CVE-2009-3263
published 2009-09-18CVE-2009-3263: Cross-site scripting (XSS) vulnerability in Google Chrome 2.x and 3.x before 3.0.195.21 allows remote attackers to inject arbitrary web script or HTML via a…
PriorityP417medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.39%
69.6th percentile
Cross-site scripting (XSS) vulnerability in Google Chrome 2.x and 3.x before 3.0.195.21 allows remote attackers to inject arbitrary web script or HTML via a (1) RSS or (2) Atom feed, related to the rendering of the application/rss+xml content type as XML "active content."
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qm5r-9c54-3rgj: Cross-site scripting (XSS) vulnerability in Google Chrome 2
ghsa_unreviewed·2022-05-02
CVE-2009-3263 [MEDIUM] CWE-79 GHSA-qm5r-9c54-3rgj: Cross-site scripting (XSS) vulnerability in Google Chrome 2
Cross-site scripting (XSS) vulnerability in Google Chrome 2.x and 3.x before 3.0.195.21 allows remote attackers to inject arbitrary web script or HTML via a (1) RSS or (2) Atom feed, related to the rendering of the application/rss+xml content type as XML "active content."
Red Hat
asterisk: IAX2 DoS vulnerability (AST-2009-006)
vendor_redhat·2009-09-03·CVSS 7.8
CVE-2009-2346 [HIGH] asterisk: IAX2 DoS vulnerability (AST-2009-006)
asterisk: IAX2 DoS vulnerability (AST-2009-006)
The IAX2 protocol implementation in Asterisk Open Source 1.2.x before 1.2.35, 1.4.x before 1.4.26.2, 1.6.0.x before 1.6.0.15, and 1.6.1.x before 1.6.1.6; Business Edition B.x.x before B.2.5.10, C.2.x before C.2.4.3, and C.3.x before C.3.1.1; and s800i 1.3.x before 1.3.0.3 allows remote attackers to cause a denial of service (call-number exhaustion) by initiating many IAX2 message exchanges, a related issue to CVE-2008-3263.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://code.google.com/p/chromium/issues/detail?id=21238http://googlechromereleases.blogspot.com/2009/09/stable-channel-update.htmlhttp://secunia.com/advisories/36770http://securethoughts.com/2009/09/exploiting-chrome-and-operas-inbuilt-atomrss-reader-with-script-execution-and-more/http://www.securityfocus.com/archive/1/506517/100/0/threadedhttp://www.securityfocus.com/bid/36416http://code.google.com/p/chromium/issues/detail?id=21238http://googlechromereleases.blogspot.com/2009/09/stable-channel-update.htmlhttp://secunia.com/advisories/36770http://securethoughts.com/2009/09/exploiting-chrome-and-operas-inbuilt-atomrss-reader-with-script-execution-and-more/http://www.securityfocus.com/archive/1/506517/100/0/threadedhttp://www.securityfocus.com/bid/36416
2009-09-18
Published