VDB
CVE-2008-5749
CVE-2008-5749
PUBLISHED
CVSS 6.800000190734863 MEDIUM
** DISPUTED ** Argument injection vulnerability in Google Chrome 1.0.154.36 on Windows XP SP3 allows remote attackers to execute arbitrary commands via the --renderer-path option in a chromehtml: URI. NOTE: a third party disputes this issue, stating that Chrome "will ask for user permission" and "cannot launch the applet even [if] you have given out the permission."
EPSS 3.73% · 89.3th percentile
Risk Scores
CVSS 2.0
6.800000190734863
EPSS Score
3.73%
89.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| chrome | 1.0.154.36 | |
| n/a | n/a | n/a |
Timeline
- Dec 23, 2008 PoC Published
- Dec 29, 2008 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 13, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Feb 10, 2023 EPSS Score
- Apr 4, 2023 EPSS Score
- May 27, 2023 EPSS Score
- Sep 9, 2023 EPSS Score
- Nov 1, 2023 EPSS Score
References
- http://retrogod.altervista.org/9sg_chrome.html url
- 20081226 Re: Re: Google Chrome Browser (ChromeHTML://) remote parameter injection POC mailing-list
- 7566 exploit
- 20081225 Re: Google Chrome Browser (ChromeHTML://) remote parameter injection POC mailing-list
- 4821 third-party-advisory
- 32997 vdb
- 20081223 Google Chrome Browser (ChromeHTML://) remote parameter injection POC mailing-list
- https://nvd.nist.gov/vuln/detail/CVE-2008-5749 advisory