Google V8 vulnerabilities
29 known vulnerabilities affecting google/v8.
Total CVEs
29
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH21MEDIUM4
Vulnerabilities
Page 1 of 2
CVE-2009-2555P3CRITICALCVSS 9.3≤ 1.02009-07-21
CVE-2009-2555 [CRITICAL] CWE-119 CVE-2009-2555: Heap-based buffer overflow in src/jsregexp.cc in Google V8 before 1.1.10.14, as used in Google Chrom
Heap-based buffer overflow in src/jsregexp.cc in Google V8 before 1.1.10.14, as used in Google Chrome before 2.0.172.37, allows remote attackers to execute arbitrary code in the Chrome sandbox via a crafted JavaScript regular expression.
nvd
CVE-2016-1669P3HIGHCVSS 8.8≤ 5.0.712016-05-14
CVE-2016-1669 [HIGH] CWE-119 CVE-2016-1669: The Zone::New function in zone.cc in Google V8 before 5.0.71.47, as used in Google Chrome before 50.
The Zone::New function in zone.cc in Google V8 before 5.0.71.47, as used in Google Chrome before 50.0.2661.102, does not properly determine when to expand certain memory allocations, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via crafted JavaScript code.
nvd
CVE-2016-1678P3HIGHCVSS 8.8≤ 5.0.712016-06-05
CVE-2016-1678 [HIGH] CWE-119 CVE-2016-1678: objects.cc in Google V8 before 5.0.71.32, as used in Google Chrome before 51.0.2704.63, does not pro
objects.cc in Google V8 before 5.0.71.32, as used in Google Chrome before 51.0.2704.63, does not properly restrict lazy deoptimization, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted JavaScript code.
nvd
CVE-2016-5128P3HIGHCVSS 8.8v5.2.3602016-07-23
CVE-2016-5128 [HIGH] CWE-254 CVE-2016-5128: objects.cc in Google V8 before 5.2.361.27, as used in Google Chrome before 52.0.2743.82, does not pr
objects.cc in Google V8 before 5.2.361.27, as used in Google Chrome before 52.0.2743.82, does not prevent API interceptors from modifying a store target without setting a property, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.
nvd
CVE-2014-1704P4CRITICALCVSS 10.0≤ 3.23.17v3.23.0+16 more2014-03-16
CVE-2014-1704 [CRITICAL] CVE-2014-1704: Multiple unspecified vulnerabilities in Google V8 before 3.23.17.18, as used in Google Chrome before
Multiple unspecified vulnerabilities in Google V8 before 3.23.17.18, as used in Google Chrome before 33.0.1750.149, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2016-2843P3CRITICALCVSS 9.8≤ 4.9.3852016-03-06
CVE-2016-2843 [CRITICAL] CVE-2016-2843: Multiple unspecified vulnerabilities in Google V8 before 4.9.385.26, as used in Google Chrome before
Multiple unspecified vulnerabilities in Google V8 before 4.9.385.26, as used in Google Chrome before 49.0.2623.75, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2013-6668P3HIGHCVSS 7.5≤ 3.24.35v3.24.0+34 more2014-03-05
CVE-2013-6668 [HIGH] CVE-2013-6668: Multiple unspecified vulnerabilities in Google V8 before 3.24.35.10, as used in Google Chrome before
Multiple unspecified vulnerabilities in Google V8 before 3.24.35.10, as used in Google Chrome before 33.0.1750.146, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2016-5129P4HIGHCVSS 8.8≤ 5.2.3602016-07-23
CVE-2016-5129 [HIGH] CWE-119 CVE-2016-5129: Google V8 before 5.2.361.32, as used in Google Chrome before 52.0.2743.82, does not properly process
Google V8 before 5.2.361.32, as used in Google Chrome before 52.0.2743.82, does not properly process left-trimmed objects, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via crafted JavaScript code.
nvd
CVE-2016-3679P4HIGHCVSS 8.8≤ 4.9.3852016-03-29
CVE-2016-3679 [HIGH] CVE-2016-3679: Multiple unspecified vulnerabilities in Google V8 before 4.9.385.33, as used in Google Chrome before
Multiple unspecified vulnerabilities in Google V8 before 4.9.385.33, as used in Google Chrome before 49.0.2623.108, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2014-3152P4HIGHCVSS 7.5≤ 3.25.28v3.25.0+27 more2014-05-21
CVE-2014-3152 [HIGH] CWE-189 CVE-2014-3152: Integer underflow in the LCodeGen::PrepareKeyedOperand function in arm/lithium-codegen-arm.cc in Goo
Integer underflow in the LCodeGen::PrepareKeyedOperand function in arm/lithium-codegen-arm.cc in Google V8 before 3.25.28.16, as used in Google Chrome before 35.0.1916.114, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger a negative key value.
