CVE-2015-6764

CRITICAL

Google Chrome < 46.0.2490.86 - Denial of Service via JSON Stringifier Array Handling

Title source: llm
STIX 2.1

Description

The BasicJsonStringifier::SerializeJSArray function in json-stringifier.h in the JSON stringifier in Google V8, as used in Google Chrome before 47.0.2526.73, improperly loads array elements, which allows remote attackers to cause a denial of service (out-of-bounds memory access) or possibly have unspecified other impact via crafted JavaScript code.

References (11)

Core 11
Core References
Release Notes, Vendor Advisory x_refsource_confirm
http://googlechromereleases.blogspot.com/2015/12/stable-channel-update.html
Mailing List vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2016-01/msg00045.html
Patch x_refsource_confirm
https://codereview.chromium.org/1440223002
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/201603-09
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2015/dsa-3415
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/78209
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1034298

Scores

CVSS v3 9.8
EPSS 0.1388
EPSS Percentile 94.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-119
Status published
Products (5)
debian/debian_linux 8.0
debian/debian_linux 9.0
google/chrome < 46.0.2490.86
nodejs/node.js 4.0.0 - 4.1.2
nodejs/node.js 4.2.0 - 4.2.3
Published Dec 06, 2015
Tracked Since Feb 18, 2026