Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-6764

Опубликовано: 06 дек. 2015
Источник: debian
EPSS Средний

Описание

The BasicJsonStringifier::SerializeJSArray function in json-stringifier.h in the JSON stringifier in Google V8, as used in Google Chrome before 47.0.2526.73, improperly loads array elements, which allows remote attackers to cause a denial of service (out-of-bounds memory access) or possibly have unspecified other impact via crafted JavaScript code.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libv8-3.14removedpackage
nodejsfixed4.2.3~dfsg-1package
nodejsnot-affectedjessiepackage
chromium-browserfixed47.0.2526.73-1package
chromium-browserend-of-lifewheezypackage
chromium-browserend-of-lifesqueezepackage

Примечания

  • libv8 not covered by security support

  • https://nodejs.org/en/blog/vulnerability/cve-2015-8027_cve-2015-6764/

EPSS

Процентиль: 94%
0.13719
Средний

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 9 лет назад

The BasicJsonStringifier::SerializeJSArray function in json-stringifier.h in the JSON stringifier in Google V8, as used in Google Chrome before 47.0.2526.73, improperly loads array elements, which allows remote attackers to cause a denial of service (out-of-bounds memory access) or possibly have unspecified other impact via crafted JavaScript code.

redhat
больше 9 лет назад

The BasicJsonStringifier::SerializeJSArray function in json-stringifier.h in the JSON stringifier in Google V8, as used in Google Chrome before 47.0.2526.73, improperly loads array elements, which allows remote attackers to cause a denial of service (out-of-bounds memory access) or possibly have unspecified other impact via crafted JavaScript code.

CVSS3: 9.8
nvd
больше 9 лет назад

The BasicJsonStringifier::SerializeJSArray function in json-stringifier.h in the JSON stringifier in Google V8, as used in Google Chrome before 47.0.2526.73, improperly loads array elements, which allows remote attackers to cause a denial of service (out-of-bounds memory access) or possibly have unspecified other impact via crafted JavaScript code.

CVSS3: 9.8
github
около 3 лет назад

The BasicJsonStringifier::SerializeJSArray function in json-stringifier.h in the JSON stringifier in Google V8, as used in Google Chrome before 47.0.2526.73, improperly loads array elements, which allows remote attackers to cause a denial of service (out-of-bounds memory access) or possibly have unspecified other impact via crafted JavaScript code.

suse-cvrf
больше 9 лет назад

Security update for nodejs

EPSS

Процентиль: 94%
0.13719
Средний