CVE-2009-0374
Google Chrome 1.0.154.43 - Clickjacking
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Google Chrome 1.0.154.43 allows remote attackers to trick a user into visiting an arbitrary URL via an onclick action that moves a crafted element to the current mouse position, related to a "Clickjacking" vulnerability. NOTE: a third party disputes the relevance of this issue, stating that "every sufficiently featured browser is and likely will remain susceptible to the behavior known as clickjacking," and adding that the exploit code "is not a valid demonstration of the issue.
** IMPUGNADA ** Google Chrome v1.0.154.43 permite a atacantes remotos engañar a un usuario para que visite una URL de su elección mediante una acción "onclick" que mueve un elemento modificado a la posición actual del ratón, relacionado con la vulnerabilidad "Clickjacking". NOTA: una tercera parte cuestiona la relevancia de este asunto, exponiendo que "cualquier navegador suficientemente expuesto es y probablemente continuará siendo susceptible del comportamiento conocido como clickjacking", y añade que el código que explota esta vulnerabilidad no es una demostración válida de la misma.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2009-01-30 CVE Reserved
- 2009-01-30 CVE Published
- 2024-03-21 EPSS Updated
- 2024-08-07 CVE Updated
- 2024-08-07 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
http://www.secniche.org/gcr_clkj | X_refsource_misc | |
http://www.securityfocus.com/archive/1/500499/100/0/threaded | Mailing List | |
http://www.securityfocus.com/archive/1/500533/100/0/threaded | Mailing List |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/7903 | 2024-08-07 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 1.0.154.43 Search vendor "Google" for product "Chrome" and version "1.0.154.43" | - |
Affected
|