Vulnerabilities (CVE)

Filtered by vendor Google Subscribe
Total 14884 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2004-2475 1 Google 1 Toolbar 2026-06-16 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Google Toolbar 2.0.114.1 allows remote attackers to inject arbitrary web script via about.html in the About section. NOTE: some followup posts suggest that the demonstration code's use of the res:// protocol does not cross privilege boundaries, since it is not allowed in the Internet Zone. Thus this might not be a vulnerability.
CVE-2002-1444 2 Google, Microsoft 2 Toolbar, Internet Explorer 2026-06-16 2.6 LOW N/A
The Google toolbar 1.1.60, when running on Internet Explorer 5.5 and 6.0, allows remote attackers to cause a denial of service (crash with an exception in oleaut32.dll) via malicious HTML, possibly related to small width and height parameters or an incorrect call to the Google.Search() function.
CVE-2002-1443 1 Google 1 Toolbar 2026-06-16 5.0 MEDIUM N/A
The Google toolbar 1.1.58 and earlier allows remote web sites to monitor a user's input into the toolbar via an "onkeydown" event handler.
CVE-2002-1442 1 Google 1 Toolbar 2026-06-16 7.5 HIGH N/A
The Google toolbar 1.1.58 and earlier allows remote web sites to perform unauthorized toolbar operations including script execution and file reading in other zones such as "My Computer" by opening a window to tools.google.com or the res: protocol, then using script to modify the window's location to the toolbar's configuration URL, which bypasses the origin verification check.