← Back

CVE-2015-5380

nvd nist
Published: Jul 9, 2015Modified: May 6, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

The Utf8DecoderBase::WriteUtf16Slow function in unicode-decoder.cc in Google V8, as used in Node.js before 0.12.6, io.js before 1.8.3 and 2.x before 2.3.3, and other products, does not verify that there is memory available for a UTF-16 surrogate pair, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted byte sequence.

Affected (12)

Products: Google: V8 · Iojs: Io.js · Nodejs: Node.js
1 product
V8
1 product
Io.js
1 product
Node.js
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
All versions
Configuration B
11 vulnerable
Vulnerable SoftwareAffected Versions
Iojs
Up to 1.8.2
Version 2.0.0
Version 2.0.1
Version 2.0.2
Version 2.1.0
Version 2.2.0
Version 2.2.1
Version 2.3.0
Version 2.3.1
Version 2.3.2
Up to 0.12.5

Timeline

No history available yet.