VendorsGooglechrome23.0.1271.41
Vulnerabilities

Google Chrome 23.0.1271.41

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

29CVEs
CVE-2012-5144
Google Chrome before 23.0.1271.97, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.5, do not properly perform AAC decoding, which allows remote attackers to cause a denial of service (stack memory corruption) or possibly have unspecified other impact via vectors related to "an off-by-one overwrite when switching to LTP profile from MAIN."
Published 2012-12-12 · Modified
10.0EPSS 0.034
CVE-2012-5142
Google Chrome before 23.0.1271.97 does not properly handle history navigation, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors.
Published 2012-12-12 · Modified
10.0EPSS 0.027
CVE-2012-5137
Use-after-free vulnerability in Google Chrome before 23.0.1271.95 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the Media Source API.
Published 2012-12-04 · Modified
10.0EPSS 0.025
CVE-2012-5143
Integer overflow in Google Chrome before 23.0.1271.97 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to PPAPI image buffers.
Published 2012-12-12 · Modified
10.0EPSS 0.017
CVE-2012-5140
Use-after-free vulnerability in Google Chrome before 23.0.1271.97 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the URL loader.
Published 2012-12-12 · Modified
10.0EPSS 0.017
CVE-2012-5139
Use-after-free vulnerability in Google Chrome before 23.0.1271.97 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to visibility events.
Published 2012-12-12 · Modified
10.0EPSS 0.017
CVE-2012-5138
Google Chrome before 23.0.1271.95 does not properly handle file paths, which has unspecified impact and attack vectors.
Published 2012-12-04 · Modified
10.0EPSS 0.015
CVE-2012-5141
Google Chrome before 23.0.1271.97 does not properly restrict instantiation of the Chromoting client plug-in, which has unspecified impact and attack vectors.
Published 2012-12-12 · Modified
10.0EPSS 0.010
CVE-2012-5121
Use-after-free vulnerability in Google Chrome before 23.0.1271.64 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to video layout.
Published 2012-11-07 · Modified
7.5EPSS 0.016
CVE-2012-5120
Google V8 before 3.13.7.5, as used in Google Chrome before 23.0.1271.64, on 64-bit Linux platforms allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that triggers an out-of-bounds access to an array.
Published 2012-11-07 · Modified
7.5EPSS 0.015
CVE-2012-5133
Use-after-free vulnerability in Google Chrome before 23.0.1271.91 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to SVG filters.
Published 2012-11-28 · Modified
7.5EPSS 0.014
CVE-2012-5135
Use-after-free vulnerability in Google Chrome before 23.0.1271.91 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to printing.
Published 2012-11-28 · Modified
7.5EPSS 0.014
CVE-2012-5116
Use-after-free vulnerability in Google Chrome before 23.0.1271.64 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of SVG filters.
Published 2012-11-07 · Modified
7.5EPSS 0.014
CVE-2012-5126
Use-after-free vulnerability in Google Chrome before 23.0.1271.64 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of plug-in placeholders.
Published 2012-11-07 · Modified
7.5EPSS 0.014
CVE-2012-5125
Use-after-free vulnerability in Google Chrome before 23.0.1271.64 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of extension tabs.
Published 2012-11-07 · Modified
7.5EPSS 0.014
CVE-2012-5124
Google Chrome before 23.0.1271.64 does not properly handle textures, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
Published 2012-11-07 · Modified
7.5EPSS 0.014
CVE-2012-5122
Google Chrome before 23.0.1271.64 does not properly perform a cast of an unspecified variable during handling of input, which allows remote attackers to cause a denial of service or possibly have other impact via unknown vectors.
Published 2012-11-07 · Modified
7.5EPSS 0.014
CVE-2012-5128
Google V8 before 3.13.7.5, as used in Google Chrome before 23.0.1271.64, does not properly perform write operations, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
Published 2012-11-07 · Modified
7.5EPSS 0.013
CVE-2012-5131
Google Chrome before 23.0.1271.91 on Mac OS X does not properly mitigate improper rendering behavior in the Intel GPU driver, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
Published 2012-11-28 · Modified
7.5EPSS 0.013
CVE-2012-5118
Google Chrome before 23.0.1271.64 on Mac OS X does not properly validate an integer value during the handling of GPU command buffers, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
Published 2012-11-07 · Modified
7.5EPSS 0.013
CVE-2012-5115
Google Chrome before 23.0.1271.64 on Mac OS X does not properly mitigate improper write behavior in graphics drivers, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that trigger "wild writes."
Published 2012-11-07 · Modified
7.5EPSS 0.013
CVE-2012-5127
Integer overflow in Google Chrome before 23.0.1271.64 allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted WebP image.
Published 2012-11-07 · Modified
7.5EPSS 0.011
CVE-2012-5117
Google Chrome before 23.0.1271.64 does not properly restrict the loading of an SVG subresource in the context of an IMG element, which has unspecified impact and remote attack vectors.
Published 2012-11-07 · Modified
7.5EPSS 0.010
CVE-2012-5134
Heap-based buffer underflow in the xmlParseAttValueComplex function in parser.c in libxml2 2.9.0 and earlier, as used in Google Chrome before 23.0.1271.91 and other products, allows remote attackers to cause a denial of service or possibly execute arbitrary code via crafted entities in an XML document.
Published 2012-11-28 · Modified
6.8EPSS 0.044
CVE-2012-5136
Google Chrome before 23.0.1271.91 does not properly perform a cast of an unspecified variable during handling of the INPUT element, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted HTML document.
Published 2012-11-28 · Modified
6.8EPSS 0.013
CVE-2012-5119
Race condition in Pepper, as used in Google Chrome before 23.0.1271.64, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to buffers.
Published 2012-11-07 · Modified
6.8EPSS 0.010
CVE-2012-5130
Skia, as used in Google Chrome before 23.0.1271.91, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
Published 2012-11-28 · Modified
5.0EPSS 0.015
CVE-2012-5132
Google Chrome before 23.0.1271.91 allows remote attackers to cause a denial of service (application crash) via a response with chunked transfer coding.
Published 2012-11-28 · Modified
5.0EPSS 0.015
CVE-2012-5123
Skia, as used in Google Chrome before 23.0.1271.64, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
Published 2012-11-07 · Modified
5.0EPSS 0.014