CVE-2013-6638
published 2013-12-07CVE-2013-6638: Multiple buffer overflows in runtime.cc in Google V8 before 3.22.24.7, as used in Google Chrome before 31.0.1650.63, allow remote attackers to cause a denial…
PriorityP432high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
1.95%
77.9th percentile
Multiple buffer overflows in runtime.cc in Google V8 before 3.22.24.7, as used in Google Chrome before 31.0.1650.63, allow remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger a large typed array, related to the (1) Runtime_TypedArrayInitialize and (2) Runtime_TypedArrayInitializeFromArrayLike functions.
Affected
83 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | <= 31.0.1650.62 | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jwf6-397g-h7f5: Multiple buffer overflows in runtime
ghsa_unreviewed·2022-05-17
CVE-2013-6638 [HIGH] CWE-119 GHSA-jwf6-397g-h7f5: Multiple buffer overflows in runtime
Multiple buffer overflows in runtime.cc in Google V8 before 3.22.24.7, as used in Google Chrome before 31.0.1650.63, allow remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger a large typed array, related to the (1) Runtime_TypedArrayInitialize and (2) Runtime_TypedArrayInitializeFromArrayLike functions.
OSV
CVE-2013-6638: Multiple buffer overflows in runtime
osv·2013-12-07·CVSS 7.5
CVE-2013-6638 [HIGH] CVE-2013-6638: Multiple buffer overflows in runtime
Multiple buffer overflows in runtime.cc in Google V8 before 3.22.24.7, as used in Google Chrome before 31.0.1650.63, allow remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger a large typed array, related to the (1) Runtime_TypedArrayInitialize and (2) Runtime_TypedArrayInitializeFromArrayLike functions.
Red Hat
v8: multiple buffer overflows in runtime.cc
vendor_redhat·2013-12-04·CVSS 7.5
CVE-2013-6638 [HIGH] v8: multiple buffer overflows in runtime.cc
v8: multiple buffer overflows in runtime.cc
Multiple buffer overflows in runtime.cc in Google V8 before 3.22.24.7, as used in Google Chrome before 31.0.1650.63, allow remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger a large typed array, related to the (1) Runtime_TypedArrayInitialize and (2) Runtime_TypedArrayInitializeFromArrayLike functions.
Statement: Not Vulnerable. This issue only affects versions of v8 that support typed arrays. This issue does not affect the versions of v8 as shipped with various Red Hat products.
Package: ruby193-v8 (CloudForms Management Engine 5) - Not affected
Package: ruby193-v8 (OpenShift Enterprise 1) - Not affected
Package: v8 (Red Hat OpenShift Enterprise 2) - Not affected
Package: ruby19
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-6638 v8: multiple buffer overflows in runtime.cc [epel-6]
bugzilla·2013-12-10·CVSS 7.5
CVE-2013-6638 [HIGH] CVE-2013-6638 v8: multiple buffer overflows in runtime.cc [epel-6]
CVE-2013-6638 v8: multiple buffer overflows in runtime.cc [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epel-6 tracking bug for v8: see b
Bugzilla
CVE-2013-6638 v8: multiple buffer overflows in runtime.cc [fedora-all]
bugzilla·2013-12-10·CVSS 7.5
CVE-2013-6638 [HIGH] CVE-2013-6638 v8: multiple buffer overflows in runtime.cc [fedora-all]
CVE-2013-6638 v8: multiple buffer overflows in runtime.cc [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affects mu
Bugzilla
CVE-2013-6638 v8: multiple buffer overflows in runtime.cc
bugzilla·2013-12-10·CVSS 7.5
CVE-2013-6638 [HIGH] CVE-2013-6638 v8: multiple buffer overflows in runtime.cc
CVE-2013-6638 v8: multiple buffer overflows in runtime.cc
Common Vulnerabilities and Exposures assigned an identifier CVE-2013-6638 to the following vulnerability:
Name: CVE-2013-6638
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6638
Assigned: 20131105
Reference: http://www.mail-archive.com/[email protected]/msg79646.html
Reference: http://code.google.com/p/v8/source/detail?r=17800
Reference: http://googlechromereleases.blogspot.com/2013/12/stable-channel-update.html
Reference: https://code.google.com/p/chromium/issues/detail?id=319722
Multiple buffer overflows in runtime.cc in Google V8 before 3.22.24.7, as used in Google Chrome before 31.0.1650.63, allow remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigge
http://code.google.com/p/v8/source/detail?r=17800http://googlechromereleases.blogspot.com/2013/12/stable-channel-update.htmlhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00090.htmlhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00096.htmlhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00122.htmlhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00124.htmlhttp://lists.opensuse.org/opensuse-updates/2014-01/msg00042.htmlhttp://lists.opensuse.org/opensuse-updates/2014-01/msg00063.htmlhttp://secunia.com/advisories/56216http://secunia.com/advisories/56217http://www.debian.org/security/2013/dsa-2811http://www.mail-archive.com/v8-dev%40googlegroups.com/msg79646.htmlhttp://www.securitytracker.com/id/1029442https://code.google.com/p/chromium/issues/detail?id=319722http://code.google.com/p/v8/source/detail?r=17800http://googlechromereleases.blogspot.com/2013/12/stable-channel-update.htmlhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00090.htmlhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00096.htmlhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00122.htmlhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00124.htmlhttp://lists.opensuse.org/opensuse-updates/2014-01/msg00042.htmlhttp://lists.opensuse.org/opensuse-updates/2014-01/msg00063.htmlhttp://secunia.com/advisories/56216http://secunia.com/advisories/56217http://www.debian.org/security/2013/dsa-2811http://www.mail-archive.com/v8-dev%40googlegroups.com/msg79646.htmlhttp://www.securitytracker.com/id/1029442https://code.google.com/p/chromium/issues/detail?id=319722
2013-12-07
Published