cbcvebase.
CVE-2016-1669
published 2016-05-14

CVE-2016-1669: The Zone::New function in zone.cc in Google V8 before 5.0.71.47, as used in Google Chrome before 50.0.2661.102, does not properly determine when to expand…

high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
The Zone::New function in zone.cc in Google V8 before 5.0.71.47, as used in Google Chrome before 50.0.2661.102, does not properly determine when to expand certain memory allocations, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via crafted JavaScript code.

Affected

19 ranges
VendorProductVersion rangeFixed in
applexcode
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiannodejs< nodejs 4.4.6~dfsg-1 (bookworm)nodejs 4.4.6~dfsg-1 (bookworm)
googlechrome<= 50.0.2661.87
googlev8<= 5.0.71
nodejsnode.js>= 0.10.0 < 0.10.460.10.46
nodejsnode.js>= 0.12.0 < 0.12.150.12.15
nodejsnode.js4.0.0 – 4.1.2
nodejsnode.js>= 4.2.0 < 4.4.64.4.6
nodejsnode.js>= 5.0.0 < 5.12.05.12.0
nodejsnode.js6.0.0 – 6.2.0
nodejsnodejs>= 0 < 4.4.6~dfsg-14.4.6~dfsg-1
nodejsnodejs>= 0 < 4.4.6~dfsg-14.4.6~dfsg-1
nodejsnodejs>= 0 < 4.4.6~dfsg-14.4.6~dfsg-1
nodejsnodejs>= 0 < 4.4.6~dfsg-14.4.6~dfsg-1
opensuseopensuse

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH