8.8
CVSSv3

CVE-2016-1678

Published: 05/06/2016 Updated: 07/11/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

objects.cc in Google V8 prior to 5.0.71.32, as used in Google Chrome prior to 51.0.2704.63, does not properly restrict lazy deoptimization, which allows remote malicious users to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted JavaScript code.

Vulnerable Product Search on Vulmon Subscribe to Product

google v8

google chrome

debian debian linux 8.0

canonical ubuntu linux 16.04

canonical ubuntu linux 15.10

redhat enterprise linux desktop 6.0

canonical ubuntu linux 14.04

redhat enterprise linux server 6.0

redhat enterprise linux workstation 6.0

suse linux enterprise 12.0

opensuse leap 42.1

opensuse opensuse 13.2

Vendor Advisories

Several security issues were fixed in Oxide ...
objectscc in Google V8 before 507132, as used in Google Chrome before 510270463, does not properly restrict lazy deoptimization, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted JavaScript code ...