VDB
CVE-2009-3934
CVE-2009-3934
PUBLISHED
CVSS 4.300000190734863 MEDIUM
The WebFrameLoaderClient::dispatchDidChangeLocationWithinPage function in src/webkit/glue/webframeloaderclient_impl.cc in Google Chrome before 3.0.195.32 allows user-assisted remote attackers to cause a denial of service via a page-local link, related to an "empty redirect chain," as demonstrated by a message in Yahoo! Mail.
EPSS 1.37% · 70.8th percentile
Risk Scores
CVSS 2.0
4.300000190734863
EPSS Score
1.37%
70.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | * |
| chrome | 0.2.152.1, 0, 0.2.149.27 |
Timeline
- Nov 12, 2009 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 21, 2022 EPSS Score
- Jul 13, 2022 EPSS Score
- Sep 5, 2022 EPSS Score
- Oct 28, 2022 EPSS Score
- Dec 20, 2022 EPSS Score
- Feb 11, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 6, 2023 EPSS Score
- May 29, 2023 EPSS Score
References
- 43068 third-party-advisory
- http://googlechromereleases.blogspot.com/2009/11/stable-channel-update.html url
- ADV-2011-0212 vdb
- http://src.chromium.org/viewvc/chrome?view=rev&revision=30772 url
- SUSE-SR:2011:002 vendor-advisory
- 59744 vdb
- http://codereview.chromium.org/326015 url
- http://code.google.com/p/chromium/issues/detail?id=22205 url
- googlechrome-webframeloader-dos(54296) vdb
- http://src.chromium.org/viewvc/chrome/branches/195/src/webkit/glue/webframeloaderclient_impl.cc?r1=30772&r2=30771 url
- https://nvd.nist.gov/vuln/detail/CVE-2009-3934 advisory