Lucene search

K
cve[email protected]CVE-2015-5605
HistoryJul 23, 2015 - 12:59 a.m.

CVE-2015-5605

2015-07-2300:59:19
CWE-17
web.nvd.nist.gov
29
cve-2015-5605
google v8
regular expression
denial of service
remote attackers
nvd

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

8.7 High

AI Score

Confidence

High

0.019 Low

EPSS

Percentile

88.7%

The regular-expression implementation in Google V8, as used in Google Chrome before 44.0.2403.89, mishandles interrupts, which allows remote attackers to cause a denial of service (application crash) via crafted JavaScript code, as demonstrated by an error in garbage collection during allocation of a stack-overflow exception message.

Affected configurations

NVD
Node
googlechromeRange43.0.2357.134
Node
opensuseopensuseMatch13.1
OR
opensuseopensuseMatch13.2

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

8.7 High

AI Score

Confidence

High

0.019 Low

EPSS

Percentile

88.7%