Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2010-0646

Quick assessment

Affected
n/a n/a
Exploitation
High exploitation probability; assess promptly
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Google Chrome是Google发布的开源WEB浏览器。 使用在浏览器Google Chrome中的Google V8的文件factory.cc存在多个整数符号错误漏洞。远程攻击者可以借助JavaScript对列的畸形使用,在Chrome沙盒中,执行任意的代码。

AI Predicted 9.8 Difficulty: Easy EPSS 4.53% · P91
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2010-0646

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
Multiple integer signedness errors in factory.cc in Google V8 before r3560, as used in Google Chrome before 4.0.249.89, allow remote attackers to execute arbitrary code in the Chrome sandbox via crafted use of JavaScript arrays.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Google Chrome Google V8 'factory.cc'整数错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Google Chrome是Google发布的开源WEB浏览器。 使用在浏览器Google Chrome中的Google V8的文件factory.cc存在多个整数符号错误漏洞。远程攻击者可以借助JavaScript对列的畸形使用,在Chrome沙盒中,执行任意的代码。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2010-0646

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2010-0646

登录查看更多情报信息。

Vendor Advisories for CVE-2010-0646 (7)

Other References for CVE-2010-0646 (3)

Same Patch Batch · n/a · 2010-02-18 · 25 CVEs total

CVE-2010-0654 Mozilla Firefox/Thunderbird/SeaMonkey download样式表敏感信息泄露漏洞
CVE-2010-0556 Google Chrome样式表重新定向信息泄露漏洞
CVE-2010-0664 Google Chrome程序函数ChildProcessSecurityPolicy::CanRequestURL栈消耗漏洞
CVE-2010-0663 Google Chrome程序内存敏感信息泄露漏洞
CVE-2010-0662 Google Chrome程序 拒绝服务攻击漏洞
CVE-2010-0661 Apple WebKit 'WebCore/bindings/v8/custom/V8DOMWindowCustom.cpp'安全绕过漏洞
CVE-2010-0660 Google Chrome敏感信息泄露漏洞
CVE-2010-0659 Apple WebKit Chrome沙盒任意代码执行漏洞
CVE-2010-0658 Google Skia多个整数溢出漏洞
CVE-2010-0657 Google Chrome桌面快捷方式代码执行和敏感信息泄露漏洞
CVE-2010-0656 Apple WebKit XMLHttpRequest请求响应信息泄露漏洞
CVE-2010-0655 Google Chrome popup窗口 拒绝服务和任意代码执行漏洞
CVE-2010-0416 Realnetworks Helix Player和RealPlayer Unescape多个缓冲区溢出漏洞
CVE-2010-0653 Opera download样式表敏感信息泄露漏洞
CVE-2010-0652 Microsoft Internet Explorer download样式表敏感信息泄露漏洞
CVE-2010-0651 Apple WebKit download样式表敏感信息泄露漏洞
CVE-2010-0650 Google Chrome和Apple Safari WebKit popup窗口安全漏洞
CVE-2010-0649 Google Chrome 'CrossCallParamsEx::CreateFromBuffer'整数溢出漏洞
CVE-2010-0648 Mozilla Firefox 目标URLdocument.styleSheets[0].href特性信息泄露漏洞
CVE-2010-0647 WebKit 代码注入漏洞

Showing top 20 of 25 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2010-0646

No comments yet


Leave a comment