CVE-2009-2935
Last modified
CVE-2009-2935 is a vulnerability of currently unknown severity. Google V8, as used in Google Chrome before 2.0.172.43, allows remote attackers to bypass intended restrictions on reading memory, and possibly obtain sensitive information or execute arbitrary code in the Chrome sandbox, via crafted JavaScript.. EPSS estimates a 5.00% chance of exploitation in the next 30 days.
Description
Google V8, as used in Google Chrome before 2.0.172.43, allows remote attackers to bypass intended restrictions on reading memory, and possibly obtain sensitive information or execute arbitrary code in the Chrome sandbox, via crafted JavaScript.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Chrome | <= 2.0.172.37 | |
| Chrome | 0.2.149.27 | |
| Chrome | 0.2.149.29 | |
| Chrome | 0.2.149.30 | |
| Chrome | 0.2.152.1 | |
| Chrome | 0.2.153.1 | |
| Chrome | 0.3.154.0 | |
| Chrome | 0.3.154.3 | |
| Chrome | 0.4.154.18 | |
| Chrome | 0.4.154.22 | |
| Chrome | 0.4.154.31 | |
| Chrome | 0.4.154.33 | |
| Chrome | 1.0.154.36 | |
| Chrome | 1.0.154.39 | |
| Chrome | 1.0.154.42 | |
| Chrome | 1.0.154.43 | |
| Chrome | 1.0.154.46 | |
| Chrome | 1.0.154.48 | |
| Chrome | 1.0.154.52 | |
| Chrome | 1.0.154.53 | |
| Chrome | 1.0.154.59 | |
| Chrome | 2.0.156.1 | |
| Chrome | 2.0.157.0 | |
| Chrome | 2.0.157.2 | |
| Chrome | 2.0.158.0 | |
| Chrome | 2.0.159.0 | |
| Chrome | 2.0.172 | |
| Chrome | 2.0.172.30 | |
| Chrome | 2.0.172.31 | |
| Chrome | 2.0.172.33 |
References
- http://code.google.com/p/chromium/issues/detail?id=18639Vendor Advisory
- http://secunia.com/advisories/36417Vendor Advisory
- http://www.vupen.com/english/advisories/2009/2420Vendor Advisory
- http://code.google.com/p/chromium/issues/detail?id=18639Vendor Advisory
- http://secunia.com/advisories/36417Vendor Advisory
- http://www.vupen.com/english/advisories/2009/2420Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-2935?
How severe is CVE-2009-2935?
How do I fix CVE-2009-2935?
Are you affected by CVE-2009-2935?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
