cbcvebase.
CVE-2015-6764
published 2015-12-06

CVE-2015-6764: The BasicJsonStringifier::SerializeJSArray function in json-stringifier.h in the JSON stringifier in Google V8, as used in Google Chrome before 47.0.2526.73…

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
The BasicJsonStringifier::SerializeJSArray function in json-stringifier.h in the JSON stringifier in Google V8, as used in Google Chrome before 47.0.2526.73, improperly loads array elements, which allows remote attackers to cause a denial of service (out-of-bounds memory access) or possibly have unspecified other impact via crafted JavaScript code.

Affected

12 ranges
VendorProductVersion rangeFixed in
applexcode
debiandebian_linux
debiandebian_linux
debiannodejs< nodejs 4.2.3~dfsg-1 (bookworm)nodejs 4.2.3~dfsg-1 (bookworm)
googlechrome<= 46.0.2490.86
nodejsnode.js4.0.0 – 4.1.2
nodejsnode.js>= 4.2.0 < 4.2.34.2.3
nodejsnode.js5.0.0 – 5.1.1
nodejsnodejs>= 0 < 4.2.3~dfsg-14.2.3~dfsg-1
nodejsnodejs>= 0 < 4.2.3~dfsg-14.2.3~dfsg-1
nodejsnodejs>= 0 < 4.2.3~dfsg-14.2.3~dfsg-1
nodejsnodejs>= 0 < 4.2.3~dfsg-14.2.3~dfsg-1

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL