Show filters
125 Total Results
Displaying 41-50 of 125
Sort by:
Attacker Value
Unknown

CVE-2021-33437

Disclosure Date: July 26, 2022 (last updated February 24, 2025)
An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There are memory leaks in frozen_cb() in mjs.c.
Attacker Value
Unknown

CVE-2021-27425

Disclosure Date: May 03, 2022 (last updated February 23, 2025)
Cesanta Software Mongoose-OS v2.17.0 is vulnerable to integer wrap-around in function mm_malloc. This improper memory assignment can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash or a remote code injection/execution.
Attacker Value
Unknown

CVE-2022-25299

Disclosure Date: February 18, 2022 (last updated February 23, 2025)
This affects the package cesanta/mongoose before 7.6. The unsafe handling of file names during upload using mg_http_upload() method may enable attackers to write files to arbitrary locations outside the designated target folder.
Attacker Value
Unknown

CVE-2021-46556

Disclosure Date: January 27, 2022 (last updated October 07, 2023)
Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via mjs_bcode_insert_offset at src/mjs_bcode.c. This vulnerability can lead to a Denial of Service (DoS).
Attacker Value
Unknown

CVE-2021-46554

Disclosure Date: January 27, 2022 (last updated October 07, 2023)
Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via mjs_json_stringify at src/mjs_json.c. This vulnerability can lead to a Denial of Service (DoS).
Attacker Value
Unknown

CVE-2021-46553

Disclosure Date: January 27, 2022 (last updated October 07, 2023)
Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via mjs_set_internal at src/mjs_object.c. This vulnerability can lead to a Denial of Service (DoS).
Attacker Value
Unknown

CVE-2021-46550

Disclosure Date: January 27, 2022 (last updated October 07, 2023)
Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via free_json_frame at src/mjs_json.c. This vulnerability can lead to a Denial of Service (DoS).
Attacker Value
Unknown

CVE-2021-46549

Disclosure Date: January 27, 2022 (last updated October 07, 2023)
Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via parse_cval_type at src/mjs_ffi.c. This vulnerability can lead to a Denial of Service (DoS).
Attacker Value
Unknown

CVE-2021-46548

Disclosure Date: January 27, 2022 (last updated October 07, 2023)
Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via add_lineno_map_item at src/mjs_bcode.c. This vulnerability can lead to a Denial of Service (DoS).
Attacker Value
Unknown

CVE-2021-46547

Disclosure Date: January 27, 2022 (last updated October 07, 2023)
Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via /usr/local/bin/mjs+0x2c17e. This vulnerability can lead to a Denial of Service (DoS).