hydrogen.cc in Google V8, as used Google Chrome before 40.0.2214.91, does not properly handle arrays with holes, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via crafted JavaScript code that triggers an array copy.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Chrome | * | 40.0.2214.85 (including) |