CVE-2010-0647
published 2010-02-18CVE-2010-0647: WebKit before r53525, as used in Google Chrome before 4.0.249.89, allows remote attackers to execute arbitrary code in the Chrome sandbox via a malformed RUBY…
PriorityP345critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
3.51%
87.8th percentile
WebKit before r53525, as used in Google Chrome before 4.0.249.89, allows remote attackers to execute arbitrary code in the Chrome sandbox via a malformed RUBY element, as demonstrated by a > sequence.
Affected
49 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | webkit | <= r53475 | — |
| chrome | <= 4.0.249.78 | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Google Chrome up to 2.0.172.32 Sandbox code injection (ID 53525 / Nessus ID 44587)
vuldb·2026-04-30·CVSS 9.3
CVE-2010-0647 [CRITICAL] Google Chrome up to 2.0.172.32 Sandbox code injection (ID 53525 / Nessus ID 44587)
A vulnerability has been found in Google Chrome up to 2.0.172.32 and classified as critical. This affects an unknown function of the component Sandbox. Performing a manipulation results in code injection.
This vulnerability was named CVE-2010-0647. The attack may be initiated remotely. There is no available exploit.
The affected component should be upgraded.
GHSA
GHSA-jpp6-jhf5-8fqg: WebKit before r53525, as used in Google Chrome before 4
ghsa_unreviewed·2022-05-02
CVE-2010-0647 [HIGH] CWE-94 GHSA-jpp6-jhf5-8fqg: WebKit before r53525, as used in Google Chrome before 4
WebKit before r53525, as used in Google Chrome before 4.0.249.89, allows remote attackers to execute arbitrary code in the Chrome sandbox via a malformed RUBY element, as demonstrated by a > sequence.
Red Hat
webkit: remote arbitrary code execution via malformed RUBY element
vendor_redhat·2010-01-06·CVSS 9.3
CVE-2010-0647 [CRITICAL] webkit: remote arbitrary code execution via malformed RUBY element
webkit: remote arbitrary code execution via malformed RUBY element
WebKit before r53525, as used in Google Chrome before 4.0.249.89, allows remote attackers to execute arbitrary code in the Chrome sandbox via a malformed RUBY element, as demonstrated by a > sequence.
Suricata
GPL RPC portmap bootparam request UDP
suricata·2010-09-23
CVE-1999-0647 GPL RPC portmap bootparam request UDP
GPL RPC portmap bootparam request UDP
Rule: alert udp $EXTERNAL_NET any -> $HOME_NET 111 (msg:"GPL RPC portmap bootparam request UDP"; content:"|00 01 86 A0|"; depth:4; offset:12; content:"|00 00 00 03|"; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:"|00 01 86 BA|"; within:4; content:"|00 00 00 00|"; depth:4; offset:4; reference:arachnids,16; reference:cve,1999-0647; classtype:rpc-portmap-decode; sid:2100577; rev:14; metadata:created_at 2010_09_23, cve CVE_1999_0647, signature_severity Informational, updated_at 2019_07_26;)
Suricata
GPL RPC portmap bootparam request TCP
suricata·2010-09-23
CVE-1999-0647 GPL RPC portmap bootparam request TCP
GPL RPC portmap bootparam request TCP
Rule: alert tcp $EXTERNAL_NET any -> $HOME_NET 111 (msg:"GPL RPC portmap bootparam request TCP"; flow:established,to_server; content:"|00 01 86 A0|"; depth:4; offset:16; content:"|00 00 00 03|"; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:"|00 01 86 BA|"; within:4; content:"|00 00 00 00|"; depth:4; offset:8; reference:arachnids,16; reference:cve,1999-0647; classtype:rpc-portmap-decode; sid:2101264; rev:15; metadata:created_at 2010_09_23, cve CVE_1999_0647, signature_severity Informational, updated_at 2024_03_08;)
No public exploits indexed.
http://code.google.com/p/chromium/issues/detail?id=31692http://googlechromereleases.blogspot.com/2010/02/stable-channel-update.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlhttp://secunia.com/advisories/38545http://secunia.com/advisories/41856http://secunia.com/advisories/43068http://securitytracker.com/id?1023583http://sites.google.com/a/chromium.org/dev/Home/chromium-security/chromium-security-bugshttp://trac.webkit.org/changeset/53525http://www.mandriva.com/security/advisories?name=MDVSA-2011:039http://www.osvdb.org/62317http://www.securityfocus.com/bid/38177http://www.ubuntu.com/usn/USN-1006-1http://www.vupen.com/english/advisories/2010/0361http://www.vupen.com/english/advisories/2010/2722http://www.vupen.com/english/advisories/2011/0212http://www.vupen.com/english/advisories/2011/0552https://bugs.webkit.org/show_bug.cgi?id=33266https://exchange.xforce.ibmcloud.com/vulnerabilities/56214https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14094http://code.google.com/p/chromium/issues/detail?id=31692http://googlechromereleases.blogspot.com/2010/02/stable-channel-update.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlhttp://secunia.com/advisories/38545http://secunia.com/advisories/41856http://secunia.com/advisories/43068http://securitytracker.com/id?1023583http://sites.google.com/a/chromium.org/dev/Home/chromium-security/chromium-security-bugshttp://trac.webkit.org/changeset/53525http://www.mandriva.com/security/advisories?name=MDVSA-2011:039http://www.osvdb.org/62317http://www.securityfocus.com/bid/38177http://www.ubuntu.com/usn/USN-1006-1http://www.vupen.com/english/advisories/2010/0361http://www.vupen.com/english/advisories/2010/2722http://www.vupen.com/english/advisories/2011/0212http://www.vupen.com/english/advisories/2011/0552https://bugs.webkit.org/show_bug.cgi?id=33266https://exchange.xforce.ibmcloud.com/vulnerabilities/56214https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14094
2010-02-18
Published