Vulnerabilities > Google > V8 > Medium

DATE CVE VULNERABILITY TITLE RISK
2016-06-05 CVE-2016-1688 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
The regexp (aka regular expression) implementation in Google V8 before 5.0.71.40, as used in Google Chrome before 51.0.2704.63, mishandles external string sizes, which allows remote attackers to cause a denial of service (out-of-bounds read) via crafted JavaScript code.
network
low complexity
debian canonical redhat suse opensuse google CWE-119
6.5
2016-06-05 CVE-2016-1677 Information Exposure vulnerability in multiple products
uri.js in Google V8 before 5.1.281.26, as used in Google Chrome before 51.0.2704.63, uses an incorrect array type, which allows remote attackers to obtain sensitive information by calling the decodeURI function and leveraging "type confusion."
network
low complexity
google debian canonical redhat opensuse suse CWE-200
6.5