Google Security Advisories · June 2009 — Google Security Advisories
3 advisories 3 CVEs

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2009-06. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2009-2121

GoogleEPSS <= 49%HIGH2009-06-23

Buffer overflow in the browser kernel in Google Chrome before 2.0.172.33 allows remote HTTP servers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted response.

CVEs:CVE-2009-2121

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2009-2060

GoogleEPSS <= 49%CRITICAL2009-06-15

src/net/http/http_transaction_winhttp.cc in Google Chrome before 1.0.154.53 uses the HTTP Host header to determine the context of a document provided in a (1) 4xx or (2) 5xx CONNECT response from a proxy server, which allows man-in-the-middle attackers...

CVEs:CVE-2009-2060

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2009-2071

GoogleEPSS <= 49%MEDIUM2009-06-15

Google Chrome before 1.0.154.53 displays a cached certificate for a (1) 4xx or (2) 5xx CONNECT response page returned by a proxy server, which allows man-in-the-middle attackers to spoof an arbitrary https site by letting a browser obtain a valid certi...

CVEs:CVE-2009-2071

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.