5

CVE-2009-2974

Exploit

Google Chrome 1.0.154.65, 1.0.154.48, and earlier allows remote attackers to (1) cause a denial of service (application hang) via vectors involving a chromehtml: URI value for the document.location property or (2) cause a denial of service (application hang and CPU consumption) via vectors involving a series of function calls that set a chromehtml: URI value for the document.location property.

Data is provided by the National Vulnerability Database (NVD)
GoogleChrome Version <= 1.0.154.48
GoogleChrome Version0.2.149.27
GoogleChrome Version0.2.149.29
GoogleChrome Version0.2.149.30
GoogleChrome Version0.2.152.1
GoogleChrome Version0.2.153.1
GoogleChrome Version0.3.154.0
GoogleChrome Version0.3.154.3
GoogleChrome Version0.4.154.18
GoogleChrome Version0.4.154.22
GoogleChrome Version0.4.154.31
GoogleChrome Version0.4.154.33
GoogleChrome Version1.0.154.36
GoogleChrome Version1.0.154.39
GoogleChrome Version1.0.154.42
GoogleChrome Version1.0.154.43
GoogleChrome Version1.0.154.46
GoogleChrome Version1.0.154.52
GoogleChrome Version1.0.154.53
GoogleChrome Version1.0.154.59
GoogleChrome Version1.0.154.65
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.54% 0.65
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P