VDB
CVE-2016-1646
CVE-2016-1646
PUBLISHED
KEV
CVSS 8.800000190734863 HIGH
The Array.prototype.concat implementation in builtins.cc in Google V8, as used in Google Chrome before 49.0.2623.108, does not properly consider element data types, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via crafted JavaScript code.
EPSS 48.11% · 98.7th percentile
Risk Scores
CVSS 3.0
8.800000190734863
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
48.11%
98.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:18.04:LTS | libv8-3.14 | 0, 3.14.5.8-11ubuntu1 |
| Ubuntu:16.04:LTS | chromium-browser | 0, 47.0.2526.73-0ubuntu1.1218, 48.0.2564.82-0ubuntu1.1222 |
| Ubuntu:16.04:LTS | libv8-3.14 | 3.14.5.8-5ubuntu2, 0 |
| Ubuntu:14.04:LTS | chromium-browser | 47.0.2526.106-0ubuntu0.14.04.1.1107, 0, 29.0.1547.65-0ubuntu2 |
| Ubuntu:14.04:LTS | oxide-qt | 1.6.5-0ubuntu0.14.04.1, 1.12.5-0ubuntu0.14.04.1, 1.9.5-0ubuntu0.14.04.1 |
| Ubuntu:16.04:LTS | oxide-qt | 0, 1.9.5-0ubuntu1, 1.10.3-0ubuntu0.15.10.1 |
Timeline
- Mar 25, 2016 CVE Published
- Sep 24, 2019 VulnCheck KEV Exploitation
- Sep 25, 2019 PoC Published
- Oct 9, 2020 PoC Published
- Feb 4, 2022 EPSS Score
- Jun 8, 2022 CISA KEV Added
- Jun 8, 2022 VulnCheck KEV Exploitation
- Jun 14, 2023 PoC Published
- Nov 8, 2023 EPSS Score
- Dec 5, 2024 VulnCheck KEV Exploitation
- Dec 17, 2024 EPSS Score
- Dec 24, 2024 PoC Published
References
- https://ubuntu.com/security/CVE-2016-1646 third-party-advisory
- http://googlechromereleases.blogspot.com/2016/03/ third-party-advisory
- https://ubuntu.com/security/notices/USN-2955-1 vendor-advisory
- https://www.cve.org/CVERecord?id=CVE-2016-1646 third-party-advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog third-party-advisory