Google Security Advisories · July 2009 — Google Security Advisories
5 advisories 5 CVEs

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2009-07. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2009-2352

GoogleActive exploitation (sightings)CRITICAL2009-07-07

Google Chrome 1.0.154.48 and earlier does not block javascript: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header or (2) specifyi...

CVEs:CVE-2009-2352

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2009-2555

GoogleEPSS <= 49%HIGH2009-07-21

Heap-based buffer overflow in src/jsregexp.cc in Google V8 before 1.1.10.14, as used in Google Chrome before 2.0.172.37, allows remote attackers to execute arbitrary code in the Chrome sandbox via a crafted JavaScript regular expression.

CVEs:CVE-2009-2555

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
v8 affected google
Upstream advisory

CVE-2009-2556

GoogleEPSS <= 49%HIGH2009-07-21

Google Chrome before 2.0.172.37 allows attackers to leverage renderer access to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors that trigger excessive memory allocation.

CVEs:CVE-2009-2556

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2009-2578

GoogleEPSS <= 49%HIGH2009-07-22

Google Chrome 2.x through 2.0.172 allows remote attackers to cause a denial of service (application crash) via a long Unicode string argument to the write method, a related issue to CVE-2009-2479.

CVEs:CVE-2009-2578

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2009-2348

Open SourceEPSS <= 49%MEDIUM2009-07-17

Android 1.5 CRBxx allows local users to bypass the (1) Manifest.permission.CAMERA (aka android.permission.CAMERA) and (2) Manifest.permission.AUDIO_RECORD (aka android.permission.RECORD_AUDIO) configuration settings by installing and executing an appli...

CVEs:CVE-2009-2348

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.