Vulnerability index

Browse CVEs

130 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Mjs MEDIUM 5.5
CVE-2023-29569

Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via ffi_cb_impl_wpwwwww at src/mjs_ffi.c. This vulnerability can lead to a Denial …

No fix yet
Fix from $1,600 2023-04-14
Mjs MEDIUM 5.5
CVE-2023-29571

Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via gc_sweep at src/mjs_gc.c. This vulnerability can lead to a Denial of Service (…

No fix yet
Fix from $1,600 2023-04-12
Mjs MEDIUM 5.5
CVE-2021-36535

Buffer Overflow vulnerability in Cesanta mJS 1.26 allows remote attackers to cause a denial of service via crafted .js file to mjs_set_errorf.

No fix yet
Fix from $1,600 2023-02-03
Mjs MEDIUM 5.5
CVE-2021-33447

An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is NULL pointer dereference in mjs_print() in m…

Fix: 2.20.0+
Fix from $1,600 2022-07-26
Mjs MEDIUM 5.5
CVE-2021-33448

An issue was discovered in mjs(mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is stack buffer overflow at 0x7fffe9049390.

Fix: 2.20.0+
Fix from $1,600 2022-07-26
Mjs MEDIUM 5.5
CVE-2021-33449

An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is NULL pointer dereference in mjs_bcode_part_g…

Fix: 2.20.0+
Fix from $1,600 2022-07-26
Mjs MEDIUM 5.5
CVE-2021-33437

An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There are memory leaks in frozen_cb() in mjs.c.

Fix: 2.20.0+
Fix from $1,600 2022-07-26
Mjs MEDIUM 5.5
CVE-2021-33438

An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is stack buffer overflow in json_parse_array() …

Fix: 2.20.0+
Fix from $1,600 2022-07-26
Mjs MEDIUM 5.5
CVE-2021-33439

An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is Integer overflow in gc_compact_strings() in …

Fix: 2.20.0+
Fix from $1,600 2022-07-26
Mjs MEDIUM 5.5
CVE-2021-33440

An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is NULL pointer dereference in mjs_bcode_commit…

Fix: 2.20.0+
Fix from $1,600 2022-07-26
Mjs MEDIUM 5.5
CVE-2021-33441

An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is NULL pointer dereference in exec_expr() in m…

Fix: 2.20.0+
Fix from $1,600 2022-07-26
Mjs MEDIUM 5.5
CVE-2021-33442

An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is NULL pointer dereference in json_printf() in…

Fix: 2.20.0+
Fix from $1,600 2022-07-26
Mjs MEDIUM 5.5
CVE-2021-33443

An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is stack buffer overflow in mjs_execute() in mj…

Fix: 2.20.0+
Fix from $1,600 2022-07-26
Mjs MEDIUM 5.5
CVE-2021-33444

An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is NULL pointer dereference in getprop_builtin_…

Fix: 2.20.0+
Fix from $1,600 2022-07-26
Mjs MEDIUM 5.5
CVE-2021-33445

An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is NULL pointer dereference in mjs_string_char_…

Fix: 2.20.0+
Fix from $1,600 2022-07-26
Mjs MEDIUM 5.5
CVE-2021-33446

An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is NULL pointer dereference in mjs_next() in mj…

Fix: 2.20.0+
Fix from $1,600 2022-07-26
Mongoose Os CRITICAL 9.8
CVE-2021-27425

Cesanta Software Mongoose-OS v2.17.0 is vulnerable to integer wrap-around in function mm_malloc. This improper memory assignment can lead to arbitrar…

Mitigation only
Fix from $2,300 2022-05-03
Mongoose HIGH 7.5
CVE-2022-25299

This affects the package cesanta/mongoose before 7.6. The unsafe handling of file names during upload using mg_http_upload() method may enable attack…

Fix: 7.6+
Fix from $1,950 2022-02-18
Mjs MEDIUM 5.5
CVE-2021-46547

Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via /usr/local/bin/mjs+0x2c17e. This vulnerability can lead to a Denial of Service…

Patch available
Fix from $1,600 2022-01-27
Mjs MEDIUM 5.5
CVE-2021-46548

Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via add_lineno_map_item at src/mjs_bcode.c. This vulnerability can lead to a Denia…

Patch available
Fix from $1,600 2022-01-27
Mjs MEDIUM 5.5
CVE-2021-46549

Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via parse_cval_type at src/mjs_ffi.c. This vulnerability can lead to a Denial of S…

Patch available
Fix from $1,600 2022-01-27
Mjs MEDIUM 5.5
CVE-2021-46550

Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via free_json_frame at src/mjs_json.c. This vulnerability can lead to a Denial of …

Patch available
Fix from $1,600 2022-01-27
Mjs MEDIUM 5.5
CVE-2021-46553

Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via mjs_set_internal at src/mjs_object.c. This vulnerability can lead to a Denial …

Patch available
Fix from $1,600 2022-01-27
Mjs MEDIUM 5.5
CVE-2021-46554

Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via mjs_json_stringify at src/mjs_json.c. This vulnerability can lead to a Denial …

Patch available
Fix from $1,600 2022-01-27
Mjs MEDIUM 5.5
CVE-2021-46556

Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via mjs_bcode_insert_offset at src/mjs_bcode.c. This vulnerability can lead to a D…

Patch available
Fix from $1,600 2022-01-27
Mjs HIGH 7.8
CVE-2021-46522

Cesanta MJS v2.20.0 was discovered to contain a heap buffer overflow via /usr/lib/x86_64-linux-gnu/libasan.so.4+0xaff53.

No fix yet
Fix from $1,950 2022-01-27
Mjs HIGH 7.8
CVE-2021-46523

Cesanta MJS v2.20.0 was discovered to contain a heap buffer overflow via to_json_or_debug at mjs/src/mjs_json.c.

No fix yet
Fix from $1,950 2022-01-27
Mjs HIGH 7.8
CVE-2021-46524

Cesanta MJS v2.20.0 was discovered to contain a heap buffer overflow via snquote at mjs/src/mjs_json.c.

Patch available
Fix from $1,950 2022-01-27
Mjs HIGH 7.8
CVE-2021-46525

Cesanta MJS v2.20.0 was discovered to contain a heap-use-after-free via mjs_apply at src/mjs_exec.c.

Patch available
Fix from $1,950 2022-01-27
Mjs HIGH 7.8
CVE-2021-46526

Cesanta MJS v2.20.0 was discovered to contain a global buffer overflow via snquote at src/mjs_json.c.

Patch available
Fix from $1,950 2022-01-27