Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2015-5380

Опубликовано: 09 июл. 2015
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 7.5

Описание

The Utf8DecoderBase::WriteUtf16Slow function in unicode-decoder.cc in Google V8, as used in Node.js before 0.12.6, io.js before 1.8.3 and 2.x before 2.3.3, and other products, does not verify that there is memory available for a UTF-16 surrogate pair, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted byte sequence.

РелизСтатусПримечание
artful

ignored

end of life
bionic

not-affected

8.10.0~dfsg-2
devel

not-affected

8.11.2~dfsg-1
esm-apps/bionic

not-affected

8.10.0~dfsg-2
esm-apps/xenial

not-affected

4.2.6~dfsg-1ubuntu4.1
esm-infra-legacy/trusty

not-affected

code not present
precise

ignored

end of life
precise/esm

DNE

precise was needed
trusty

not-affected

code not present
trusty/esm

not-affected

code not present

Показывать по

EPSS

Процентиль: 72%
0.00755
Низкий

7.5 High

CVSS2

Связанные уязвимости

redhat
почти 10 лет назад

The Utf8DecoderBase::WriteUtf16Slow function in unicode-decoder.cc in Google V8, as used in Node.js before 0.12.6, io.js before 1.8.3 and 2.x before 2.3.3, and other products, does not verify that there is memory available for a UTF-16 surrogate pair, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted byte sequence.

nvd
почти 10 лет назад

The Utf8DecoderBase::WriteUtf16Slow function in unicode-decoder.cc in Google V8, as used in Node.js before 0.12.6, io.js before 1.8.3 and 2.x before 2.3.3, and other products, does not verify that there is memory available for a UTF-16 surrogate pair, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted byte sequence.

debian
почти 10 лет назад

The Utf8DecoderBase::WriteUtf16Slow function in unicode-decoder.cc in ...

github
около 3 лет назад

The Utf8DecoderBase::WriteUtf16Slow function in unicode-decoder.cc in Google V8, as used in Node.js before 0.12.6, io.js before 1.8.3 and 2.x before 2.3.3, and other products, does not verify that there is memory available for a UTF-16 surrogate pair, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted byte sequence.

suse-cvrf
больше 5 лет назад

Security update for Mozilla Firefox

EPSS

Процентиль: 72%
0.00755
Низкий

7.5 High

CVSS2