CVE Vulnerabilities

CVE-2009-2974

Published: Aug 27, 2009 | Modified: Aug 28, 2009
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

Google Chrome 1.0.154.65, 1.0.154.48, and earlier allows remote attackers to (1) cause a denial of service (application hang) via vectors involving a chromehtml: URI value for the document.location property or (2) cause a denial of service (application hang and CPU consumption) via vectors involving a series of function calls that set a chromehtml: URI value for the document.location property.

Affected Software

Name Vendor Start Version End Version
Chrome Google * 1.0.154.48 (including)
Chrome Google 0.2.149.27 (including) 0.2.149.27 (including)
Chrome Google 0.2.149.29 (including) 0.2.149.29 (including)
Chrome Google 0.2.149.30 (including) 0.2.149.30 (including)
Chrome Google 0.2.152.1 (including) 0.2.152.1 (including)
Chrome Google 0.2.153.1 (including) 0.2.153.1 (including)
Chrome Google 0.3.154.0 (including) 0.3.154.0 (including)
Chrome Google 0.3.154.3 (including) 0.3.154.3 (including)
Chrome Google 0.4.154.18 (including) 0.4.154.18 (including)
Chrome Google 0.4.154.22 (including) 0.4.154.22 (including)
Chrome Google 0.4.154.31 (including) 0.4.154.31 (including)
Chrome Google 0.4.154.33 (including) 0.4.154.33 (including)
Chrome Google 1.0.154.36 (including) 1.0.154.36 (including)
Chrome Google 1.0.154.39 (including) 1.0.154.39 (including)
Chrome Google 1.0.154.42 (including) 1.0.154.42 (including)
Chrome Google 1.0.154.43 (including) 1.0.154.43 (including)
Chrome Google 1.0.154.46 (including) 1.0.154.46 (including)
Chrome Google 1.0.154.52 (including) 1.0.154.52 (including)
Chrome Google 1.0.154.53 (including) 1.0.154.53 (including)
Chrome Google 1.0.154.59 (including) 1.0.154.59 (including)
Chrome Google 1.0.154.65 (including) 1.0.154.65 (including)

References