Vulnerability Database

296,515

Total vulnerabilities in the database

CVE-2009-2955

Google Chrome 1.0.154.48 and earlier allows remote attackers to cause a denial of service (CPU consumption and application hang) via JavaScript code with a long string value for the hash property (aka location.hash), a related issue to CVE-2008-5715.

  • Published: Aug 24, 2009
  • Updated: Apr 13, 2023
  • CVE: CVE-2009-2955
  • Severity: Medium
  • Exploit:

CVSS v2:

  • Severity: Medium
  • Score: 5
  • AV:N/AC:L/Au:N/C:N/I:N/A:P

CWEs:

Software From Fixed in
google / chrome 0.3.154.3 0.3.154.3.x
google / chrome 0.2.149.30 0.2.149.30.x
google / chrome 0.4.154.31 0.4.154.31.x
google / chrome 1.0.154.39 1.0.154.39.x
google / chrome - 1.0.154.48.x
google / chrome 0.2.149.27 0.2.149.27.x
google / chrome 0.4.154.33 0.4.154.33.x
google / chrome 1.0.154.43 1.0.154.43.x
google / chrome 1.0.154.42 1.0.154.42.x
google / chrome 0.4.154.18 0.4.154.18.x
google / chrome 0.2.149.29 0.2.149.29.x
google / chrome 0.2.152.1 0.2.152.1.x
google / chrome 0.3.154.0 0.3.154.0.x
google / chrome 0.2.153.1 0.2.153.1.x
google / chrome 1.0.154.36 1.0.154.36.x
google / chrome 1.0.154.46 1.0.154.46.x
google / chrome 0.4.154.22 0.4.154.22.x