Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:15749
HistoryMay 02, 2019 - 5:04 a.m.

Denial Of Service (DoS)

2019-05-0205:04:13
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12

0.024 Low

EPSS

Percentile

90.0%

V8 is Google’s open source JavaScript engine. It was discovered that V8 did not properly check the stack size limit in certain cases. A remote attacker able to send a request that caused a script executed by V8 to use deep recursion could trigger a stack overflow, leading to a crash of an application using V8. (CVE-2014-5256) Multiple flaws were discovered in V8. Untrusted JavaScript code executed by V8 could use either of these flaws to crash V8 or, possibly, execute arbitrary code with the privileges of the user running V8. (CVE-2013-6639, CVE-2013-6640, CVE-2013-6650, CVE-2013-6668, CVE-2014-1704) All v8314-v8 users are advised to upgrade to these updated packages, which contain backported patches to correct these issues. All applications using V8 must be restarted for this update to take effect.