9.3
CVE-2016-1646
- EPSS 48.11%
- Veröffentlicht 29.03.2016 10:59:00
- Zuletzt bearbeitet 21.04.2026 17:50:52
- Erkennungen
The Array.prototype.concat implementation in builtins.cc in Google V8, as used in Google Chrome before 49.0.2623.108, does not properly consider element data types, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via crafted JavaScript code.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Debian ≫ Debian Linux Version 8.0
Debian ≫ Debian Linux Version 9.0
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 15.10
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition esm
Suse ≫ Package Hub Version -
Redhat ≫ Enterprise Linux Desktop Version 6.0
Redhat ≫ Enterprise Linux Eus Version 6.7
Redhat ≫ Enterprise Linux Server Version 6.0
Redhat ≫ Enterprise Linux Workstation Version 6.0
08.06.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog
Google Chromium V8 Out-of-Bounds Read Vulnerability
SchwachstelleGoogle Chromium V8 Engine contains an out-of-bounds read vulnerability that allows a remote attacker to cause a denial of service or possibly have another unspecified impact via crafted JavaScript code. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
BeschreibungApply updates per vendor instructions.
Erforderliche Maßnahmen| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 48.11% | 0.987 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
| NIST | 9.3 | 8.6 | 10 |
AV:N/AC:M/Au:N/C:C/I:C/A:C
|
| CISA-ADP | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
CWE-125 Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.
http://googlechromereleases.blogspot.com/2016/03/stable-channel-update_24.html
http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00000.html
http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00001.html
http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00039.html
http://rhn.redhat.com/errata/RHSA-2016-0525.html
http://www.debian.org/security/2016/dsa-3531
http://www.securitytracker.com/id/1035423
http://www.ubuntu.com/usn/USN-2955-1
https://code.google.com/p/chromium/issues/detail?id=594574
https://codereview.chromium.org/1804963002/
https://security.gentoo.org/glsa/201605-02
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-1646