Show filters
93 Total Results
Displaying 91-93 of 93
Sort by:
Attacker Value
Unknown

CVE-2017-18212

Disclosure Date: March 01, 2018 (last updated November 26, 2024)
An issue was discovered in JerryScript 1.0. There is a heap-based buffer over-read in the lit_read_code_unit_from_hex function in lit/lit-char-helpers.c via a RegExp("[\x0"); payload.
0
Attacker Value
Unknown

CVE-2017-14749

Disclosure Date: September 26, 2017 (last updated November 26, 2024)
JerryScript 1.0 allows remote attackers to cause a denial of service (jmem_heap_alloc_block_internal heap memory corruption) or possibly execute arbitrary code via a crafted .js file, because unrecognized \ characters cause incorrect 0x00 characters in bytecode.literal data.
0
Attacker Value
Unknown

CVE-2017-9250

Disclosure Date: May 28, 2017 (last updated November 26, 2024)
The lexer_process_char_literal function in jerry-core/parser/js/js-lexer.c in JerryScript 1.0 does not skip memory allocation for empty strings, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via malformed JavaScript source code, related to the jmem_heap_free_block function.