Lucene search

K
cveMitreCVE-2015-5380
HistoryJul 09, 2015 - 10:59 a.m.

CVE-2015-5380

2015-07-0910:59:00
CWE-119
mitre
web.nvd.nist.gov
39
cve-2015-5380
memory corruption
google v8
node.js
io.js
utf-16
surrogate pair
denial of service
nvd

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

9.4

Confidence

High

EPSS

0.008

Percentile

81.1%

The Utf8DecoderBase::WriteUtf16Slow function in unicode-decoder.cc in Google V8, as used in Node.js before 0.12.6, io.js before 1.8.3 and 2.x before 2.3.3, and other products, does not verify that there is memory available for a UTF-16 surrogate pair, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted byte sequence.

Affected configurations

Nvd
Node
googlev8Match-
Node
iojsio.jsRange1.8.2
OR
iojsio.jsMatch2.0.0
OR
iojsio.jsMatch2.0.1
OR
iojsio.jsMatch2.0.2
OR
iojsio.jsMatch2.1.0
OR
iojsio.jsMatch2.2.0
OR
iojsio.jsMatch2.2.1
OR
iojsio.jsMatch2.3.0
OR
iojsio.jsMatch2.3.1
OR
iojsio.jsMatch2.3.2
OR
nodejsnode.jsRange0.12.5
VendorProductVersionCPE
googlev8-cpe:2.3:a:google:v8:-:*:*:*:*:*:*:*
iojsio.js*cpe:2.3:a:iojs:io.js:*:*:*:*:*:*:*:*
iojsio.js2.0.0cpe:2.3:a:iojs:io.js:2.0.0:*:*:*:*:*:*:*
iojsio.js2.0.1cpe:2.3:a:iojs:io.js:2.0.1:*:*:*:*:*:*:*
iojsio.js2.0.2cpe:2.3:a:iojs:io.js:2.0.2:*:*:*:*:*:*:*
iojsio.js2.1.0cpe:2.3:a:iojs:io.js:2.1.0:*:*:*:*:*:*:*
iojsio.js2.2.0cpe:2.3:a:iojs:io.js:2.2.0:*:*:*:*:*:*:*
iojsio.js2.2.1cpe:2.3:a:iojs:io.js:2.2.1:*:*:*:*:*:*:*
iojsio.js2.3.0cpe:2.3:a:iojs:io.js:2.3.0:*:*:*:*:*:*:*
iojsio.js2.3.1cpe:2.3:a:iojs:io.js:2.3.1:*:*:*:*:*:*:*
Rows per page:
1-10 of 121

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

9.4

Confidence

High

EPSS

0.008

Percentile

81.1%