CVE-2010-0646
published 2010-02-18CVE-2010-0646: Multiple integer signedness errors in factory.cc in Google V8 before r3560, as used in Google Chrome before 4.0.249.89, allow remote attackers to execute…
PriorityP346critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
4.53%
90.6th percentile
Multiple integer signedness errors in factory.cc in Google V8 before r3560, as used in Google Chrome before 4.0.249.89, allow remote attackers to execute arbitrary code in the Chrome sandbox via crafted use of JavaScript arrays.
Affected
49 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | <= 4.0.249.78 | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Google Chrome up to 2.0.172.32 factory.cc numeric error (Nessus ID 44587 / ID 116891)
vuldb·2026-04-30·CVSS 10.0
CVE-2010-0646 [CRITICAL] Google Chrome up to 2.0.172.32 factory.cc numeric error (Nessus ID 44587 / ID 116891)
A vulnerability, which was classified as critical, was found in Google Chrome up to 2.0.172.32. The impacted element is an unknown function of the file factory.cc. Such manipulation leads to numeric error.
This vulnerability is uniquely identified as CVE-2010-0646. The attack can be launched remotely. No exploit exists.
You should upgrade the affected component.
GHSA
GHSA-f8xj-3764-2w44: Multiple integer signedness errors in factory
ghsa_unreviewed·2022-05-02
CVE-2010-0646 [HIGH] GHSA-f8xj-3764-2w44: Multiple integer signedness errors in factory
Multiple integer signedness errors in factory.cc in Google V8 before r3560, as used in Google Chrome before 4.0.249.89, allow remote attackers to execute arbitrary code in the Chrome sandbox via crafted use of JavaScript arrays.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://code.google.com/p/chromium/issues/detail?id=31009http://code.google.com/p/v8/source/detail?r=3560http://codereview.chromium.org/525064http://googlechromereleases.blogspot.com/2010/02/stable-channel-update.htmlhttp://secunia.com/advisories/38545http://securitytracker.com/id?1023583http://sites.google.com/a/chromium.org/dev/Home/chromium-security/chromium-security-bugshttp://www.osvdb.org/62316http://www.securityfocus.com/bid/38177http://www.vupen.com/english/advisories/2010/0361https://exchange.xforce.ibmcloud.com/vulnerabilities/56213https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14222http://code.google.com/p/chromium/issues/detail?id=31009http://code.google.com/p/v8/source/detail?r=3560http://codereview.chromium.org/525064http://googlechromereleases.blogspot.com/2010/02/stable-channel-update.htmlhttp://secunia.com/advisories/38545http://securitytracker.com/id?1023583http://sites.google.com/a/chromium.org/dev/Home/chromium-security/chromium-security-bugshttp://www.osvdb.org/62316http://www.securityfocus.com/bid/38177http://www.vupen.com/english/advisories/2010/0361https://exchange.xforce.ibmcloud.com/vulnerabilities/56213https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14222
2010-02-18
Published