CVE-2018-6128 | UXSS via URL parsing bug | 66 | May 9 2018 |
CVE-2017-5124 | UXSS with MHTML | 61 | Oct 20 2017 |
cr-687844 | window.external leaks global object + cross origin script access | 57 | Feb 2 2017 |
CVE-2017-5007 | UXSS through bypassing ScopedPageSuspender with closing windows | 55 | Dec 5 2016 |
cr-656274 | Cross-origin object leak via fetch | 56 (canary) | Oct 15 2016 |
cr-594383 | UXSS via window.open() via file:// pages | 54 | Oct 15 2016 |
CVE-2016-5207 | UXSS via fullscreen element updates | 54 | Oct 14 2016 |
CVE-2016-5204 | UXSS by intercepting a UA shadow tree | 52 | Jul 24 2016 |
CVE-2016-1676 | Persistent UXSS via SchemaRegistry | 50 | Apr 19 2016 |
CVE-2016-1667 | UXSS through adopting image elements | 50 | Apr 21 2016 |
CVE-2016-1674 | UXSS via the interception of Binding with Object.prototype.create | 49 | Mar 26 2016 |
CVE-2016-1673 | UXSS using a FrameNavigationDisabler bypass | 49 | Mar 24 2016 |
cr-583445 | UXSS in DocumentLoader::createWriterFor | 48 | Feb 2 2016 |
CVE-2016-1631 | UXSS using Flash message loop | 47 | Dec 14 2015 |
CVE-2015-6770 | UXSS using document.adoptNode | 45 | Oct 8 2015 |
CVE-2015-6769 | UXSS via the unload_event module | 45 | Sep 22 2015 |
CVE-2015-6765 | UXSS via ContainerNode::parserInsertBefore | 44 | Aug 11 2015 |
CVE-2015-1268 | UXSS using IDBKeyRange static methods | 43 | May 31 2015 |
CVE-2014-1747 | UXSS via local MHTML files | 35 | Dec 25 2013 |
CVE-2014-1701 | UXSS via dispatchEvent on iframes | 32 | Feb 11 2014 |
CVE-2011-2856 | Arbitrary cross-origin bypass using __defineGetter__ prototype override | 15 | Aug 18 2011 |
CVE-2011-3243 | Universal XSS using contentWindow.eval | 12 | May 24 2011 |
CVE-2011-1438 | bypass SOP with blob: | 11 | Mar 2 2011 |
cr-74372 | chrome://blob-internals/ XSS | 11 | Feb 28 2011 |
cr-37383 | javascript: url with a leading NULL byte can bypass cross origin protection. | ? | Mar 4 2010 |