cbcvebase.
CVE-2016-1678
published 2016-06-05

CVE-2016-1678: objects.cc in Google V8 before 5.0.71.32, as used in Google Chrome before 51.0.2704.63, does not properly restrict lazy deoptimization, which allows remote…

high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
objects.cc in Google V8 before 5.0.71.32, as used in Google Chrome before 51.0.2704.63, does not properly restrict lazy deoptimization, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted JavaScript code.

Affected

12 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
googlechrome<= 50.0.2661.102
googlev8<= 5.0.71
opensuseleap
opensuseopensuse
redhatenterprise_linux_desktop
redhatenterprise_linux_server
redhatenterprise_linux_workstation
suselinux_enterprise

CVSS provenance

nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH