CVE-2010-0649
published 2010-02-18CVE-2010-0649: Integer overflow in the CrossCallParamsEx::CreateFromBuffer function in sandbox/src/crosscall_server.cc in Google Chrome before 4.0.249.89 allows attackers to…
PriorityP427critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
1.26%
66.6th percentile
Integer overflow in the CrossCallParamsEx::CreateFromBuffer function in sandbox/src/crosscall_server.cc in Google Chrome before 4.0.249.89 allows attackers to leverage renderer access to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a malformed message, related to deserializing of sandbox messages.
Affected
47 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | <= 4.0.249.78 | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Google Chrome up to 2.0.172.32 crosscall_server.cc CreateFromBuffer numeric error (Nessus ID 44587 / ID 116891)
vuldb·2026-04-30·CVSS 9.3
CVE-2010-0649 [CRITICAL] Google Chrome up to 2.0.172.32 crosscall_server.cc CreateFromBuffer numeric error (Nessus ID 44587 / ID 116891)
A vulnerability was found in Google Chrome up to 2.0.172.32. It has been classified as critical. Affected is the function CrossCallParamsEx::CreateFromBuffer of the file sandbox/src/crosscall_server.cc. The manipulation leads to numeric error.
This vulnerability is referenced as CVE-2010-0649. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is recommended.
GHSA
GHSA-4472-77jr-3q62: Integer overflow in the CrossCallParamsEx::CreateFromBuffer function in sandbox/src/crosscall_server
ghsa_unreviewed·2022-05-02
CVE-2010-0649 [HIGH] GHSA-4472-77jr-3q62: Integer overflow in the CrossCallParamsEx::CreateFromBuffer function in sandbox/src/crosscall_server
Integer overflow in the CrossCallParamsEx::CreateFromBuffer function in sandbox/src/crosscall_server.cc in Google Chrome before 4.0.249.89 allows attackers to leverage renderer access to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a malformed message, related to deserializing of sandbox messages.
Suricata
GPL SQL Slammer Worm propagation attempt
suricata·2010-09-23
CVE-2002-0649 GPL SQL Slammer Worm propagation attempt
GPL SQL Slammer Worm propagation attempt
Rule: alert udp $EXTERNAL_NET any -> $HOME_NET 1434 (msg:"GPL SQL Slammer Worm propagation attempt"; content:"|04|"; depth:1; content:"|81 F1 03 01 04 9B 81 F1 01|"; content:"sock"; content:"send"; reference:bugtraq,5310; reference:bugtraq,5311; reference:cve,2002-0649; reference:nessus,11214; reference:url,vil.nai.com/vil/content/v_99992.htm; classtype:misc-attack; sid:2102003; rev:9; metadata:created_at 2010_09_23, cve CVE_2002_0649, confidence Medium, signature_severity Informational, updated_at 2019_07_26;)
Suricata
GPL WORM Slammer Worm propagation attempt OUTBOUND
suricata·2010-09-23
CVE-2002-0649 GPL WORM Slammer Worm propagation attempt OUTBOUND
GPL WORM Slammer Worm propagation attempt OUTBOUND
Rule: alert udp $HOME_NET any -> $EXTERNAL_NET 1434 (msg:"GPL WORM Slammer Worm propagation attempt OUTBOUND"; content:"|04|"; depth:1; content:"|81 F1 03 01 04 9B 81 F1|"; content:"sock"; content:"send"; reference:bugtraq,5310; reference:bugtraq,5311; reference:cve,2002-0649; reference:nessus,11214; reference:url,vil.nai.com/vil/content/v_99992.htm; classtype:misc-attack; sid:2102004; rev:8; metadata:created_at 2010_09_23, cve CVE_2002_0649, confidence Medium, signature_severity Informational, updated_at 2019_07_26;)
No writeups or analysis indexed.
http://code.google.com/p/chromium/issues/detail?id=32915http://googlechromereleases.blogspot.com/2010/02/stable-channel-update.htmlhttp://secunia.com/advisories/38545http://securitytracker.com/id?1023583http://sites.google.com/a/chromium.org/dev/Home/chromium-security/chromium-security-bugshttp://www.osvdb.org/62320http://www.securityfocus.com/bid/38177http://www.vupen.com/english/advisories/2010/0361https://exchange.xforce.ibmcloud.com/vulnerabilities/56217https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14256http://code.google.com/p/chromium/issues/detail?id=32915http://googlechromereleases.blogspot.com/2010/02/stable-channel-update.htmlhttp://secunia.com/advisories/38545http://securitytracker.com/id?1023583http://sites.google.com/a/chromium.org/dev/Home/chromium-security/chromium-security-bugshttp://www.osvdb.org/62320http://www.securityfocus.com/bid/38177http://www.vupen.com/english/advisories/2010/0361https://exchange.xforce.ibmcloud.com/vulnerabilities/56217https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14256
2010-02-18
Published