CyberSec.Space Logo
返回 CVE 浏览器

CVE-2016-1646

Known Exploited (CISA KEV)HIGH
8.8
CVSS Severity Score
EPSS Score40.3590%
EPSS Percentile95.05th
Published2016年3月29日
Last Modified2026年4月21日

Vulnerability Description

The Array.prototype.concat implementation in builtins.cc in Google V8, as used in Google Chrome before 49.0.2623.108, does not properly consider element data types, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via crafted JavaScript code.

Affected Platforms (CPE)

💻
Debian

Debian Linux

= 8.0
💻
Debian

Debian Linux

= 9.0
💻
Canonical

Ubuntu Linux

= 14.04
💻
Canonical

Ubuntu Linux

= 15.10
💻
Canonical

Ubuntu Linux

= 16.04
📦
Google

Chrome

< 49.0.2623.108
📦
Suse

Package Hub

All versions
💻
Opensuse

Leap

= 42.1
💻
Opensuse

Opensuse

= 13.1
💻
Redhat

Enterprise Linux Desktop

= 6.0
💻
Redhat

Enterprise Linux Eus

= 6.7
💻
Redhat

Enterprise Linux Server

= 6.0
💻
Redhat

Enterprise Linux Workstation

= 6.0

References & Advisories

相关漏洞威胁