Google Security Advisories · January 2009 — Google Security Advisories
3 advisories 3 CVEs

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2009-01. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2009-0374

GoogleActive exploitation (sightings)HIGH2009-01-30

Google Chrome 1.0.154.43 allows remote attackers to trick a user into visiting an arbitrary URL via an onclick action that moves a crafted element to the current mouse position, related to a "Clickjacking" vulnerability. NOTE: a third party disputes t...

CVEs:CVE-2009-0374

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2009-1690

GoogleEPSS <= 49%HIGH2009-01-14

Use-after-free vulnerability in WebKit, as used in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, iPhone OS for iPod touch 1.1 through 2.2.1, Google Chrome 1.0.154.53, and possibly other products, allows remote attackers to execute arbitrary cod...

CVEs:CVE-2009-1690

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
iphone_os affected apple
safari affected apple
Upstream advisory

CVE-2008-5915

GoogleEPSS <= 49%LOW2009-01-20

An unspecified function in the JavaScript implementation in Google Chrome creates and exposes a "temporary footprint" when there is a current login to a web site, which makes it easier for remote attackers to trick a user into acting upon a spoofed pop...

CVEs:CVE-2008-5915

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.