Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2009-2352


Google Chrome 1.0.154.48 and earlier does not block javascript: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header or (2) specifying the content of a Refresh header, a related issue to CVE-2009-1312. NOTE: it was later reported that 2.0.172.28, 2.0.172.37, and 3.0.193.2 Beta are also affected.


Published

2009-07-07T23:30:00.280

Last Modified

2025-04-09T00:30:58.490

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 4.3 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application google chrome ≤ 1.0.154.48 Yes
Application google chrome 0.2.149.29 Yes
Application google chrome 0.2.149.30 Yes
Application google chrome 0.2.152.1 Yes
Application google chrome 0.2.153.1 Yes
Application google chrome 0.3.154.0 Yes
Application google chrome 0.3.154.3 Yes
Application google chrome 0.4.154.18 Yes
Application google chrome 0.4.154.22 Yes
Application google chrome 0.4.154.31 Yes
Application google chrome 0.4.154.33 Yes
Application google chrome 1.0.154.36 Yes
Application google chrome 1.0.154.39 Yes
Application google chrome 1.0.154.42 Yes
Application google chrome 1.0.154.43 Yes
Application google chrome 1.0.154.46 Yes

References