CVE-2016-1653
published 2016-04-18CVE-2016-1653: The LoadBuffer implementation in Google V8, as used in Google Chrome before 50.0.2661.75, mishandles data types, which allows remote attackers to cause a…
PriorityP434high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
2.57%
83.4th percentile
The LoadBuffer implementation in Google V8, as used in Google Chrome before 50.0.2661.75, mishandles data types, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that triggers an out-of-bounds write operation, related to compiler/pipeline.cc and compiler/simplified-lowering.cc.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| chrome | <= 49.0.2623.112 | — | |
| opensuse | leap | — | — |
| suse | linux_enterprise | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hxq2-8x4p-5j8p: The LoadBuffer implementation in Google V8, as used in Google Chrome before 50
ghsa_unreviewed·2022-05-14
CVE-2016-1653 [HIGH] CWE-119 GHSA-hxq2-8x4p-5j8p: The LoadBuffer implementation in Google V8, as used in Google Chrome before 50
The LoadBuffer implementation in Google V8, as used in Google Chrome before 50.0.2661.75, mishandles data types, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that triggers an out-of-bounds write operation, related to compiler/pipeline.cc and compiler/simplified-lowering.cc.
OSV
oxide-qt vulnerabilities
osv·2016-04-27·CVSS 9.8
CVE-2016-1578 [CRITICAL] oxide-qt vulnerabilities
oxide-qt vulnerabilities
A use-after-free was discovered when responding synchronously to
permission requests. An attacker could potentially exploit this to cause
a denial of service via application crash, or execute arbitrary code with
the privileges of the user invoking the program. (CVE-2016-1578)
An out-of-bounds read was discovered in V8. If a user were tricked in to
opening a specially crafted website, an attacker could potentially exploit
this to cause a denial of service via renderer crash. (CVE-2016-1646)
A use-after-free was discovered in the navigation implementation in
Chromium in some circumstances. If a user were tricked in to opening a
specially crafted website, an attacker could potentially exploit this to
cause a denial of service via application crash, or execute arbit
OSV
CVE-2016-1653: The LoadBuffer implementation in Google V8, as used in Google Chrome before 50
osv·2016-04-18·CVSS 8.8
CVE-2016-1653 [HIGH] CVE-2016-1653: The LoadBuffer implementation in Google V8, as used in Google Chrome before 50
The LoadBuffer implementation in Google V8, as used in Google Chrome before 50.0.2661.75, mishandles data types, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that triggers an out-of-bounds write operation, related to compiler/pipeline.cc and compiler/simplified-lowering.cc.
Ubuntu
Oxide vulnerabilities
vendor_ubuntu·2016-04-27·CVSS 9.8
CVE-2016-1578 [CRITICAL] Oxide vulnerabilities
Title: Oxide vulnerabilities
Summary: Several security issues were fixed in Oxide.
A use-after-free was discovered when responding synchronously to
permission requests. An attacker could potentially exploit this to cause
a denial of service via application crash, or execute arbitrary code with
the privileges of the user invoking the program. (CVE-2016-1578)
An out-of-bounds read was discovered in V8. If a user were tricked in to
opening a specially crafted website, an attacker could potentially exploit
this to cause a denial of service via renderer crash. (CVE-2016-1646)
A use-after-free was discovered in the navigation implementation in
Chromium in some circumstances. If a user were tricked in to opening a
specially crafted website, an attacker could potentially exploit this to
cause
Red Hat
chromium-browser: out-of-bounds write in V8
vendor_redhat·2016-04-13·CVSS 8.8
CVE-2016-1653 [HIGH] chromium-browser: out-of-bounds write in V8
chromium-browser: out-of-bounds write in V8
The LoadBuffer implementation in Google V8, as used in Google Chrome before 50.0.2661.75, mishandles data types, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that triggers an out-of-bounds write operation, related to compiler/pipeline.cc and compiler/simplified-lowering.cc.
No detection rules found.
No public exploits indexed.
arXiv
SOK: On the Analysis of Web Browser Security
arxiv_fulltext·2021-12-31
SOK: On the Analysis of Web Browser Security
: On the Analysis of Web Browser Security
fancyplain
Rev.
\ of LastPage
Jungwon Lim*,\;
Yonghwi Jin*^ ,\;
Mansour Alharthi,\;
Xiaokuan Zhang,\;
Jinho Jung,\;
Rajat Gupta,\;
Kuilin Li,\;
Daehee Jang^ ,\;
Taesoo Kim\;
Georgia Institute of Technology ^ Theori Inc. ^ Sungshin Women's University
## Abstract
Web browsers are integral parts of everyone's daily life.
They are commonly used
for security-critical and privacy sensitive tasks,
like banking transactions and checking medical records.
Unfortunately,
modern web browsers are
too complex to be bug free
( , 25 million lines of code in Chrome),
and their role as an interface to the cyberspace
makes them an attractive target for attacks.
Accordingly,
web browsers naturally
become an arena for demonstrating
advanced exploitation techni
arXiv
Rethinking Misalignment to Raise the Bar for Heap Pointer Corruption
arxiv_fulltext·2018-08-08
Rethinking Misalignment to Raise the Bar for Heap Pointer Corruption
Rethinking Misalignment to Raise the Bar for Heap Pointer Corruption
Daehee Jang
KAIST
[email protected]
Hojoon Lee
KAIST
[email protected]
Brent Byunghoon Kang
KAIST
[email protected]
Michael Shell
Georgia Institute of Technology
[email protected]
Homer Simpson
Twentieth Century Fox
[email protected]
James Kirk
and Montgomery Scott
Starfleet Academy
[email protected]
\@IEEEpubidpullup9
Permission to freely reproduce all or part
of this paper for noncommercial purposes is granted provided that
copies bear this notice and the full citation on the first
page. Reproduction for commercial purposes is strictly prohibited
without the prior written consent of the Internet Society, the
first-named author (for reproduction of an entire paper only), and
the
Bugzilla
CVE-2016-1653 chromium-browser: out-of-bounds write in V8
bugzilla·2016-04-14·CVSS 8.8
CVE-2016-1653 [HIGH] CVE-2016-1653 chromium-browser: out-of-bounds write in V8
CVE-2016-1653 chromium-browser: out-of-bounds write in V8
A out-of-bounds write flaw was found in the V8 component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=589792
External References:
http://googlechromereleases.blogspot.com/2016/04/stable-channel-update_13.html
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2016:0638 https://rhn.redhat.com/errata/RHSA-2016-0638.html
http://googlechromereleases.blogspot.com/2016/04/stable-channel-update_13.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00040.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00041.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00049.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00050.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0638.htmlhttp://www.debian.org/security/2016/dsa-3549http://www.ubuntu.com/usn/USN-2955-1https://codereview.chromium.org/1740123002https://crbug.com/589792https://security.gentoo.org/glsa/201605-02http://googlechromereleases.blogspot.com/2016/04/stable-channel-update_13.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00040.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00041.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00049.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00050.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0638.htmlhttp://www.debian.org/security/2016/dsa-3549http://www.ubuntu.com/usn/USN-2955-1https://codereview.chromium.org/1740123002https://crbug.com/589792https://security.gentoo.org/glsa/201605-02
2016-04-18
Published