CVE-2015-5380
CVE-2015-5380 is a high-severity vulnerability in Google V8 with a CVSS 2.0 base score of 7.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-119.
Key facts
- Severity: High (CVSS 2.0 base score 7.5)
- EPSS exploit prediction: 3% (87th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-119
- Affected product: Google V8
- Published:
- Last modified:
Description
The Utf8DecoderBase::WriteUtf16Slow function in unicode-decoder.cc in Google V8, as used in Node.js before 0.12.6, io.js before 1.8.3 and 2.x before 2.3.3, and other products, does not verify that there is memory available for a UTF-16 surrogate pair, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted byte sequence.
Frequently asked questions
- What is CVE-2015-5380?
- The Utf8DecoderBase::WriteUtf16Slow function in unicode-decoder.cc in Google V8, as used in Node.js before 0.12.6, io.js before 1.8.3 and 2.x before 2.3.3, and other products, does not verify that there is memory available for a UTF-16 surrogate pair, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted byte sequence.
- How severe is CVE-2015-5380?
- CVE-2015-5380 has a CVSS 2.0 base score of 7.5, rated high severity.
- Is CVE-2015-5380 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 3% (87th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2015-5380?
- CVE-2015-5380 primarily affects Google V8. In total, 12 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2015-5380?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2015-5380 published?
- CVE-2015-5380 was published on 2015-07-09 and last updated on 2026-06-17.
References
- http://blog.nodejs.org/2015/07/03/node-v0-12-6-stable/
- http://www.securityfocus.com/bid/75556
- https://codereview.chromium.org/1226493003
- https://github.com/joyent/node/issues/25583
- https://medium.com/%40iojs/important-security-upgrades-for-node-js-and-io-js-8ac14ece5852
Affected products (12)
- cpe:2.3:a:google:v8:-:*:*:*:*:*:*:*
- cpe:2.3:a:iojs:io.js:*:*:*:*:*:*:*:*
- cpe:2.3:a:iojs:io.js:2.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:iojs:io.js:2.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:iojs:io.js:2.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:iojs:io.js:2.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:iojs:io.js:2.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:iojs:io.js:2.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:iojs:io.js:2.3.0:*:*:*:*:*:*:*
- cpe:2.3:a:iojs:io.js:2.3.1:*:*:*:*:*:*:*
- cpe:2.3:a:iojs:io.js:2.3.2:*:*:*:*:*:*:*
- cpe:2.3:a:nodejs:node.js:*:*:*:*:*:*:*:*
More vulnerabilities in Google V8
- CVE-2015-8548 — Critical (CVSS 10.0): Multiple unspecified vulnerabilities in Google V8 before 4.7.80.23, as used in Google Chrome before 47.0.2526.80, allow…
- CVE-2014-1704 — Critical (CVSS 10.0): Multiple unspecified vulnerabilities in Google V8 before 3.23.17.18, as used in Google Chrome before 33.0.1750.149,…
- CVE-2016-2843 — Critical (CVSS 9.8): Multiple unspecified vulnerabilities in Google V8 before 4.9.385.26, as used in Google Chrome before 49.0.2623.75,…
- CVE-2009-2555 — Critical (CVSS 9.3): Heap-based buffer overflow in src/jsregexp.cc in Google V8 before 1.1.10.14, as used in Google Chrome before…
- CVE-2026-85046 — High (CVSS 8.8): Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside…
- CVE-2016-5129 — High (CVSS 8.8): Google V8 before 5.2.361.32, as used in Google Chrome before 52.0.2743.82, does not properly process left-trimmed…
All CVEs affecting Google V8 →
Other CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer) vulnerabilities
- CVE-2026-105285 — Critical (CVSS 10.0): A security vulnerability has been detected in Totolink A3002MU 1.0.0-B20230403.1455. This affects an unknown function…
- CVE-2026-104610 — Critical (CVSS 10.0): A security vulnerability has been detected in Tenda HG7, HG9 and HG10 300001138_en_xpon. This impacts the function…
- CVE-2026-101039 — Critical (CVSS 10.0): A vulnerability was identified in FAST FAC1900R 20190827_2.0.2. Affected by this issue is the function copy_msg_element…
- CVE-2026-96257 — Critical (CVSS 10.0): A flaw has been found in Fast FAC1203R Gigabit Edition 2.0.4. Affected by this issue is the function copy_msg_element…
- CVE-2026-94089 — Critical (CVSS 10.0): A vulnerability was determined in D-Link DIR-868L 2.01b05. This issue affects the function strcpy of the file…
- CVE-2026-94003 — Critical (CVSS 10.0): A vulnerability has been found in Comfast CF-N1-S 2.6.0.1. Impacted is the function get_css_path_from_uri of the file…