Google Security Advisories · December 2004 — Google Security Advisories
2 advisories 2 CVEs

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2004-12. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2004-2475

GoogleEPSS <= 49%CRITICAL2004-12-31

Cross-site scripting (XSS) vulnerability in Google Toolbar 2.0.114.1 allows remote attackers to inject arbitrary web script via about.html in the About section. NOTE: some followup posts suggest that the demonstration code's use of the res:// protocol...

CVEs:CVE-2004-2475

Affected products

ProductStatusVendorPackageEcosystem
toolbar affected google
Upstream advisory

CVE-2004-1110

Open SourceEPSS <= 49%MEDIUM2004-12-01

The mtink status monitor before 1.0.5 for Epson printers allows local users to overwrite arbitrary files via a symlink attack on the epson temporary file.

CVEs:CVE-2004-1110

Affected products

ProductStatusVendorPackageEcosystem
linux affected gentoo
mtink affected jean-jacques_sarton
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.