CVE-2016-5129

CWE-119Buffer Overflow8 documents8 sources
Severity
8.8HIGH
EPSS
2.5%
top 14.74%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 23
Latest updateMay 17

Description

Google V8 before 5.2.361.32, as used in Google Chrome before 52.0.2743.82, does not properly process left-trimmed objects, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via crafted JavaScript code.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages3 packages

NVDgoogle/chrome51.0.2704.106
NVDgoogle/v85.2.360
Alpinenodejs< 6.10.0-r0

🔴Vulnerability Details

3
GHSA
GHSA-2c2c-vqcm-ccr6: Google V8 before 52022-05-17
CVEList
CVE-2016-5129: Google V8 before 52016-07-23
OSV
CVE-2016-5129: Google V8 before 52016-07-23

📋Vendor Advisories

3
Android
CVE-2016-5129: Android Security Bulletin 2017-04-01 CVE: CVE-2016-5129 Severity: HIGH Affected AOSP versions: 62017-04-01
Ubuntu
Oxide vulnerabilities2016-08-05
Red Hat
chromium-browser: memory corruption in v82016-07-20

💬Community

1
Bugzilla
CVE-2016-5129 chromium-browser: memory corruption in v82016-07-21
CVE-2016-5129 (HIGH CVSS 8.8) | Google V8 before 5.2.361.32 | cvebase.io