Google V8 vulnerabilities

29 known vulnerabilities affecting google/v8.

Total CVEs
29
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH21MEDIUM4

Vulnerabilities

Page 1 of 2
CVE-2016-5129HIGHCVSS 8.8≤ 5.2.3602016-07-23
CVE-2016-5129 [HIGH] CWE-119 CVE-2016-5129: Google V8 before 5.2.361.32, as used in Google Chrome before 52.0.2743.82, does not properly process Google V8 before 5.2.361.32, as used in Google Chrome before 52.0.2743.82, does not properly process left-trimmed objects, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via crafted JavaScript code.
nvd
CVE-2016-5128HIGHCVSS 8.8v5.2.3602016-07-23
CVE-2016-5128 [HIGH] CWE-254 CVE-2016-5128: objects.cc in Google V8 before 5.2.361.27, as used in Google Chrome before 52.0.2743.82, does not pr objects.cc in Google V8 before 5.2.361.27, as used in Google Chrome before 52.0.2743.82, does not prevent API interceptors from modifying a store target without setting a property, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.
nvd
CVE-2016-1678HIGHCVSS 8.8≤ 5.0.712016-06-05
CVE-2016-1678 [HIGH] CWE-119 CVE-2016-1678: objects.cc in Google V8 before 5.0.71.32, as used in Google Chrome before 51.0.2704.63, does not pro objects.cc in Google V8 before 5.0.71.32, as used in Google Chrome before 51.0.2704.63, does not properly restrict lazy deoptimization, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted JavaScript code.
nvd
CVE-2016-1677MEDIUMCVSS 6.5≤ 5.1.2812016-06-05
CVE-2016-1677 [MEDIUM] CWE-200 CVE-2016-1677: uri.js in Google V8 before 5.1.281.26, as used in Google Chrome before 51.0.2704.63, uses an incorre uri.js in Google V8 before 5.1.281.26, as used in Google Chrome before 51.0.2704.63, uses an incorrect array type, which allows remote attackers to obtain sensitive information by calling the decodeURI function and leveraging "type confusion."
nvd
CVE-2016-1688MEDIUMCVSS 6.5≤ 5.0.712016-06-05
CVE-2016-1688 [MEDIUM] CWE-119 CVE-2016-1688: The regexp (aka regular expression) implementation in Google V8 before 5.0.71.40, as used in Google The regexp (aka regular expression) implementation in Google V8 before 5.0.71.40, as used in Google Chrome before 51.0.2704.63, mishandles external string sizes, which allows remote attackers to cause a denial of service (out-of-bounds read) via crafted JavaScript code.
nvd
CVE-2016-1669HIGHCVSS 8.8≤ 5.0.712016-05-14
CVE-2016-1669 [HIGH] CWE-119 CVE-2016-1669: The Zone::New function in zone.cc in Google V8 before 5.0.71.47, as used in Google Chrome before 50. The Zone::New function in zone.cc in Google V8 before 5.0.71.47, as used in Google Chrome before 50.0.2661.102, does not properly determine when to expand certain memory allocations, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via crafted JavaScript code.
nvd
CVE-2016-3679HIGHCVSS 8.8≤ 4.9.3852016-03-29
CVE-2016-3679 [HIGH] CVE-2016-3679: Multiple unspecified vulnerabilities in Google V8 before 4.9.385.33, as used in Google Chrome before Multiple unspecified vulnerabilities in Google V8 before 4.9.385.33, as used in Google Chrome before 49.0.2623.108, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2016-2843CRITICALCVSS 9.8≤ 4.9.3852016-03-06
CVE-2016-2843 [CRITICAL] CVE-2016-2843: Multiple unspecified vulnerabilities in Google V8 before 4.9.385.26, as used in Google Chrome before Multiple unspecified vulnerabilities in Google V8 before 4.9.385.26, as used in Google Chrome before 49.0.2623.75, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2015-8548CRITICALCVSS 10.0≤ 4.7.802015-12-14
CVE-2015-8548 [CRITICAL] CVE-2015-8548: Multiple unspecified vulnerabilities in Google V8 before 4.7.80.23, as used in Google Chrome before Multiple unspecified vulnerabilities in Google V8 before 4.7.80.23, as used in Google Chrome before 47.0.2526.80, allow attackers to cause a denial of service or possibly have other impact via unknown vectors, a different issue than CVE-2015-8478.
nvd
CVE-2015-8478HIGHCVSS 7.5≤ 4.6.85.232015-12-06
