CVE-2015-5380: Google v8
High severity, CVSS 7.5. EPSS: 3% chance of exploitation in the next 30 days.
The Utf8DecoderBase::WriteUtf16Slow function in unicode-decoder.cc in Google V8, as used in Node.js before 0.12.6, io.js before 1.8.3 and 2.x before 2.3.3, and other products, does not verify that there is memory available for a UTF-16 surrogate pair, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted byte sequence.
Affected products
- Google v8: affected versions not specified
- Iojs Io.js: up to and including 1.8.2; version 2.0.0 only; version 2.0.1 only; version 2.0.2 only; version 2.1.0 only; version 2.2.0 only; …
- Node.js Node.js: up to and including 0.12.5
Published 2015-07-09. Last modified 2026-06-17.