Cesanta records
145 published records for vendor cesanta.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 13
- With a fix record
- 26.9%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-787 Out-of-bounds Write18
- CWE-674 Uncontrolled Recursion12
- CWE-476 NULL Pointer Dereference12
- CWE-416 Use After Free9
- CWE-125 Out-of-bounds Read8
- CWE-823 Use of Out-of-range Pointer Offset7
The weakness classes this vendor ships most often: where to look.
CWEAll records
145 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
51Plan | CVE-2019-19307No exploit | An integer overflow in parse_mqtt in mongoose.c in Cesanta Mongoose 6.16 allows an attacker to achieve remote DoS (infinite loop), or possibcesanta · mongoose · CWE-125 | Critical9.8 | — | 41.6% | Nov 26, 2019 |
48Plan | CVE-2017-2894No exploit | An exploitable stack buffer overflow vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8.cesanta · mongoose · CWE-787 | Critical9.8 | — | 31.0% | Nov 7, 2017 |
40Plan | CVE-2018-20353No exploit | An invalid read of 8 bytes due to a use-after-free vulnerability during a "NULL test" in the mg_http_get_proto_data function in mongoose.c icesanta · mongoose · CWE-416 | Critical9.8 | — | 3.6% | Jun 10, 2019 |
40Plan | CVE-2018-20355No exploit | An invalid write of 8 bytes due to a use-after-free vulnerability in the mg_http_free_proto_data_cgi function call in mongoose.c in Cesanta cesanta · mongoose · CWE-416 | Critical9.8 | — | 3.6% | Jun 10, 2019 |
40Plan | CVE-2018-20356No exploit | An invalid read of 8 bytes due to a use-after-free vulnerability in the mg_http_free_proto_data_cgi function call in mongoose.c in Cesanta Mcesanta · mongoose · CWE-416 | Critical9.8 | — | 3.6% | Jun 10, 2019 |
40Plan | CVE-2018-20354No exploit | An invalid read of 8 bytes due to a use-after-free vulnerability during a "return" in the mg_http_get_proto_data function in mongoose.c in Ccesanta · mongoose · CWE-416 | Critical9.8 | — | 3.6% | Jun 10, 2019 |
40Plan | CVE-2017-2892No exploit | An exploitable arbitrary memory read vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8.cesanta · mongoose · CWE-190 | Critical9.8 | — | 3.0% | Nov 7, 2017 |
40Plan | CVE-2017-2891No exploit | An exploitable use-after-free vulnerability exists in the HTTP server implementation of Cesanta Mongoose 6.8.cesanta · mongoose · CWE-416 | Critical9.8 | — | 2.8% | Nov 7, 2017 |
40Plan | CVE-2017-2922No exploit | An exploitable memory corruption vulnerability exists in the Websocket protocol implementation of Cesanta Mongoose 6.8.cesanta · mongoose · CWE-416 | Critical9.8 | — | 2.6% | Nov 7, 2017 |
40Plan | CVE-2017-2921No exploit | An exploitable memory corruption vulnerability exists in the Websocket protocol implementation of Cesanta Mongoose 6.8.cesanta · mongoose · CWE-190 | Critical9.8 | — | 2.4% | Nov 7, 2017 |
40Plan | CVE-2021-31875No exploit | In mjs_json.c in Cesanta MongooseOS mJS 1.26, a maliciously formed JSON string can trigger an off-by-one heap-based buffer overflow in mjs_jcesanta · mongooseos mjs · CWE-193 | Critical9.8 | — | 2.2% | Apr 28, 2021 |
40Plan | CVE-2019-12951No exploit | An issue was discovered in Mongoose before 6.15.cesanta · mongoose · CWE-787 | Critical9.8 | — | 2.0% | Jun 24, 2019 |
40Plan | CVE-2021-27425No exploit | Cesanta Software Mongoose-OS Integer Overflow or Wraparoundcesanta · mongoose os · CWE-190 | Critical9.8 | — | 1.7% | May 3, 2022 |
39Monitor | CVE-2020-25756No exploit | A buffer overflow vulnerability exists in the mg_get_http_header function in Cesanta Mongoose 6.18 due to a lack of bounds checking.cesanta · mongoose · CWE-120 | Critical9.8 | — | 1.6% | Sep 18, 2020 |
39Monitor | CVE-2023-43338No exploit | Cesanta mjs v2.20.0 was discovered to contain a function pointer hijacking vulnerability via the function mjs_get_ptr().cesanta · mjs · CWE-787 | Critical9.8 | — | 1.0% | Sep 22, 2023 |
