Google Security Advisories · October 2008 — Google Security Advisories
2 advisories 2 CVEs

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2008-10. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2008-4706

GoogleEPSS <= 49%CRITICAL2008-10-23

SQL injection vulnerability in VBGooglemap Hotspot Edition 1.0.3, a vBulletin module, allows remote attackers to execute arbitrary SQL commands via the mapid parameter in a showdetails action to (1) vbgooglemaphse.php and (2) mapa.php.

CVEs:CVE-2008-4706

Affected products

ProductStatusVendorPackageEcosystem
vbgooglemap affected vbulletin
Upstream advisory

CVE-2008-4724

GoogleEPSS <= 49%CRITICAL2008-10-23

Multiple cross-site scripting (XSS) vulnerabilities in Google Chrome 0.2.149.30 allow remote attackers to inject arbitrary web script or HTML via an ftp:// URL for an HTML document within a (1) JPG, (2) PDF, or (3) TXT file. NOTE: the provenance of th...

CVEs:CVE-2008-4724

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.