chromium-browser: Out of bounds access in v8
Published Dec 6, 2015
7.5
HIGHCVSS 2.0
EPSS 2.13%
Description
js/array.js in Google V8, as used in Google Chrome before 47.0.2526.73, improperly implements certain map and filter operations for arrays, which allows remote attackers to cause a denial of service (out-of-bounds memory access) or possibly have unspecified other impact via crafted JavaScript code.
Affected products
No data.
No data.
Red Hat Enterprise Linux 6 Supplementary
chromium-browser-0:47.0.2526.73-1.el6
Fixed · RHSA-2015:2545
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 Supplementary | chromium-browser-0:47.0.2526.73-1.el6 | Fixed | RHSA-2015:2545 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (10 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 2.13% (0.02131) | 81.30th | v5 (v2026.06.15) |
| Jun 15, 2026 | 2.13% (0.02131) | 79.51th | v5 (v2026.06.15) |
| Mar 30, 2025 | 1.80% (0.01797) | 81.14th | v4 (v2025.03.14) |
| Mar 29, 2025 | 11.90% (0.11899) | 89.55th | v4 (v2025.03.14) |
| Mar 17, 2025 | 1.80% (0.01797) | 81.56th | v4 (v2025.03.14) |
| Dec 12, 2024 | 2.19% (0.02187) | 89.81th | v3 (v2023.03.01) |
| Mar 7, 2023 | 2.19% (0.02187) | 87.61th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.97% (0.01974) | 78.97th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.97% (0.01974) | 77.12th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.97% (0.01974) | 56.20th | v2 (v2022.01.01) |
References (13)
- http://googlechromereleases.blogspot.com/2015/12/stable-channel-update.html x_refsource_CONFIRM
- http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00016.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00017.html vendor-advisoryx_refsource_SUSE
- http://www.debian.org/security/2015/dsa-3415 vendor-advisoryx_refsource_DEBIAN
- http://www.securitytracker.com/id/1034298 vdb-entryx_refsource_SECTRACK
- http://www.ubuntu.com/usn/USN-2825-1 vendor-advisoryx_refsource_UBUNTU
- https://access.redhat.com/security/cve/CVE-2015-6771 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1287486 Issue Tracking
- https://chromium.googlesource.com/v8/v8/+/c227dd5734efa41e4973c834c910bb684a9e1998 x_refsource_CONFIRM
- https://code.google.com/p/chromium/issues/detail?id=544991 x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2015-6771
- https://security.gentoo.org/glsa/201603-09 vendor-advisoryx_refsource_GENTOO
- https://www.cve.org/CVERecord?id=CVE-2015-6771
Change history (0)
No recorded changes yet.