← All CVEs

CVE-2016-1646

high · 8.8Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply updates per vendor instructions.

Added 2022-06-08Remediation due 2022-06-22

The Array.prototype.concat implementation in builtins.cc in Google V8, as used in Google Chrome before 49.0.2623.108, does not properly consider element data types, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via crafted JavaScript code.

8.8
CVSS
48.1%
EPSS (exploit prob.)
99th
EPSS percentile
2016-03-29
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Weaknesses

CWE-125

Affected products

VendorProductAffected versions
debiandebian_linux8.0
debiandebian_linux9.0
canonicalubuntu_linux14.04
canonicalubuntu_linux15.10
canonicalubuntu_linux16.04
googlechrome< 49.0.2623.108
susepackage_huball versions
opensuseleap42.1
opensuseopensuse13.1
redhatenterprise_linux_desktop6.0
redhatenterprise_linux_eus6.7
redhatenterprise_linux_server6.0
redhatenterprise_linux_workstation6.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2016-1646