39Monitor | CVE-2023-50044No exploit | Cesanta MJS 2.20.0 has a getprop_builtin_foreign out-of-bounds read if a Built-in API name occurs in a substring of an input string.cesanta · mjs · CWE-120 | Critical9.8 | — | 0.9% | Dec 20, 2023 |
39Monitor | CVE-2024-42383No exploit | Use of Out-of-range Pointer Offset in Mongoose Web Server librarycesanta · mongoose · CWE-823 | Critical9.8 | — | 0.3% | Nov 18, 2024 |
37Monitor | CVE-2017-2893No exploit | An exploitable NULL pointer dereference vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8.cesanta · mongoose · CWE-476 | High7.5 | — | 24.9% | Nov 7, 2017 |
37Monitor | CVE-2018-18765No exploit | An exploitable arbitrary memory read vulnerability exists in the MQTT packet-parsing functionality of Cesanta Mongoose 6.13.cesanta · mongoose · CWE-125 | Critical9.1 | — | 1.8% | Oct 29, 2018 |
37Monitor | CVE-2018-18764No exploit | An exploitable arbitrary memory read vulnerability exists in the MQTT packet-parsing functionality of Cesanta Mongoose 6.13.cesanta · mongoose · CWE-125 | Critical9.1 | — | 1.8% | Oct 29, 2018 |
37Monitor | CVE-2026-73251No exploit | Mongoose Built-in TLS: CA-bundle certificate chain accepted without any signature verificationcesanta · mongoose · CWE-295 | Critical9.3 | — | 0.3% | Aug 20, 2026 |
36Monitor | CVE-2017-11567Proof of concept | Cross-site request forgery (CSRF) vulnerability in Mongoose Web Server before 6.9 allows remote attackers to hijack the authentication of uscesanta · mongoose embedded web server library · CWE-352 | High8.8 | — | 4.1% | Sep 7, 2017 |
36Monitor | CVE-2018-20352No exploit | Use-after-free vulnerability in the mg_cgi_ev_handler function in mongoose.c in Cesanta Mongoose Embedded Web Server Library 6.13 and earliecesanta · mongoose embedded web server library · CWE-416 | High8.8 | — | 2.7% | Jun 10, 2019 |
36Monitor | CVE-2021-26529No exploit | The mg_tls_init function in Cesanta Mongoose HTTPS server 7.0 and 6.7-6.18 (compiled with mbedTLS support) is vulnerable to remote OOB writecesanta · mongoose · CWE-787 | Critical9.1 | — | 1.5% | Feb 8, 2021 |
36Monitor | CVE-2021-26528No exploit | The mg_http_serve_file function in Cesanta Mongoose HTTP server 7.0 is vulnerable to remote OOB write attack via connection request after excesanta · mongoose · CWE-787 | Critical9.1 | — | 1.5% | Feb 8, 2021 |
- CVE-2019-1930751Plan
An integer overflow in parse_mqtt in mongoose.c in Cesanta Mongoose 6.16 allows an attacker to achieve remote DoS (infinite loop), or possib
CriticalCVSS 9.8No exploitEPSS 42%cesanta · mongooseNov 26, 2019
- CVE-2017-289448Plan
An exploitable stack buffer overflow vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8.
CriticalCVSS 9.8No exploitEPSS 31%cesanta · mongooseNov 7, 2017
- CVE-2018-2035340Plan
An invalid read of 8 bytes due to a use-after-free vulnerability during a "NULL test" in the mg_http_get_proto_data function in mongoose.c i
CriticalCVSS 9.8No exploitEPSS 4%cesanta · mongooseJun 10, 2019
- CVE-2018-2035540Plan
An invalid write of 8 bytes due to a use-after-free vulnerability in the mg_http_free_proto_data_cgi function call in mongoose.c in Cesanta
CriticalCVSS 9.8No exploitEPSS 4%cesanta · mongooseJun 10, 2019
- CVE-2018-2035640Plan
An invalid read of 8 bytes due to a use-after-free vulnerability in the mg_http_free_proto_data_cgi function call in mongoose.c in Cesanta M
CriticalCVSS 9.8No exploitEPSS 4%cesanta · mongooseJun 10, 2019
- CVE-2018-2035440Plan
An invalid read of 8 bytes due to a use-after-free vulnerability during a "return" in the mg_http_get_proto_data function in mongoose.c in C
CriticalCVSS 9.8No exploitEPSS 4%cesanta · mongooseJun 10, 2019
- CVE-2017-289240Plan
An exploitable arbitrary memory read vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8.
CriticalCVSS 9.8No exploitEPSS 3%cesanta · mongooseNov 7, 2017
- CVE-2017-289140Plan
An exploitable use-after-free vulnerability exists in the HTTP server implementation of Cesanta Mongoose 6.8.
