Show filters
125 Total Results
Displaying 11-20 of 125
Sort by:
Attacker Value
Unknown

CVE-2024-42384

Disclosure Date: November 18, 2024 (last updated November 20, 2024)
Integer Overflow or Wraparound vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and produce a segmentation fault on the application.
Attacker Value
Unknown

CVE-2024-42383

Disclosure Date: November 18, 2024 (last updated November 20, 2024)
Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows to write a NULL byte value beyond the memory space dedicated for the hostname field.
Attacker Value
Unknown

CVE-2023-49553

Disclosure Date: January 02, 2024 (last updated January 10, 2024)
An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_destroy function in the msj.c file.
Attacker Value
Unknown

CVE-2023-49552

Disclosure Date: January 02, 2024 (last updated January 10, 2024)
An Out of Bounds Write in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_op_json_stringify function in the msj.c file.
Attacker Value
Unknown

CVE-2023-49551

Disclosure Date: January 02, 2024 (last updated January 06, 2024)
An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_op_json_parse function in the msj.c file.
Attacker Value
Unknown

CVE-2023-49550

Disclosure Date: January 02, 2024 (last updated January 06, 2024)
An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs+0x4ec508 component.
Attacker Value
Unknown

CVE-2023-49549

Disclosure Date: January 02, 2024 (last updated January 10, 2024)
An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_getretvalpos function in the msj.c file.
Attacker Value
Unknown

CVE-2023-50044

Disclosure Date: December 20, 2023 (last updated December 29, 2023)
Cesanta MJS 2.20.0 has a getprop_builtin_foreign out-of-bounds read if a Built-in API name occurs in a substring of an input string.
Attacker Value
Unknown

CVE-2023-43338

Disclosure Date: September 23, 2023 (last updated October 08, 2023)
Cesanta mjs v2.20.0 was discovered to contain a function pointer hijacking vulnerability via the function mjs_get_ptr(). This vulnerability allows attackers to execute arbitrary code via a crafted input.
Attacker Value
Unknown

CVE-2020-25887

Disclosure Date: August 22, 2023 (last updated October 08, 2023)
Buffer overflow in mg_resolve_from_hosts_file in Mongoose 6.18, when reading from a crafted hosts file.