CVE-2009-3264
The getSVGDocument method in Google Chrome before 3.0.195.21 omits an unspecified "access check," which allows remote web servers to bypass the Same Origin Policy and conduct cross-site scripting attacks via unknown vectors, related to a user's visit to…
Does this matter?
Lower severity and a low EPSS score (3.50%). Track it; it rarely justifies an emergency change on its own.
Description
The getSVGDocument method in Google Chrome before 3.0.195.21 omits an unspecified "access check," which allows remote web servers to bypass the Same Origin Policy and conduct cross-site scripting attacks via unknown vectors, related to a user's visit to a different web server that hosts an SVG document.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 3.50% probability · 88th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- google/chrome
- Source
- cve@mitre.org
References
- http://code.google.com/p/chromium/issues/detail?id=21338Vendor Advisory
- http://googlechromereleases.blogspot.com/2009/09/stable-channel-update.html
- http://osvdb.org/58193
- http://secunia.com/advisories/36770Vendor Advisory
- http://www.securityfocus.com/bid/36416
- http://code.google.com/p/chromium/issues/detail?id=21338Vendor Advisory
- http://googlechromereleases.blogspot.com/2009/09/stable-channel-update.html
- http://osvdb.org/58193
- http://secunia.com/advisories/36770Vendor Advisory
- http://www.securityfocus.com/bid/36416
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.