Advisories
GoogleEPSS <= 49%CRITICAL2009-02-11
Integer underflow in the Huffman decoding functionality (pvmp3_huffman_parsing.cpp) in OpenCORE 2.0 and earlier allows remote attackers to cause a denial of service (process crash) and possibly execute arbitrary code via a crafted MP3 file that trigger...
CVEs:CVE-2009-0475
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| opencore |
affected |
android |
— |
— |
GoogleEPSS <= 49%HIGH2009-02-03
Cross-domain vulnerability in the V8 JavaScript engine in Google Chrome before 1.0.154.46 allows remote attackers to bypass the Same Origin Policy via a crafted script that accesses another frame and reads its full URL and possibly other sensitive info...
CVEs:CVE-2009-0276
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2009-02-03
Google Chrome before 1.0.154.46 does not properly restrict access from web pages to the (1) Set-Cookie and (2) Set-Cookie2 HTTP response headers, which allows remote attackers to obtain sensitive information from cookies via XMLHttpRequest calls and ot...
CVEs:CVE-2009-0411
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
Open SourceEPSS <= 49%CRITICAL2009-02-17
Integer overflow in the showLog function in fake_log_device.c in liblog in Open Handset Alliance Android 1.0 allows attackers to trigger a buffer overflow and possibly have unspecified other impact by sending a large number of input lines.
CVEs:CVE-2009-0608
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android_sdk |
affected |
android |
— |
— |
Open SourceEPSS <= 49%CRITICAL2009-02-17
Multiple integer overflows in malloc_leak.c in Bionic in Open Handset Alliance Android 1.0 have unknown impact and attack vectors, related to the (1) chk_calloc and (2) leak_calloc functions.
CVEs:CVE-2009-0607
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android_sdk |
affected |
openhandsetalliance |
— |
— |
Open SourceEPSS <= 49%HIGH2009-02-17
The link_image function in linker/linker.c in the dynamic linker in Bionic in Open Handset Alliance Android 1.0 on the T-Mobile G1 phone does not properly handle file descriptors 0, 1, and 2 for a setgid program, which allows local users to create arbi...
CVEs:CVE-2009-0606
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android_sdk |
affected |
openhandsetalliance |
— |
— |