Google Security Advisories · June 2007 — Google Security Advisories
2 advisories 2 CVEs

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2007-06. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2007-3150

GoogleEPSS <= 49%HIGH2007-06-11

Google Desktop allows user-assisted remote attackers to execute arbitrary programs via a man-in-the-middle attack that injects JavaScript, a www.google.com search IFRAME, and a META HTTP-EQUIV="refresh" that targets a www.google.com search for a local ...

CVEs:CVE-2007-3150

Affected products

ProductStatusVendorPackageEcosystem
desktop affected google
Upstream advisory

CVE-2007-3484

GoogleEPSS <= 49%CRITICAL2007-06-28

Cross-site scripting (XSS) vulnerability in search.php in Google Custom Search Engine allows remote attackers to inject arbitrary web script or HTML via the q parameter. NOTE: this issue is disputed by the Google Security Team, who states that "Google...

CVEs:CVE-2007-3484

Affected products

ProductStatusVendorPackageEcosystem
custom_search_engine affected google
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.