CVE-2009-2556
Google Chrome before 2.0.172.37 allows attackers to leverage renderer access to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors that trigger excessive memory allocation.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.60%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Google Chrome before 2.0.172.37 allows attackers to leverage renderer access to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors that trigger excessive memory allocation.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 1.60% probability · 74th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- google/chrome
- Source
- cve@mitre.org
References
- http://googlechromereleases.blogspot.com/2009/07/stable-beta-update-bug-fixes.htmlVendor Advisory
- http://secunia.com/advisories/35844Vendor Advisory
- http://www.securityfocus.com/bid/35723
- http://www.vupen.com/english/advisories/2009/1924Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/51802
- http://googlechromereleases.blogspot.com/2009/07/stable-beta-update-bug-fixes.htmlVendor Advisory
- http://secunia.com/advisories/35844Vendor Advisory
- http://www.securityfocus.com/bid/35723
- http://www.vupen.com/english/advisories/2009/1924Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/51802
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.