Lucene search

K

Cesanta Security Vulnerabilities

cve
cve

CVE-2020-25756

A buffer overflow vulnerability exists in the mg_get_http_header function in Cesanta Mongoose 6.18 due to a lack of bounds checking. A crafted HTTP header can exploit this bug. NOTE: a committer has stated "this will not happen in...

9.8CVSS

9.5AI Score

0.006EPSS

2020-09-18 05:15 AM
25
cve
cve

CVE-2021-31875

In mjs_json.c in Cesanta MongooseOS mJS 1.26, a maliciously formed JSON string can trigger an off-by-one heap-based buffer overflow in mjs_json_parse, which can potentially lead to redirection of control flow. NOTE: the original reporter disputes the significance of this finding because "there...

9.8CVSS

9.5AI Score

0.006EPSS

2021-04-29 02:15 AM
50
cve
cve

CVE-2023-49553

An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_destroy function in the msj.c...

7.5CVSS

7.3AI Score

0.001EPSS

2024-01-02 11:15 PM
13
cve
cve

CVE-2023-49552

An Out of Bounds Write in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_op_json_stringify function in the msj.c...

7.5CVSS

7.3AI Score

0.001EPSS

2024-01-02 11:15 PM
13
cve
cve

CVE-2023-49549

An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_getretvalpos function in the msj.c...

7.5CVSS

7.3AI Score

0.001EPSS

2024-01-02 11:15 PM
10
cve
cve

CVE-2023-49551

An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_op_json_parse function in the msj.c...

7.5CVSS

7.3AI Score

0.001EPSS

2024-01-02 11:15 PM
15
cve
cve

CVE-2023-49550

An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs+0x4ec508...

7.5CVSS

7.3AI Score

0.001EPSS

2024-01-02 11:15 PM
14
cve
cve

CVE-2023-50044

Cesanta MJS 2.20.0 has a getprop_builtin_foreign out-of-bounds read if a Built-in API name occurs in a substring of an input...

9.8CVSS

9.2AI Score

0.001EPSS

2023-12-20 09:15 AM
16
cve
cve

CVE-2023-43338

Cesanta mjs v2.20.0 was discovered to contain a function pointer hijacking vulnerability via the function mjs_get_ptr(). This vulnerability allows attackers to execute arbitrary code via a crafted...

9.8CVSS

9.7AI Score

0.006EPSS

2023-09-23 12:15 AM
18
cve
cve

CVE-2023-34188

The HTTP server in Mongoose before 7.10 accepts requests containing negative Content-Length headers. By sending a single attack payload over TCP, an attacker can cause an infinite loop in which the server continuously reparses that payload, and does not respond to any other...

7.5CVSS

7.4AI Score

0.001EPSS

2023-06-23 08:15 PM
13
cve
cve

CVE-2020-25887

Buffer overflow in mg_resolve_from_hosts_file in Mongoose 6.18, when reading from a crafted hosts...

8.8CVSS

8.7AI Score

0.001EPSS

2023-08-22 07:16 PM
13
cve
cve

CVE-2023-2905

Due to a failure in validating the length of a provided MQTT_CMD_PUBLISH parsed message with a variable length header, Cesanta Mongoose, an embeddable web server, version 7.10 is susceptible to a heap-based buffer overflow vulnerability in the default configuration. Version 7.9 and prior does not.....

8.8CVSS

8.7AI Score

0.0004EPSS

2023-08-09 05:15 AM
16
cve
cve

CVE-2021-46509

Cesanta MJS v2.20.0 was discovered to contain a stack overflow via snquote at...

7.8CVSS

7.8AI Score

0.003EPSS

2022-01-27 09:15 PM
31
cve
cve

CVE-2021-33437

An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There are memory leaks in frozen_cb() in...

5.5CVSS

5.5AI Score

0.001EPSS

2022-07-26 01:15 PM
30
cve
cve

CVE-2023-30087

Buffer Overflow vulnerability found in Cesanta MJS v.1.26 allows a local attacker to cause a denial of service via the mjs_mk_string function in...

5.5CVSS

5.3AI Score

0.001EPSS

2023-05-09 04:15 PM
8
cve
cve

CVE-2023-30088

An issue found in Cesanta MJS v.1.26 allows a local attacker to cause a denial of service via the mjs_execute function in...

