Skip to content
Noroxi

QuickJS Project records

14 published records for vendor quickjs project.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
71.4%
Median publish → KEV
No record has entered KEV

All records

14 records
  • Use-after-free in js_std_promise_rejection_check in QuickJS

    HighCVSS 8.8No exploitEPSS 0%

    quickjs project · quickjsOct 16, 2025

  • Use-after-free in js_print_object in QuickJS

    HighCVSS 8.8No exploitEPSS 0%

    quickjs project · quickjsOct 16, 2025

  • quickjs-ng through 0.9.0 has an incorrect size calculation in JS_ReadBigInt for a BigInt, leading to a heap-based buffer overflow.

    HighCVSS 8.4No exploitEPSS 0%

    quickjs-ng · quickjsApr 27, 2025

  • Buffer Overflow vulnerability in quickjs.c in QuickJS, allows remote attackers to cause denial of service.

    HighCVSS 7.5No exploitEPSS 2%

    quickjs project · quickjsJul 13, 2021

  • QuickJS commit 2788d71 was discovered to contain a stack-overflow via the component js_proxy_isArray at quickjs.c.

    HighCVSS 7.5No exploitEPSS 1%

    quickjs project · quickjsMay 12, 2023

  • QuickJS before c4cdd61 has a build_for_in_iterator NULL pointer dereference because of an erroneous lexical scope of "this" with eval.

    HighCVSS 7.5No exploitEPSS 1%

    quickjs project · quickjsApr 23, 2024

  • A crafted JavaScript input executed with the QuickJS release 2025-09-13, fixed in commit fcd33c1afa7b3028531f53cd1190a3877454f6b3 (2025-12-1

    HighCVSS 7.5No exploitEPSS 0%

    quickjs project · quickjsMar 6, 2026

  • Type confusion in string addition in QuickJS

    HighCVSS 7.1No exploitEPSS 1%

    quickjs project · quickjsOct 16, 2025

  • Integer overflow in js_bigint_from_string in QuickJS

    HighCVSS 7.1No exploitEPSS 0%

    quickjs project · quickjsOct 16, 2025

  • Type confusion in string addition in QuickJS

    HighCVSS 7.1No exploitEPSS 0%

    quickjs project · quickjsOct 16, 2025

  • A crafted JavaScript input can trigger an internal assertion failure in QuickJS release 2025-09-13, fixed in commit 1dbba8a88eaa40d15a8a9b70

    MediumCVSS 6.5No exploitEPSS 0%

    quickjs project · quickjsMar 6, 2026

  • Heap out-of-bounds read in js_typed_array_indexOf in QuickJS

    MediumCVSS 5.9No exploitEPSS 0%

    quickjs project · quickjsOct 16, 2025

  • Heap out-of-bounds read in js_bigint_to_string1 in QuickJS

    MediumCVSS 5.9No exploitEPSS 0%

    quickjs project · quickjsOct 16, 2025

  • QuickJS before 7414e5f has a quickjs.h JS_FreeValueRT use-after-free because of incorrect garbage collection of async functions with closure

    LowCVSS 3.9No exploitEPSS 0%

    quickjs project · quickjsApr 23, 2024