CVE-2007-6536
- EPSS 0.97%
- Published 27.12.2007 23:46:00
- Last modified 09.04.2025 00:30:58
The Custom Button Installer dialog in Google Toolbar 4 and 5 beta presents certain domain names in the (1) "Downloaded from" and (2) "Privacy considerations" sections without verifying domain names, which makes it easier for remote attackers to spoof...
CVE-2004-2475
- EPSS 0.86%
- Published 31.12.2004 05:00:00
- Last modified 03.04.2025 01:03:51
Cross-site scripting (XSS) vulnerability in Google Toolbar 2.0.114.1 allows remote attackers to inject arbitrary web script via about.html in the About section. NOTE: some followup posts suggest that the demonstration code's use of the res:// protoc...
CVE-2002-1442
- EPSS 0.68%
- Published 11.04.2003 04:00:00
- Last modified 03.04.2025 01:03:51
The Google toolbar 1.1.58 and earlier allows remote web sites to perform unauthorized toolbar operations including script execution and file reading in other zones such as "My Computer" by opening a window to tools.google.com or the res: protocol, th...
- EPSS 0.38%
- Published 11.04.2003 04:00:00
- Last modified 03.04.2025 01:03:51
The Google toolbar 1.1.58 and earlier allows remote web sites to monitor a user's input into the toolbar via an "onkeydown" event handler.
CVE-2002-1444
- EPSS 17.1%
- Published 15.08.2002 04:00:00
- Last modified 03.04.2025 01:03:51
The Google toolbar 1.1.60, when running on Internet Explorer 5.5 and 6.0, allows remote attackers to cause a denial of service (crash with an exception in oleaut32.dll) via malicious HTML, possibly related to small width and height parameters or an i...