nvd
CVE-2013-6638P4HIGHCVSS 7.5≤ 3.22.24v3.22.0+23 more2013-12-07
CVE-2013-6638 [HIGH] CWE-119 CVE-2013-6638: Multiple buffer overflows in runtime.cc in Google V8 before 3.22.24.7, as used in Google Chrome befo
Multiple buffer overflows in runtime.cc in Google V8 before 3.22.24.7, as used in Google Chrome before 31.0.1650.63, allow remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger a large typed array, related to the (1) Runtime_TypedArrayInitialize and (2) Runtime_TypedArrayInitializeFromArrayLike
nvd
CVE-2015-8548P4CRITICALCVSS 10.0≤ 4.7.802015-12-14
CVE-2015-8548 [CRITICAL] CVE-2015-8548: Multiple unspecified vulnerabilities in Google V8 before 4.7.80.23, as used in Google Chrome before
Multiple unspecified vulnerabilities in Google V8 before 4.7.80.23, as used in Google Chrome before 47.0.2526.80, allow attackers to cause a denial of service or possibly have other impact via unknown vectors, a different issue than CVE-2015-8478.
nvd
CVE-2015-1242P4HIGHCVSS 7.5≤ 4.2.77.72015-04-19
CVE-2015-1242 [HIGH] CVE-2015-1242: The ReduceTransitionElementsKind function in hydrogen-check-elimination.cc in Google V8 before 4.2.7
The ReduceTransitionElementsKind function in hydrogen-check-elimination.cc in Google V8 before 4.2.77.8, as used in Google Chrome before 42.0.2311.90, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that leverages "type confusion" in the check-elimination optimization.
nvd
CVE-2013-6639P4HIGHCVSS 7.5≤ 3.22.24v3.22.0+23 more2013-12-07
CVE-2013-6639 [HIGH] CWE-119 CVE-2013-6639: The DehoistArrayIndex function in hydrogen-dehoist.cc (aka hydrogen.cc) in Google V8 before 3.22.24.
The DehoistArrayIndex function in hydrogen-dehoist.cc (aka hydrogen.cc) in Google V8 before 3.22.24.7, as used in Google Chrome before 31.0.1650.63, allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via JavaScript code that sets the value of an array element with a crafted index.
nvd
CVE-2016-1677P4MEDIUMCVSS 6.5≤ 5.1.2812016-06-05
CVE-2016-1677 [MEDIUM] CWE-200 CVE-2016-1677: uri.js in Google V8 before 5.1.281.26, as used in Google Chrome before 51.0.2704.63, uses an incorre
uri.js in Google V8 before 5.1.281.26, as used in Google Chrome before 51.0.2704.63, uses an incorrect array type, which allows remote attackers to obtain sensitive information by calling the decodeURI function and leveraging "type confusion."
nvd
CVE-2013-6640P4HIGHCVSS 7.5≤ 3.22.24v3.22.0+23 more2013-12-07
CVE-2013-6640 [HIGH] CWE-119 CVE-2013-6640: The DehoistArrayIndex function in hydrogen-dehoist.cc (aka hydrogen.cc) in Google V8 before 3.22.24.
The DehoistArrayIndex function in hydrogen-dehoist.cc (aka hydrogen.cc) in Google V8 before 3.22.24.7, as used in Google Chrome before 31.0.1650.63, allows remote attackers to cause a denial of service (out-of-bounds read) via JavaScript code that sets a variable to the value of an array element with a crafted index.
nvd
CVE-2015-1346P4HIGHCVSS 7.5≤ 3.30.33.142015-01-22
CVE-2015-1346 [HIGH] CVE-2015-1346: Multiple unspecified vulnerabilities in Google V8 before 3.30.33.15, as used in Google Chrome before
Multiple unspecified vulnerabilities in Google V8 before 3.30.33.15, as used in Google Chrome before 40.0.2214.91, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2012-5120P4HIGHCVSS 7.5≤ 3.13.7v1.0+192 more2012-11-07
CVE-2012-5120 [HIGH] CWE-119 CVE-2012-5120: Google V8 before 3.13.7.5, as used in Google Chrome before 23.0.1271.64, on 64-bit Linux platforms a
Google V8 before 3.13.7.5, as used in Google Chrome before 23.0.1271.64, on 64-bit Linux platforms allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that triggers an out-of-bounds access to an array.
nvd
CVE-2015-3333P4HIGHCVSS 7.5≤ 4.2.77.72015-04-19
CVE-2015-3333 [HIGH] CVE-2015-3333: Multiple unspecified vulnerabilities in Google V8 before 4.2.77.14, as used in Google Chrome before
Multiple unspecified vulnerabilities in Google V8 before 4.2.77.14, as used in Google Chrome before 42.0.2311.90, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2015-3910P4HIGHCVSS 7.5≤ 4.3.61.202015-05-20
CVE-2015-3910 [HIGH] CVE-2015-3910: Multiple unspecified vulnerabilities in Google V8 before 4.3.61.21, as used in Google Chrome before
Multiple unspecified vulnerabilities in Google V8 before 4.3.61.21, as used in Google Chrome before 43.0.2357.65, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
1 / 2Next →