7.5
CVSSv2

CVE-2015-5380

Published: 09/07/2015 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The Utf8DecoderBase::WriteUtf16Slow function in unicode-decoder.cc in Google V8, as used in Node.js prior to 0.12.6, io.js prior to 1.8.3 and 2.x prior to 2.3.3, and other products, does not verify that there is memory available for a UTF-16 surrogate pair, which allows remote malicious users to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted byte sequence.

Vulnerable Product Search on Vulmon Subscribe to Product

google v8 -

iojs io.js 2.0.0

iojs io.js 2.3.2

iojs io.js 2.0.2

iojs io.js 2.2.0

iojs io.js 2.0.1

iojs io.js 2.1.0

iojs io.js 2.3.1

iojs io.js 2.3.0

iojs io.js

iojs io.js 2.2.1

nodejs node.js

Vendor Advisories

The Utf8DecoderBase::WriteUtf16Slow function in unicode-decodercc in Google V8, as used in Nodejs before 0126, iojs before 183 and 2x before 233, and other products, does not verify that there is memory available for a UTF-16 surrogate pair, which allows remote attackers to cause a denial of service (memory corruption) or possibly have un ...