Vulnerabilities > Google > High

DATE CVE VULNERABILITY TITLE RISK
2010-05-28 CVE-2010-2110 Unspecified vulnerability in Google Chrome
Google Chrome before 5.0.375.55 does not properly execute JavaScript code in the extension context, which has unspecified impact and remote attack vectors.
network
low complexity
google
7.5
2010-05-28 CVE-2010-2109 Unspecified vulnerability in Google Chrome
Unspecified vulnerability in Google Chrome before 5.0.375.55 allows user-assisted remote attackers to cause a denial of service (memory error) or possibly have unspecified other impact via vectors related to the "drag + drop" functionality.
network
low complexity
google
7.5
2010-05-28 CVE-2010-2108 Unspecified vulnerability in Google Chrome
Unspecified vulnerability in Google Chrome before 5.0.375.55 allows remote attackers to bypass the whitelist-mode plugin blocker via unknown vectors.
network
low complexity
google
7.5
2010-05-03 CVE-2010-1665 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Google Chrome
Google Chrome before 4.1.249.1064 does not properly handle fonts, which allows remote attackers to cause a denial of service (memory corruption) and possibly have unspecified other impact via unknown vectors.
network
low complexity
google CWE-119
7.5
2010-04-23 CVE-2010-1506 Multiple Security vulnerability in RETIRED: Google Chrome prior to 4.1.249.1059
The Google V8 bindings in Google Chrome before 4.1.249.1059 allow attackers to cause a denial of service (memory corruption) via unknown vectors.
network
low complexity
google
7.8
2010-04-23 CVE-2010-1500 Multiple Security vulnerability in RETIRED: Google Chrome prior to 4.1.249.1059
Google Chrome before 4.1.249.1059 does not properly support forms, which has unknown impact and attack vectors, related to a "type confusion error."
network
low complexity
google
7.5
2010-04-01 CVE-2010-1237 Improper Input Validation vulnerability in Google Chrome
Google Chrome 4.1 BETA before 4.1.249.1036 allows remote attackers to cause a denial of service (memory error) or possibly have unspecified other impact via an empty SVG element.
network
low complexity
google CWE-20
7.5
2010-04-01 CVE-2010-1234 Remote Security vulnerability in Chrome
Unspecified vulnerability in Google Chrome before 4.1.249.1036 allows remote attackers to truncate the URL shown in the HTTP Basic Authentication dialog via unknown vectors.
network
low complexity
google
7.5
2010-04-01 CVE-2010-1231 Remote Security vulnerability in Chrome
Google Chrome before 4.1.249.1036 processes HTTP headers before invoking the SafeBrowsing feature, which allows remote attackers to have an unspecified impact via crafted headers.
network
low complexity
google
7.5
2009-09-29 CVE-2009-3456 Cryptographic Issues vulnerability in Google Chrome
Google Chrome, possibly 3.0.195.21 and earlier, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
network
low complexity
google CWE-310
7.5