CyberSec.Space Logo
Back to CVE Browser

CVE-2016-1646

Known Exploited (CISA KEV)HIGH
8.8
CVSS Severity Score
EPSS Score40.3590%
EPSS Percentile95.05th
PublishedMar 29, 2016
Last ModifiedApr 21, 2026

Vulnerability Description

The Array.prototype.concat implementation in builtins.cc in Google V8, as used in Google Chrome before 49.0.2623.108, does not properly consider element data types, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via crafted JavaScript code.

Affected Platforms (CPE)

πŸ’»
Debian

Debian Linux

= 8.0
πŸ’»
Debian

Debian Linux

= 9.0
πŸ’»
Canonical

Ubuntu Linux

= 14.04
πŸ’»
Canonical

Ubuntu Linux

= 15.10
πŸ’»
Canonical

Ubuntu Linux

= 16.04
πŸ“¦
Google

Chrome

< 49.0.2623.108
πŸ“¦
Suse

Package Hub

All versions
πŸ’»
Opensuse

Leap

= 42.1
πŸ’»
Opensuse

Opensuse

= 13.1
πŸ’»
Redhat

Enterprise Linux Desktop

= 6.0
πŸ’»
Redhat

Enterprise Linux Eus

= 6.7
πŸ’»
Redhat

Enterprise Linux Server

= 6.0
πŸ’»
Redhat

Enterprise Linux Workstation

= 6.0

References & Advisories

Related Vulnerabilities