VYPR

V8

by Google

Source repositories

CVEs (142)

  • CVE-2011-3115May 24, 2012
    risk 0.00cvss epss 0.02

    Google V8, as used in Google Chrome before 19.0.1084.52, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger "type corruption."

  • CVE-2011-3111May 24, 2012
    risk 0.00cvss epss 0.01

    Google V8, as used in Google Chrome before 19.0.1084.52, allows remote attackers to cause a denial of service (invalid read operation) via unspecified vectors.

  • CVE-2011-3103May 24, 2012
    risk 0.00cvss epss 0.02

    Google V8, as used in Google Chrome before 19.0.1084.52, does not properly perform garbage collection, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted JavaScript code.

  • CVE-2011-3092May 16, 2012
    risk 0.00cvss epss 0.02

    The regex implementation in Google V8, as used in Google Chrome before 19.0.1084.46, allows remote attackers to cause a denial of service (invalid write operation) or possibly have unspecified other impact via unknown vectors.

  • CVE-2011-3057Mar 22, 2012
    risk 0.00cvss epss 0.02

    Google V8, as used in Google Chrome before 17.0.963.83, allows remote attackers to cause a denial of service via vectors that trigger an invalid read operation.

  • CVE-2011-3031Mar 5, 2012
    risk 0.00cvss epss 0.02

    Use-after-free vulnerability in the element wrapper in Google V8, as used in Google Chrome before 17.0.963.65, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

  • CVE-2011-5037Dec 30, 2011
    risk 0.00cvss epss 0.01

    Google V8 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters, as demonstrated by attacks against Node.js.

  • CVE-2011-3914Dec 13, 2011
    risk 0.00cvss epss 0.01

    The internationalization (aka i18n) functionality in Google V8, as used in Google Chrome before 16.0.912.63, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that trigger an out-of-bounds write.

  • CVE-2011-2830Oct 28, 2011
    risk 0.00cvss epss 0.01

    Google V8, as used in Google Chrome before 14.0.835.163, does not properly implement script object wrappers, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via unknown vectors.

  • CVE-2011-3886Oct 25, 2011
    risk 0.00cvss epss 0.01

    Google V8, as used in Google Chrome before 15.0.874.102, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that triggers out-of-bounds write operations.

  • CVE-2011-2875Sep 19, 2011
    risk 0.00cvss epss 0.01

    Google V8, as used in Google Chrome before 14.0.835.163, does not properly perform object sealing, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that leverage "type confusion."

  • CVE-2011-2862Sep 19, 2011
    risk 0.00cvss epss 0.01

    Google V8, as used in Google Chrome before 14.0.835.163, does not properly restrict access to built-in objects, which has unspecified impact and remote attack vectors.

  • CVE-2011-2856Sep 19, 2011
    risk 0.00cvss epss 0.01

    Google V8, as used in Google Chrome before 14.0.835.163, allows remote attackers to bypass the Same Origin Policy via unspecified vectors.

  • CVE-2011-2828Aug 29, 2011
    risk 0.00cvss epss 0.01

    Google V8, as used in Google Chrome before 13.0.782.215, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that trigger an out-of-bounds write.

  • CVE-2011-2802Aug 3, 2011
    risk 0.00cvss epss 0.01

    Google V8, as used in Google Chrome before 13.0.782.107, does not properly perform const lookups, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted web site.

  • CVE-2011-2348Jun 29, 2011
    risk 0.00cvss epss 0.01

    Google V8, as used in Google Chrome before 12.0.742.112, performs an incorrect bounds check, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

  • CVE-2011-1286Mar 11, 2011
    risk 0.00cvss epss 0.02

    Google V8, as used in Google Chrome before 10.0.648.127, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that trigger incorrect access to memory.

  • CVE-2011-1193Mar 11, 2011
    risk 0.00cvss epss 0.02

    Google V8, as used in Google Chrome before 10.0.648.127, allows remote attackers to bypass the Same Origin Policy via unspecified vectors.

  • CVE-2010-0646Feb 18, 2010
    risk 0.00cvss epss 0.05

    Multiple integer signedness errors in factory.cc in Google V8 before r3560, as used in Google Chrome before 4.0.249.89, allow remote attackers to execute arbitrary code in the Chrome sandbox via crafted use of JavaScript arrays.

  • CVE-2010-0645Feb 18, 2010
    risk 0.00cvss epss 0.03

    Multiple integer overflows in factory.cc in Google V8 before r3560, as used in Google Chrome before 4.0.249.89, allow remote attackers to execute arbitrary code in the Chrome sandbox via crafted use of JavaScript arrays.

Page 7 of 8