Show filters
125 Total Results
Displaying 21-30 of 125
Sort by:
Attacker Value
Unknown

CVE-2023-2905

Disclosure Date: August 09, 2023 (last updated October 08, 2023)
Due to a failure in validating the length of a provided MQTT_CMD_PUBLISH parsed message with a variable length header, Cesanta Mongoose, an embeddable web server, version 7.10 is susceptible to a heap-based buffer overflow vulnerability in the default configuration. Version 7.9 and prior does not appear to be vulnerable. This issue is resolved in version 7.11.
Attacker Value
Unknown

CVE-2023-34188

Disclosure Date: June 23, 2023 (last updated October 08, 2023)
The HTTP server in Mongoose before 7.10 accepts requests containing negative Content-Length headers. By sending a single attack payload over TCP, an attacker can cause an infinite loop in which the server continuously reparses that payload, and does not respond to any other requests.
Attacker Value
Unknown

CVE-2023-30088

Disclosure Date: May 09, 2023 (last updated October 08, 2023)
An issue found in Cesanta MJS v.1.26 allows a local attacker to cause a denial of service via the mjs_execute function in mjs.c.
Attacker Value
Unknown

CVE-2023-30087

Disclosure Date: May 09, 2023 (last updated October 08, 2023)
Buffer Overflow vulnerability found in Cesanta MJS v.1.26 allows a local attacker to cause a denial of service via the mjs_mk_string function in mjs.c.
Attacker Value
Unknown

CVE-2023-29570

Disclosure Date: April 24, 2023 (last updated October 08, 2023)
Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via mjs_ffi_cb_free at src/mjs_ffi.c. This vulnerability can lead to a Denial of Service (DoS).
Attacker Value
Unknown

CVE-2023-29569

Disclosure Date: April 14, 2023 (last updated October 08, 2023)
Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via ffi_cb_impl_wpwwwww at src/mjs_ffi.c. This vulnerability can lead to a Denial of Service (DoS).
Attacker Value
Unknown

CVE-2023-29571

Disclosure Date: April 12, 2023 (last updated October 08, 2023)
Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via gc_sweep at src/mjs_gc.c. This vulnerability can lead to a Denial of Service (DoS).
Attacker Value
Unknown

CVE-2021-36535

Disclosure Date: February 03, 2023 (last updated October 08, 2023)
Buffer Overflow vulnerability in Cesanta mJS 1.26 allows remote attackers to cause a denial of service via crafted .js file to mjs_set_errorf.
Attacker Value
Unknown

CVE-2021-33449

Disclosure Date: July 26, 2022 (last updated October 07, 2023)
An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is NULL pointer dereference in mjs_bcode_part_get_by_offset() in mjs.c.
Attacker Value
Unknown

CVE-2021-33448

Disclosure Date: July 26, 2022 (last updated October 07, 2023)
An issue was discovered in mjs(mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is stack buffer overflow at 0x7fffe9049390.