Google Security Advisories · April 2009 — Google Security Advisories
4 advisories 4 CVEs

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2009-04. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2008-6687

GoogleEPSS <= 49%CRITICAL2009-04-10

Cross-site scripting (XSS) vulnerability in DCD GoogleMap (dcdgooglemap) 1.1.0 and earlier extension for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

CVEs:CVE-2008-6687

Affected products

ProductStatusVendorPackageEcosystem
dcdgooglemap affected david_cadu
Upstream advisory

CVE-2009-1412

GoogleEPSS <= 49%CRITICAL2009-04-24

Argument injection vulnerability in the chromehtml: protocol handler in Google Chrome before 1.0.154.59, when invoked by Internet Explorer, allows remote attackers to determine the existence of files, and open tabs for URLs that do not satisfy the IsWe...

CVEs:CVE-2009-1412

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2009-1413

GoogleEPSS <= 49%CRITICAL2009-04-24

Google Chrome 1.0.x does not cancel timeouts upon a page transition, which makes it easier for attackers to conduct Universal XSS attacks by calling setTimeout to trigger future execution of JavaScript code, and then modifying document.location to arra...

CVEs:CVE-2009-1413

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2009-1414

GoogleEPSS <= 49%CRITICAL2009-04-24

Google Chrome 2.0.x lets modifications to the global object persist across a page transition, which makes it easier for attackers to conduct Universal XSS attacks via unspecified vectors.

CVEs:CVE-2009-1414

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.