v8: unspecified out-of-bounds access vulnerability
Published Dec 6, 2015
9.8
CRITICALCVSS 3.1
EPSS 5.73%
Description
The BasicJsonStringifier::SerializeJSArray function in json-stringifier.h in the JSON stringifier in Google V8, as used in Google Chrome before 47.0.2526.73, improperly loads array elements, which allows remote attackers to cause a denial of service (out-of-bounds memory access) or possibly have unspecified other impact via crafted JavaScript code.
Affected products
No data.
No data.
Red Hat Enterprise Linux 6 Supplementary
chromium-browser-0:47.0.2526.73-1.el6
Fixed · RHSA-2015:2545
OpenShift Enterprise 1
nodejs
Not affected
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo) Operational Tools
nodejs
Not affected
Red Hat Software Collections
nodejs010-nodejs
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 Supplementary | chromium-browser-0:47.0.2526.73-1.el6 | Fixed | RHSA-2015:2545 |
| OpenShift Enterprise 1 | nodejs | Not affected | n/a |
| Red Hat Enterprise Linux OpenStack Platform 7 (Kilo) Operational Tools | nodejs | Not affected | n/a |
| Red Hat Software Collections | nodejs010-nodejs | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue did not affect the versions of nodejs as shipped with Red Hat Enterprise Software Collections version 2, Red Hat OpenStack Platform and Red Hat Openshift Enterprise and Openshift Online as they do not include the vulnerable version of nodejs.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (16 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 5.73% (0.05726) | 92.81th | v5 (v2026.06.15) |
| Jun 15, 2026 | 4.69% (0.04692) | 90.59th | v5 (v2026.06.15) |
| Mar 8, 2026 | 13.88% (0.13882) | 94.17th | v4 (v2025.03.14) |
| Jan 17, 2026 | 25.16% (0.25162) | 96.01th | v4 (v2025.03.14) |
| Aug 25, 2025 | 18.79% (0.18787) | 95.04th | v4 (v2025.03.14) |
| Jun 29, 2025 | 13.73% (0.13726) | 93.92th | v4 (v2025.03.14) |
| Jun 26, 2025 | 21.52% (0.21523) | 95.41th | v4 (v2025.03.14) |
| Mar 30, 2025 | 13.58% (0.13575) | 93.62th | v4 (v2025.03.14) |
| Mar 29, 2025 | 32.18% (0.32179) | 95.03th | v4 (v2025.03.14) |
| Mar 17, 2025 | 13.58% (0.13575) | 93.69th | v4 (v2025.03.14) |
| Dec 12, 2024 | 2.09% (0.02092) | 89.56th | v3 (v2023.03.01) |
| Nov 8, 2023 | 2.09% (0.02092) | 87.86th | v3 (v2023.03.01) |
| Mar 7, 2023 | 1.28% (0.01276) | 83.56th | v3 (v2023.03.01) |
| Mar 6, 2023 | 2.17% (0.02172) | 80.77th | v2 (v2022.01.01) |
| Apr 1, 2022 | 2.17% (0.02172) | 78.91th | v2 (v2022.01.01) |
| Feb 4, 2022 | 2.17% (0.02172) | 57.73th | v2 (v2022.01.01) |
References (16)
- http://googlechromereleases.blogspot.com/2015/12/stable-channel-update.html x_refsource_CONFIRM
- http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00016.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00017.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-updates/2016-01/msg00045.html vendor-advisoryx_refsource_SUSE
- http://www.debian.org/security/2015/dsa-3415 vendor-advisoryx_refsource_DEBIAN
- http://www.securityfocus.com/bid/78209 vdb-entryx_refsource_BID
- http://www.securitytracker.com/id/1034298 vdb-entryx_refsource_SECTRACK
- https://access.redhat.com/security/cve/CVE-2015-6764 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1285774 Issue Tracking
- https://chromium.googlesource.com/v8/v8/+/6df9a1db8c85ab63dee63879456b6027df53fabc x_refsource_CONFIRM
- https://code.google.com/p/chromium/issues/detail?id=554946 x_refsource_CONFIRM
- https://codereview.chromium.org/1440223002 x_refsource_CONFIRM
- https://nodejs.org/en/blog/vulnerability/cve-2015-8027_cve-2015-6764/
- https://nvd.nist.gov/vuln/detail/CVE-2015-6764
- https://security.gentoo.org/glsa/201603-09 vendor-advisoryx_refsource_GENTOO
- https://www.cve.org/CVERecord?id=CVE-2015-6764
Change history (0)
No recorded changes yet.