5.5CVSS

5.3AI Score

0.001EPSS

2023-05-09 04:15 PM
18
cve
cve

CVE-2023-29570

Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via mjs_ffi_cb_free at src/mjs_ffi.c. This vulnerability can lead to a Denial of Service...

5.5CVSS

5.5AI Score

0.001EPSS

2023-04-24 02:15 PM
12
cve
cve

CVE-2023-29571

Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via gc_sweep at src/mjs_gc.c. This vulnerability can lead to a Denial of Service...

5.5CVSS

5.4AI Score

0.001EPSS

2023-04-12 03:15 PM
17
cve
cve

CVE-2023-29569

Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via ffi_cb_impl_wpwwwww at src/mjs_ffi.c. This vulnerability can lead to a Denial of Service...

5.5CVSS

5.5AI Score

0.001EPSS

2023-04-14 12:15 PM
10
cve
cve

CVE-2021-36535

Buffer Overflow vulnerability in Cesanta mJS 1.26 allows remote attackers to cause a denial of service via crafted .js file to...

5.5CVSS

5.5AI Score

0.001EPSS

2023-02-03 06:15 PM
8
cve
cve

CVE-2019-13503

mq_parse_http in mongoose.c in Mongoose 6.15 has a heap-based buffer...

7.5CVSS

7.6AI Score

0.003EPSS

2019-07-11 02:15 AM
148
cve
cve

CVE-2020-18392

Stack overflow vulnerability in parse_array Cesanta MJS 1.20.1, allows remote attackers to cause a Denial of Service (DoS) via a crafted...

5.5CVSS

5.4AI Score

0.001EPSS

2021-05-28 09:15 PM
62
3
cve
cve

CVE-2018-18764

An exploitable arbitrary memory read vulnerability exists in the MQTT packet-parsing functionality of Cesanta Mongoose 6.13. It is a heap-based buffer over-read in a parse_mqtt getu16 call. A specially crafted MQTT SUBSCRIBE packet can cause an arbitrary out-of-bounds memory read potentially...

9.1CVSS

8.8AI Score

0.001EPSS

2022-10-03 04:22 PM
36
cve
cve

CVE-2021-33448

An issue was discovered in mjs(mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is stack buffer overflow at...

5.5CVSS

5.8AI Score

0.001EPSS

2022-07-26 01:15 PM
31
6
cve
cve

CVE-2021-33449

An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is NULL pointer dereference in mjs_bcode_part_get_by_offset() in...

5.5CVSS

5.5AI Score

0.001EPSS

2022-07-26 01:15 PM
30
6
cve
cve

CVE-2021-33447

An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is NULL pointer dereference in mjs_print() in...

5.5CVSS

5.5AI Score

0.001EPSS

2022-07-26 01:15 PM
26
6
cve
cve

CVE-2021-33446

An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is NULL pointer dereference in mjs_next() in...

5.5CVSS

5.5AI Score

0.001EPSS

2022-07-26 01:15 PM
34
6
cve
cve

CVE-2021-33444

An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is NULL pointer dereference in getprop_builtin_foreign() in...

5.5CVSS

5.5AI Score

0.001EPSS

2022-07-26 01:15 PM
37
4
cve
cve

CVE-2021-33441

An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is NULL pointer dereference in exec_expr() in...

5.5CVSS

5.5AI Score

0.001EPSS

2022-07-26 01:15 PM
29
4
cve
cve

CVE-2021-33438

An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is stack buffer overflow in json_parse_array() in...

5.5CVSS

5.8AI Score

0.001EPSS

2022-07-26 01:15 PM
20
cve
cve

CVE-2021-33439

An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is Integer overflow in gc_compact_strings() in...

5.5CVSS

5.7AI Score

0.001EPSS

2022-07-26 01:15 PM
34
cve
cve

CVE-2021-33443

An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is stack buffer overflow in mjs_execute() in...

5.5CVSS

5.8AI Score

0.001EPSS

2022-07-26 01:15 PM
26
4
cve
cve

CVE-2021-33440

An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is NULL pointer dereference in mjs_bcode_commit() in...

5.5CVSS

5.5AI Score

0.001EPSS

2022-07-26 01:15 PM
30
cve
cve

CVE-2021-33442

An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is NULL pointer dereference in json_printf() in...