CriticalCVSS 9.8No exploitEPSS 3%cesanta · mongooseNov 7, 2017
- CVE-2017-292240Plan
An exploitable memory corruption vulnerability exists in the Websocket protocol implementation of Cesanta Mongoose 6.8.
CriticalCVSS 9.8No exploitEPSS 3%cesanta · mongooseNov 7, 2017
- CVE-2017-292140Plan
An exploitable memory corruption vulnerability exists in the Websocket protocol implementation of Cesanta Mongoose 6.8.
CriticalCVSS 9.8No exploitEPSS 2%cesanta · mongooseNov 7, 2017
- CVE-2021-3187540Plan
In mjs_json.c in Cesanta MongooseOS mJS 1.26, a maliciously formed JSON string can trigger an off-by-one heap-based buffer overflow in mjs_j
CriticalCVSS 9.8No exploitEPSS 2%cesanta · mongooseos mjsApr 28, 2021
- CVE-2019-1295140Plan
An issue was discovered in Mongoose before 6.15.
CriticalCVSS 9.8No exploitEPSS 2%cesanta · mongooseJun 24, 2019
- CVE-2021-2742540Plan
Cesanta Software Mongoose-OS Integer Overflow or Wraparound
CriticalCVSS 9.8No exploitEPSS 2%cesanta · mongoose osMay 3, 2022
- CVE-2020-2575639Monitor
A buffer overflow vulnerability exists in the mg_get_http_header function in Cesanta Mongoose 6.18 due to a lack of bounds checking.
CriticalCVSS 9.8No exploitEPSS 2%cesanta · mongooseSep 18, 2020
- CVE-2023-4333839Monitor
Cesanta mjs v2.20.0 was discovered to contain a function pointer hijacking vulnerability via the function mjs_get_ptr().
CriticalCVSS 9.8No exploitEPSS 1%cesanta · mjsSep 22, 2023
- CVE-2023-5004439Monitor
Cesanta MJS 2.20.0 has a getprop_builtin_foreign out-of-bounds read if a Built-in API name occurs in a substring of an input string.
CriticalCVSS 9.8No exploitEPSS 1%cesanta · mjsDec 20, 2023
- CVE-2024-4238339Monitor
Use of Out-of-range Pointer Offset in Mongoose Web Server library
CriticalCVSS 9.8No exploitEPSS 0%cesanta · mongooseNov 18, 2024
- CVE-2017-289337Monitor
An exploitable NULL pointer dereference vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8.
HighCVSS 7.5No exploitEPSS 25%cesanta · mongooseNov 7, 2017
- CVE-2018-1876537Monitor
An exploitable arbitrary memory read vulnerability exists in the MQTT packet-parsing functionality of Cesanta Mongoose 6.13.
CriticalCVSS 9.1No exploitEPSS 2%cesanta · mongooseOct 29, 2018
- CVE-2018-1876437Monitor
An exploitable arbitrary memory read vulnerability exists in the MQTT packet-parsing functionality of Cesanta Mongoose 6.13.
CriticalCVSS 9.1No exploitEPSS 2%cesanta · mongooseOct 29, 2018
- CVE-2026-7325137Monitor
Mongoose Built-in TLS: CA-bundle certificate chain accepted without any signature verification
CriticalCVSS 9.3No exploitEPSS 0%cesanta · mongooseAug 20, 2026
- CVE-2017-1156736Monitor
Cross-site request forgery (CSRF) vulnerability in Mongoose Web Server before 6.9 allows remote attackers to hijack the authentication of us
HighCVSS 8.8Proof of conceptEPSS 4%cesanta · mongoose embedded web server librarySep 7, 2017
- CVE-2018-2035236Monitor
Use-after-free vulnerability in the mg_cgi_ev_handler function in mongoose.c in Cesanta Mongoose Embedded Web Server Library 6.13 and earlie
HighCVSS 8.8No exploitEPSS 3%cesanta · mongoose embedded web server libraryJun 10, 2019
- CVE-2021-2652936Monitor
The mg_tls_init function in Cesanta Mongoose HTTPS server 7.0 and 6.7-6.18 (compiled with mbedTLS support) is vulnerable to remote OOB write
CriticalCVSS 9.1No exploitEPSS 1%cesanta · mongooseFeb 8, 2021
- CVE-2021-2652836Monitor
The mg_http_serve_file function in Cesanta Mongoose HTTP server 7.0 is vulnerable to remote OOB write attack via connection request after ex
CriticalCVSS 9.1No exploitEPSS 1%cesanta · mongooseFeb 8, 2021