Denial of Service Vulnerability in Google Chrome Affecting Google V8 Engine
CVE-2016-1653

8.8HIGH

Key Information:

Vendor
Debian
Vendor
CVE Published:
18 April 2016

Summary

The LoadBuffer implementation in the Google V8 engine, utilized by Google Chrome prior to version 50.0.2661.75, improperly handles data types. This vulnerability allows attackers to execute specially crafted JavaScript code that can lead to an out-of-bounds write operation, potentially causing a denial of service or other unforeseen impacts. The issue is associated with specific files within the V8 compiler architecture.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.