5.5CVSS

5.5AI Score

0.001EPSS

2022-07-26 01:15 PM
35
4
cve
cve

CVE-2021-33445

An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is NULL pointer dereference in mjs_string_char_code_at() in...

5.5CVSS

5.5AI Score

0.001EPSS

2022-07-26 01:15 PM
37
4
cve
cve

CVE-2021-27425

Cesanta Software Mongoose-OS v2.17.0 is vulnerable to integer wrap-around in function mm_malloc. This improper memory assignment can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash or a remote code...

9.8CVSS

9.5AI Score

0.005EPSS

2022-05-03 09:15 PM
42
cve
cve

CVE-2022-25299

This affects the package cesanta/mongoose before 7.6. The unsafe handling of file names during upload using mg_http_upload() method may enable attackers to write files to arbitrary locations outside the designated target...

9.8CVSS

7.5AI Score

0.003EPSS

2022-02-18 01:15 PM
64
cve
cve

CVE-2021-46550

Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via free_json_frame at src/mjs_json.c. This vulnerability can lead to a Denial of Service...

5.5CVSS

5.4AI Score

0.002EPSS

2022-01-27 09:15 PM
34
cve
cve

CVE-2021-46548

Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via add_lineno_map_item at src/mjs_bcode.c. This vulnerability can lead to a Denial of Service...

5.5CVSS

5.4AI Score

0.002EPSS

2022-01-27 09:15 PM
32
cve
cve

CVE-2021-46549

Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via parse_cval_type at src/mjs_ffi.c. This vulnerability can lead to a Denial of Service...

5.5CVSS

5.4AI Score

0.002EPSS

2022-01-27 09:15 PM
36
cve
cve

CVE-2021-46554

Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via mjs_json_stringify at src/mjs_json.c. This vulnerability can lead to a Denial of Service...

5.5CVSS

5.4AI Score

0.002EPSS

2022-01-27 09:15 PM
33
cve
cve

CVE-2021-46547

Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via /usr/local/bin/mjs+0x2c17e. This vulnerability can lead to a Denial of Service...

5.5CVSS

5.4AI Score

0.002EPSS

2022-01-27 09:15 PM
33
cve
cve

CVE-2021-46553

Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via mjs_set_internal at src/mjs_object.c. This vulnerability can lead to a Denial of Service...

5.5CVSS

5.4AI Score

0.002EPSS

2022-01-27 09:15 PM
36
cve
cve

CVE-2021-46556

Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via mjs_bcode_insert_offset at src/mjs_bcode.c. This vulnerability can lead to a Denial of Service...

5.5CVSS

5.4AI Score

0.002EPSS

2022-01-27 09:15 PM
33
cve
cve

CVE-2021-46522

Cesanta MJS v2.20.0 was discovered to contain a heap buffer overflow via...

7.8CVSS

7.9AI Score

0.003EPSS

2022-01-27 09:15 PM
35
cve
cve

CVE-2021-46528

Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via /usr/local/bin/mjs+0x5361e. This vulnerability can lead to a Denial of Service...

5.5CVSS

5.4AI Score

0.002EPSS

2022-01-27 09:15 PM
31
cve
cve

CVE-2021-46532

Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via exec_expr at src/mjs_exec.c. This vulnerability can lead to a Denial of Service...

5.5CVSS

5.4AI Score

0.002EPSS

2022-01-27 09:15 PM
33
cve
cve

CVE-2021-46540

Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via mjs_get_mjs at src/mjs_builtin.c. This vulnerability can lead to a Denial of Service...

5.5CVSS

5.4AI Score

0.002EPSS

2022-01-27 09:15 PM
31
cve
cve

CVE-2021-46544

Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via /usr/lib/x86_64-linux-gnu/libasan.so.4+0x59e19. This vulnerability can lead to a Denial of Service...

5.5CVSS

5.4AI Score

0.002EPSS

2022-01-27 09:15 PM
34
cve
cve

CVE-2021-46523

Cesanta MJS v2.20.0 was discovered to contain a heap buffer overflow via to_json_or_debug at...

7.8CVSS

7.9AI Score

0.003EPSS

2022-01-27 09:15 PM
31
Total number of security vulnerabilities113