CVE-2016-1669

HIGH

Google V8 <5.0.71.47 - Buffer Overflow

Title source: llm

Description

The Zone::New function in zone.cc in Google V8 before 5.0.71.47, as used in Google Chrome before 50.0.2661.102, does not properly determine when to expand certain memory allocations, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via crafted JavaScript code.

Exploits (1)

github NO CODE 31 stars
by OpenSISE · cpoc
https://github.com/OpenSISE/CVE_PoC_Collect/tree/master/Browser/CVE-2016-1669.html

References (22)

... and 2 more

Scores

CVSS v3 8.8
EPSS 0.0163
EPSS Percentile 81.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-119
Status published
Products (10)
canonical/ubuntu_linux 14.04
canonical/ubuntu_linux 15.10
canonical/ubuntu_linux 16.04
debian/debian_linux 8.0
google/chrome < 50.0.2661.87
google/v8 < 5.0.71
nodejs/node.js 0.10.0 - 0.10.46
nodejs/node.js 4.0.0 - 4.1.2
nodejs/node.js 4.2.0 - 4.4.6
opensuse/opensuse 13.1
Published May 14, 2016
Tracked Since Feb 18, 2026