Vulnerability Intelligence Report
CVE-2009-2555
Heap-based buffer overflow in src/jsregexp.cc in Google V8 before 1.1.10.14, as used in Google Chrome before 2.0.172.37, allows remote attackers to execute arbitrary code in the Chrome sandbox via a crafted JavaScript regular expression.
No Active Exploit Signals
CVSS Base Score
9.3
HIGH
EPSS Probability:3.43%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| v8 | all | |
| chrome | 0.2.149.29, 0.2.149.30, 0.2.152.1, 0.2.153.1, 0.3.154.0, 0.3.154.3, 0.4.154.18, 0.4.154.22, 0.4.154.31, 0.4.154.33, 1.0.154.36, 1.0.154.39, 1.0.154.42, 1.0.154.43, 1.0.154.46, 1.0.154.48, 1.0.154.52, 1.0.154.53, 1.0.154.59, 2.0.156.1, 2.0.157.0, 2.0.157.2, 2.0.158.0, 2.0.159.0, 2.0.172, 2.0.172.30, 2.0.172.31 |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
3.430%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | MITRE Corporation · N/A · USA |
| Reserved | 2009-07-21T00:00:00 |
| Published | 2009-07-21T16:00:00 |
| Patch Date | 2009-07-16 |
| Last Updated | 2024-08-07T05:52:15 |
Community Chatter & Buzz