CVE-2009-0374
Last modified
CVE-2009-0374 is a vulnerability of currently unknown severity. Google Chrome 1.0.154.43 allows remote attackers to trick a user into visiting an arbitrary URL via an onclick action that moves a crafted element to the current mouse position, related to a "Clickjacking" vulnerability. NOTE: a third party disputes the relevance of this issue, stating that "every sufficiently featured browser is and likely will remain susceptible to the behavior known as clickjacking," and adding that the exploit code "is not a valid demonstration of the issue.. EPSS estimates a 2.40% chance of exploitation in the next 30 days.
Description
Google Chrome 1.0.154.43 allows remote attackers to trick a user into visiting an arbitrary URL via an onclick action that moves a crafted element to the current mouse position, related to a "Clickjacking" vulnerability. NOTE: a third party disputes the relevance of this issue, stating that "every sufficiently featured browser is and likely will remain susceptible to the behavior known as clickjacking," and adding that the exploit code "is not a valid demonstration of the issue.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Chrome | 1.0.154.43 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-0374?
How severe is CVE-2009-0374?
How do I fix CVE-2009-0374?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2009
- CVE-2009-0368OpenSC before 0.11.7 allows physically proximate attackers t…
- CVE-2009-0369Microsoft Internet Explorer 7 allows remote attackers to tri…
- CVE-2009-0370Multiple unspecified vulnerabilities in IBM AIX 5.2.0 throug…
- CVE-2009-0371Directory traversal vulnerability in post.php in SiteXS CMS …
- CVE-2009-0372Unrestricted file upload vulnerability in index.php in Milte…
- CVE-2009-0373SQL injection vulnerability in the ElearningForce Flash Maga…
- CVE-2009-0375Buffer overflow in a DLL file in RealNetworks RealPlayer 10,…
- CVE-2009-0376Heap-based buffer overflow in a DLL file in RealNetworks Rea…
- CVE-2009-0377SQL injection vulnerability in the beamospetition (com_beamo…
- CVE-2009-0378Cross-site scripting (XSS) vulnerability in index.php in the…
- CVE-2009-0379SQL injection vulnerability in the Prince Clan Chess Club (c…
- CVE-2009-0380SQL injection vulnerability in the Sigsiu Online Business In…
Are you affected by CVE-2009-0374?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
