- EPSS 0.31%
- Veröffentlicht 18.09.2009 22:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Google Chrome 1.0.154.48 and earlier allows remote attackers to cause a denial of service (CPU consumption) via an automatically submitted form containing a KEYGEN element, a related issue to CVE-2009-1828.
CVE-2009-3011
- EPSS 0.24%
- Veröffentlicht 31.08.2009 16:30:06
- Zuletzt bearbeitet 09.04.2025 00:30:58
Google Chrome 1.0.154.48 and earlier, 2.0.172.28, 2.0.172.37, and 3.0.193.2 Beta does not properly block data: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related ...
CVE-2009-2973
- EPSS 0.12%
- Veröffentlicht 27.08.2009 17:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Google Chrome before 2.0.172.43 does not prevent SSL connections to a site with an X.509 certificate signed with the (1) MD2 or (2) MD4 algorithm, which makes it easier for man-in-the-middle attackers to spoof arbitrary HTTPS servers via a crafted ce...
- EPSS 0.54%
- Veröffentlicht 27.08.2009 17:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Google Chrome 1.0.154.65, 1.0.154.48, and earlier allows remote attackers to (1) cause a denial of service (application hang) via vectors involving a chromehtml: URI value for the document.location property or (2) cause a denial of service (applicati...
- EPSS 2.04%
- Veröffentlicht 27.08.2009 17:00:01
- Zuletzt bearbeitet 09.04.2025 00:30:58
Google V8, as used in Google Chrome before 2.0.172.43, allows remote attackers to bypass intended restrictions on reading memory, and possibly obtain sensitive information or execute arbitrary code in the Chrome sandbox, via crafted JavaScript.
CVE-2008-7061
- EPSS 7.51%
- Veröffentlicht 24.08.2009 19:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The tooltip manager (chrome/views/tooltip_manager.cc) in Google Chrome 0.2.149.29 Build 1798 and possibly other versions before 0.2.149.30 allows remote attackers to cause a denial of service (CPU consumption or crash) via a tag with a long title att...
- EPSS 0.31%
- Veröffentlicht 24.08.2009 15:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Google Chrome 1.0.154.48 and earlier allows remote attackers to cause a denial of service (CPU consumption and application hang) via JavaScript code with a long string value for the hash property (aka location.hash), a related issue to CVE-2008-5715.
CVE-2008-6994
- EPSS 19.3%
- Veröffentlicht 19.08.2009 05:24:52
- Zuletzt bearbeitet 09.04.2025 00:30:58
Stack-based buffer overflow in the SaveAs feature (SaveFileAsWithFilter function) in win_util.cc in Google Chrome 0.2.149.27 allows user-assisted remote attackers to execute arbitrary code via a web page with a long TITLE element, which triggers the ...
CVE-2008-6995
- EPSS 9.8%
- Veröffentlicht 19.08.2009 05:24:52
- Zuletzt bearbeitet 09.04.2025 00:30:58
Integer underflow in net/base/escape.cc in chrome.dll in Google Chrome 0.2.149.27 allows remote attackers to cause a denial of service (browser crash) via a URI with an invalid handler followed by a "%" (percent) character, which triggers a buffer ov...
- EPSS 15.09%
- Veröffentlicht 19.08.2009 05:24:52
- Zuletzt bearbeitet 09.04.2025 00:30:58
Google Chrome BETA (0.2.149.27) does not prompt the user before saving an executable file, which makes it easier for remote attackers or malware to cause a denial of service (disk consumption) or exploit other vulnerabilities via a URL that reference...