Vulnerabilities > Google > Chrome > 18.0.1025.166

DATE CVE VULNERABILITY TITLE RISK
2012-05-16 CVE-2011-3092 Improper Input Validation vulnerability in Google Chrome
The regex implementation in Google V8, as used in Google Chrome before 19.0.1084.46, allows remote attackers to cause a denial of service (invalid write operation) or possibly have unspecified other impact via unknown vectors.
network
low complexity
google CWE-20
critical
10.0
2012-05-16 CVE-2011-3091 Resource Management Errors vulnerability in Google Chrome
Use-after-free vulnerability in the IndexedDB implementation in Google Chrome before 19.0.1084.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
network
low complexity
google CWE-399
critical
10.0
2012-05-16 CVE-2011-3090 Race Condition vulnerability in Google Chrome
Race condition in Google Chrome before 19.0.1084.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to worker processes.
network
high complexity
google CWE-362
7.6
2012-05-16 CVE-2011-3089 Resource Management Errors vulnerability in Google Chrome
Use-after-free vulnerability in Google Chrome before 19.0.1084.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving tables.
network
low complexity
google CWE-399
critical
10.0
2012-05-16 CVE-2011-3088 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Google Chrome
Google Chrome before 19.0.1084.46 does not properly draw hairlines, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
network
low complexity
google CWE-119
5.0
2012-05-16 CVE-2011-3086 Resource Management Errors vulnerability in Google Chrome
Use-after-free vulnerability in Google Chrome before 19.0.1084.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving a STYLE element.
network
low complexity
google CWE-399
critical
10.0
2012-05-16 CVE-2011-3085 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Google Chrome
The Autofill feature in Google Chrome before 19.0.1084.46 does not properly restrict field values, which allows remote attackers to cause a denial of service (UI corruption) and possibly conduct spoofing attacks via vectors involving long values.
network
low complexity
google CWE-119
5.0
2012-05-16 CVE-2011-3084 Permissions, Privileges, and Access Controls vulnerability in Google Chrome
Google Chrome before 19.0.1084.46 does not use a dedicated process for the loading of links found on an internal page, which might allow attackers to bypass intended sandbox restrictions via a crafted page.
network
low complexity
google CWE-264
7.5
2012-05-16 CVE-2011-3083 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Google Chrome
browser/profiles/profile_impl_io_data.cc in Google Chrome before 19.0.1084.46 does not properly handle a malformed ftp URL in the SRC attribute of a VIDEO element, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted web page.
network
low complexity
google CWE-119
5.0
2012-05-01 CVE-2012-1521 USE After Free vulnerability in Google Chrome
Use-after-free vulnerability in the XML parser in Google Chrome before 18.0.1025.168 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
network
google apple CWE-416
6.8