVE-2014-7942No exploit | The Fonts implementation in Google Chrome before 40.0.2214.91 does not initialize memory for a data structure, which allows remote attackersgoogle · chrome · CWE-399 | High7.5 | — | 1.6% | Jan 22, 2015 |
30Monitor | CVE-2015-1346No exploit | Multiple unspecified vulnerabilities in Google V8 before 3.30.33.15, as used in Google Chrome before 40.0.2214.91, allow attackers to cause google · chrome | High7.5 | — | 1.2% | Jan 22, 2015 |
20Monitor | CVE-2014-7943No exploit | Skia, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecifiegoogle · chrome · CWE-119 | Medium5.0 | — | 1.6% | Jan 22, 2015 |
20Monitor | CVE-2014-7941No exploit | The SelectionOwner::ProcessTarget function in ui/base/x/selection_owner.cc in the UI implementation in Google Chrome before 40.0.2214.91 usegoogle · chrome · CWE-119 | Medium5.0 | — | 1.6% | Jan 22, 2015 |
18Monitor | CVE-2014-7939No exploit | Google Chrome before 40.0.2214.91, when the Harmony proxy in Google V8 is enabled, allows remote attackers to bypass the Same Origin Policy google · chrome · CWE-264 | Medium4.3 | — | 2.5% | Jan 22, 2015 |
- CVE-2023-153136Monitor
Use after free in ANGLE in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially exploit heap corruption via a craf
HighCVSS 8.8No exploitEPSS 3%google · chromeMar 21, 2023
- CVE-2017-700036Monitor
An issue was discovered in certain Apple products.
HighCVSS 8.8No exploitEPSS 3%apple · iphone osApr 3, 2018
- CVE-2015-120531Monitor
Multiple unspecified vulnerabilities in Google Chrome before 40.0.2214.91 allow attackers to cause a denial of service or possibly have othe
HighCVSS 7.5No exploitEPSS 2%google · chromeJan 22, 2015
- CVE-2014-794230Monitor
The Fonts implementation in Google Chrome before 40.0.2214.91 does not initialize memory for a data structure, which allows remote attackers
HighCVSS 7.5No exploitEPSS 2%google · chromeJan 22, 2015
- CVE-2015-134630Monitor
Multiple unspecified vulnerabilities in Google V8 before 3.30.33.15, as used in Google Chrome before 40.0.2214.91, allow attackers to cause
HighCVSS 7.5No exploitEPSS 1%google · chromeJan 22, 2015
- CVE-2014-794320Monitor
Skia, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecifie
MediumCVSS 5.0No exploitEPSS 2%google · chromeJan 22, 2015
- CVE-2014-794120Monitor
The SelectionOwner::ProcessTarget function in ui/base/x/selection_owner.cc in the UI implementation in Google Chrome before 40.0.2214.91 use
MediumCVSS 5.0No exploitEPSS 2%google · chromeJan 22, 2015
- CVE-2014-793918Monitor
Google Chrome before 40.0.2214.91, when the Harmony proxy in Google V8 is enabled, allows remote attackers to bypass the Same Origin Policy
MediumCVSS 4.3No exploitEPSS 3%google · chromeJan 22, 2015