Vulnerability index

Browse CVEs

130 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Mongoose CRITICAL 9.8
CVE-2017-2921

An exploitable memory corruption vulnerability exists in the Websocket protocol implementation of Cesanta Mongoose 6.8. A specially crafted websocket…

No fix yet
Fix from $2,300 2017-11-07
Mongoose CRITICAL 9.8
CVE-2017-2922

An exploitable memory corruption vulnerability exists in the Websocket protocol implementation of Cesanta Mongoose 6.8. A specially crafted websocket…

No fix yet
Fix from $2,300 2017-11-07
Mongoose CRITICAL 9.8
CVE-2017-2891

An exploitable use-after-free vulnerability exists in the HTTP server implementation of Cesanta Mongoose 6.8. An ordinary HTTP POST request with a CG…

No fix yet
Fix from $2,300 2017-11-07
Mongoose CRITICAL 9.8
CVE-2017-2892

An exploitable arbitrary memory read vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8. A specially crafted MQTT …

Mitigation only
Fix from $2,300 2017-11-07
Mongoose CRITICAL 9.8
CVE-2017-2894EPSS 31%

An exploitable stack buffer overflow vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8. A specially crafted MQTT …

No fix yet
Fix from $2,300 2017-11-07
Mongoose HIGH 8.2
CVE-2017-2895

An exploitable arbitrary memory read vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8. A specially crafted MQTT …

Mitigation only
Fix from $1,950 2017-11-07
Mongoose HIGH 7.5
CVE-2017-2893EPSS 25%

An exploitable NULL pointer dereference vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8. An MQTT SUBSCRIBE pack…

No fix yet
Fix from $1,950 2017-11-07
Mongoose HIGH 7.5
CVE-2017-2909

An infinite loop programming error exists in the DNS server functionality of Cesanta Mongoose 6.8 library. A specially crafted DNS request can cause …

Mitigation only
Fix from $1,950 2017-11-07
Mongoose Embedded Web Server Library HIGH 8.8
CVE-2017-11567

Cross-site request forgery (CSRF) vulnerability in Mongoose Web Server before 6.9 allows remote attackers to hijack the authentication of users for r…

Fix: after 6.8
Fix from $1,950 2017-09-07
Mongoose Embedded Web Server Library HIGH 7.5
CVE-2017-7185EPSS 12%

Use-after-free vulnerability in the mg_http_multipart_wait_for_boundary function in mongoose.c in Cesanta Mongoose Embedded Web Server Library 6.7 an…

Fix: after 6.7
Fix from $1,950 2017-04-10