Google Security Advisories · September 2009 — Google Security Advisories
5 advisories 5 CVEs

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2009-09. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2008-7246

GoogleActive exploitation (sightings)HIGH2009-09-18

Google Chrome 0.2.149.29 and earlier allows remote attackers to cause a denial of service (unusable browser) by calling the window.print function in a loop, aka a "printing DoS attack," possibly a related issue to CVE-2009-0821.

CVEs:CVE-2008-7246

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2009-3264

GoogleEPSS <= 49%CRITICAL2009-09-18

The getSVGDocument method in Google Chrome before 3.0.195.21 omits an unspecified "access check," which allows remote web servers to bypass the Same Origin Policy and conduct cross-site scripting attacks via unknown vectors, related to a user's visit t...

CVEs:CVE-2009-3264

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2009-3263

GoogleEPSS <= 49%CRITICAL2009-09-18

Cross-site scripting (XSS) vulnerability in Google Chrome 2.x and 3.x before 3.0.195.21 allows remote attackers to inject arbitrary web script or HTML via a (1) RSS or (2) Atom feed, related to the rendering of the application/rss+xml content type as X...

CVEs:CVE-2009-3263

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2009-3268

GoogleEPSS <= 49%HIGH2009-09-18

Google Chrome 1.0.154.48 and earlier allows remote attackers to cause a denial of service (CPU consumption) via an automatically submitted form containing a KEYGEN element, a related issue to CVE-2009-1828.

CVEs:CVE-2009-3268

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2009-3456

GoogleEPSS <= 49%CRITICAL2009-09-29

Google Chrome, possibly 3.0.195.21 and earlier, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a cr...

CVEs:CVE-2009-3456

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.