Google Security Advisories · November 2009 — Google Security Advisories
4 advisories 4 CVEs

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2009-11. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2009-3932

GoogleEPSS <= 49%HIGH2009-11-12

The Gears plugin in Google Chrome before 3.0.195.32 allows user-assisted remote attackers to cause a denial of service (memory corruption and plugin crash) or possibly execute arbitrary code via unspecified use of the Gears SQL API, related to putting ...

CVEs:CVE-2009-3932

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2009-3931

GoogleEPSS <= 49%HIGH2009-11-12

Incomplete blacklist vulnerability in browser/download/download_exe.cc in Google Chrome before 3.0.195.32 allows remote attackers to force the download of certain dangerous files via a "Content-Disposition: attachment" designation, as demonstrated by (...

CVEs:CVE-2009-3931

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2009-2816

GoogleEPSS <= 49%HIGH2009-11-12

The implementation of Cross-Origin Resource Sharing (CORS) in WebKit, as used in Apple Safari before 4.0.4 and Google Chrome before 3.0.195.33, includes certain custom HTTP headers in the OPTIONS request during cross-origin operations with preflight, w...

CVEs:CVE-2009-2816

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
iphone_os affected apple
opensuse affected opensuse
safari affected apple
Upstream advisory

CVE-2009-3934

GoogleEPSS <= 49%HIGH2009-11-12

The WebFrameLoaderClient::dispatchDidChangeLocationWithinPage function in src/webkit/glue/webframeloaderclient_impl.cc in Google Chrome before 3.0.195.32 allows user-assisted remote attackers to cause a denial of service via a page-local link, related ...

CVEs:CVE-2009-3934

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.