CVE-2009-3264

N/A Unknown
Published: September 18, 2009 Modified: April 23, 2026
View on NVD

Description

The getSVGDocument method in Google Chrome before 3.0.195.21 omits an unspecified "access check," which allows remote web servers to bypass the Same Origin Policy and conduct cross-site scripting attacks via unknown vectors, related to a user's visit to a different web server that hosts an SVG document.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://osvdb.org/58193
Source: cve@mitre.org
http://secunia.com/advisories/36770
Source: cve@mitre.org
Vendor Advisory
http://code.google.com/p/chromium/issues/detail?id=21338
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://osvdb.org/58193
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/36770
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://www.securityfocus.com/bid/36416
Source: af854a3a-2127-422b-91ae-364da2661108

10 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
0.2%
39th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

google