CVE-2015-8478 [HIGH] CVE-2015-8478: Multiple unspecified vulnerabilities in Google V8 before 4.7.80.23, as used in Google Chrome before Multiple unspecified vulnerabilities in Google V8 before 4.7.80.23, as used in Google Chrome before 47.0.2526.73, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2015-7834HIGHCVSS 7.5≤ 4.6.85.222015-10-15
CVE-2015-7834 [HIGH] CVE-2015-7834: Multiple unspecified vulnerabilities in Google V8 before 4.6.85.23, as used in Google Chrome before Multiple unspecified vulnerabilities in Google V8 before 4.6.85.23, as used in Google Chrome before 46.0.2490.71, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2015-6580HIGHCVSS 7.5≤ 4.4.632015-09-03
CVE-2015-6580 [HIGH] CVE-2015-6580: Multiple unspecified vulnerabilities in Google V8 before 4.5.103.29, as used in Google Chrome before Multiple unspecified vulnerabilities in Google V8 before 4.5.103.29, as used in Google Chrome before 45.0.2454.85, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2015-3910HIGHCVSS 7.5≤ 4.3.61.202015-05-20
CVE-2015-3910 [HIGH] CVE-2015-3910: Multiple unspecified vulnerabilities in Google V8 before 4.3.61.21, as used in Google Chrome before Multiple unspecified vulnerabilities in Google V8 before 4.3.61.21, as used in Google Chrome before 43.0.2357.65, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2015-1242HIGHCVSS 7.5≤ 4.2.77.72015-04-19
CVE-2015-1242 [HIGH] CVE-2015-1242: The ReduceTransitionElementsKind function in hydrogen-check-elimination.cc in Google V8 before 4.2.7 The ReduceTransitionElementsKind function in hydrogen-check-elimination.cc in Google V8 before 4.2.77.8, as used in Google Chrome before 42.0.2311.90, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that leverages "type confusion" in the check-elimination optimization.
nvd
CVE-2015-3333HIGHCVSS 7.5≤ 4.2.77.72015-04-19
CVE-2015-3333 [HIGH] CVE-2015-3333: Multiple unspecified vulnerabilities in Google V8 before 4.2.77.14, as used in Google Chrome before Multiple unspecified vulnerabilities in Google V8 before 4.2.77.14, as used in Google Chrome before 42.0.2311.90, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2015-2238HIGHCVSS 7.5≤ 4.1.0.202015-03-09
CVE-2015-2238 [HIGH] CVE-2015-2238: Multiple unspecified vulnerabilities in Google V8 before 4.1.0.21, as used in Google Chrome before 4 Multiple unspecified vulnerabilities in Google V8 before 4.1.0.21, as used in Google Chrome before 41.0.2272.76, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2015-1346HIGHCVSS 7.5≤ 3.30.33.142015-01-22
CVE-2015-1346 [HIGH] CVE-2015-1346: Multiple unspecified vulnerabilities in Google V8 before 3.30.33.15, as used in Google Chrome before Multiple unspecified vulnerabilities in Google V8 before 3.30.33.15, as used in Google Chrome before 40.0.2214.91, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2014-7967HIGHCVSS 7.5≤ 3.28.692014-10-08
CVE-2014-7967 [HIGH] CVE-2014-7967: Multiple unspecified vulnerabilities in Google V8 before 3.28.71.15, as used in Google Chrome before Multiple unspecified vulnerabilities in Google V8 before 3.28.71.15, as used in Google Chrome before 38.0.2125.101, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2014-3152HIGHCVSS 7.5≤ 3.25.28v3.25.0+27 more2014-05-21
CVE-2014-3152 [HIGH] CWE-189 CVE-2014-3152: Integer underflow in the LCodeGen::PrepareKeyedOperand function in arm/lithium-codegen-arm.cc in Goo Integer underflow in the LCodeGen::PrepareKeyedOperand function in arm/lithium-codegen-arm.cc in Google V8 before 3.25.28.16, as used in Google Chrome before 35.0.1916.114, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger a negative key value.
nvd
CVE-2014-1704CRITICALCVSS 10.0≤ 3.23.17v3.23.0+16 more2014-03-16
CVE-2014-1704 [CRITICAL] CVE-2014-1704: Multiple unspecified vulnerabilities in Google V8 before 3.23.17.18, as used in Google Chrome before Multiple unspecified vulnerabilities in Google V8 before 3.23.17.18, as used in Google Chrome before 33.0.1750.149, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd