Google Security Advisories · February 2009 — Google Security Advisories
6 advisories 6 CVEs

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2009-02. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2009-0475

GoogleEPSS <= 49%CRITICAL2009-02-11

Integer underflow in the Huffman decoding functionality (pvmp3_huffman_parsing.cpp) in OpenCORE 2.0 and earlier allows remote attackers to cause a denial of service (process crash) and possibly execute arbitrary code via a crafted MP3 file that trigger...

CVEs:CVE-2009-0475

Affected products

ProductStatusVendorPackageEcosystem
opencore affected android
Upstream advisory

CVE-2009-0276

GoogleEPSS <= 49%HIGH2009-02-03

Cross-domain vulnerability in the V8 JavaScript engine in Google Chrome before 1.0.154.46 allows remote attackers to bypass the Same Origin Policy via a crafted script that accesses another frame and reads its full URL and possibly other sensitive info...

CVEs:CVE-2009-0276

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2009-0411

GoogleEPSS <= 49%HIGH2009-02-03

Google Chrome before 1.0.154.46 does not properly restrict access from web pages to the (1) Set-Cookie and (2) Set-Cookie2 HTTP response headers, which allows remote attackers to obtain sensitive information from cookies via XMLHttpRequest calls and ot...

CVEs:CVE-2009-0411

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2009-0608

Open SourceEPSS <= 49%CRITICAL2009-02-17

Integer overflow in the showLog function in fake_log_device.c in liblog in Open Handset Alliance Android 1.0 allows attackers to trigger a buffer overflow and possibly have unspecified other impact by sending a large number of input lines.

CVEs:CVE-2009-0608

Affected products

ProductStatusVendorPackageEcosystem
android_sdk affected android
Upstream advisory

CVE-2009-0607

Open SourceEPSS <= 49%CRITICAL2009-02-17

Multiple integer overflows in malloc_leak.c in Bionic in Open Handset Alliance Android 1.0 have unknown impact and attack vectors, related to the (1) chk_calloc and (2) leak_calloc functions.

CVEs:CVE-2009-0607

Affected products

ProductStatusVendorPackageEcosystem
android_sdk affected openhandsetalliance
Upstream advisory

CVE-2009-0606

Open SourceEPSS <= 49%HIGH2009-02-17

The link_image function in linker/linker.c in the dynamic linker in Bionic in Open Handset Alliance Android 1.0 on the T-Mobile G1 phone does not properly handle file descriptors 0, 1, and 2 for a setgid program, which allows local users to create arbi...

CVEs:CVE-2009-0606

Affected products

ProductStatusVendorPackageEcosystem
android_sdk affected openhandsetalliance
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.