Vulnerabilities > Google > Chrome

DATE CVE VULNERABILITY TITLE RISK
2009-08-19 CVE-2008-6997 Remote Denial of Service vulnerability in Google Chrome 0.2.149.27
Google Chrome 0.2.149.27 allows user-assisted remote attackers to cause a denial of service (browser crash) via an IMG tag with a long src attribute, which triggers the crash when the victim performs an "Inspect Element" action.
network
google
4.3
2009-08-19 CVE-2008-6996 Unspecified vulnerability in Google Chrome 0.2.149.27
Google Chrome BETA (0.2.149.27) does not prompt the user before saving an executable file, which makes it easier for remote attackers or malware to cause a denial of service (disk consumption) or exploit other vulnerabilities via a URL that references an executable file, possibly related to the "ask where to save each file before downloading" setting.
network
low complexity
google
5.0
2009-08-19 CVE-2008-6995 Numeric Errors vulnerability in Google Chrome 0.2.149.27
Integer underflow in net/base/escape.cc in chrome.dll in Google Chrome 0.2.149.27 allows remote attackers to cause a denial of service (browser crash) via a URI with an invalid handler followed by a "%" (percent) character, which triggers a buffer over-read, as demonstrated using an "about:%" URI.
network
google CWE-189
4.3
2009-08-19 CVE-2008-6994 Buffer Errors vulnerability in Google Chrome 0.2.149.27
Stack-based buffer overflow in the SaveAs feature (SaveFileAsWithFilter function) in win_util.cc in Google Chrome 0.2.149.27 allows user-assisted remote attackers to execute arbitrary code via a web page with a long TITLE element, which triggers the overflow when the user saves the page and a long filename is generated.
network
google CWE-119
critical
9.3
2009-08-11 CVE-2009-2416 Use After Free vulnerability in multiple products
Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notation or (2) Enumeration attribute types in an XML file, as demonstrated by the Codenomicon XML fuzzing framework.
6.5
2009-07-22 CVE-2009-2578 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Google Chrome
Google Chrome 2.x through 2.0.172 allows remote attackers to cause a denial of service (application crash) via a long Unicode string argument to the write method, a related issue to CVE-2009-2479.
network
low complexity
google CWE-119
5.0
2009-07-21 CVE-2009-2556 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Google Chrome
Google Chrome before 2.0.172.37 allows attackers to leverage renderer access to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors that trigger excessive memory allocation.
network
google CWE-119
critical
9.3
2009-07-21 CVE-2009-2555 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Google Chrome and V8
Heap-based buffer overflow in src/jsregexp.cc in Google V8 before 1.1.10.14, as used in Google Chrome before 2.0.172.37, allows remote attackers to execute arbitrary code in the Chrome sandbox via a crafted JavaScript regular expression.
network
google CWE-119
critical
9.3
2009-07-07 CVE-2009-2352 Cross-Site Scripting vulnerability in Google Chrome
Google Chrome 1.0.154.48 and earlier does not block javascript: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header or (2) specifying the content of a Refresh header, a related issue to CVE-2009-1312.
network
google CWE-79
4.3
2009-06-23 CVE-2009-2121 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Google Chrome
Buffer overflow in the browser kernel in Google Chrome before 2.0.172.33 allows remote HTTP servers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted response.
network
google CWE-119
critical
9.3