Skip to content
Noroxi

Cesanta records

145 published records for vendor cesanta.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
13
With a fix record
26.9%
Median publish → KEV
No record has entered KEV

All records

145 records
  • An integer overflow in parse_mqtt in mongoose.c in Cesanta Mongoose 6.16 allows an attacker to achieve remote DoS (infinite loop), or possib

    CriticalCVSS 9.8No exploitEPSS 42%

    cesanta · mongooseNov 26, 2019

  • An exploitable stack buffer overflow vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8.

    CriticalCVSS 9.8No exploitEPSS 31%

    cesanta · mongooseNov 7, 2017

  • An invalid read of 8 bytes due to a use-after-free vulnerability during a "NULL test" in the mg_http_get_proto_data function in mongoose.c i

    CriticalCVSS 9.8No exploitEPSS 4%

    cesanta · mongooseJun 10, 2019

  • An invalid write of 8 bytes due to a use-after-free vulnerability in the mg_http_free_proto_data_cgi function call in mongoose.c in Cesanta

    CriticalCVSS 9.8No exploitEPSS 4%

    cesanta · mongooseJun 10, 2019

  • An invalid read of 8 bytes due to a use-after-free vulnerability in the mg_http_free_proto_data_cgi function call in mongoose.c in Cesanta M

    CriticalCVSS 9.8No exploitEPSS 4%

    cesanta · mongooseJun 10, 2019

  • An invalid read of 8 bytes due to a use-after-free vulnerability during a "return" in the mg_http_get_proto_data function in mongoose.c in C

    CriticalCVSS 9.8No exploitEPSS 4%

    cesanta · mongooseJun 10, 2019

  • An exploitable arbitrary memory read vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8.

    CriticalCVSS 9.8No exploitEPSS 3%

    cesanta · mongooseNov 7, 2017

  • An exploitable use-after-free vulnerability exists in the HTTP server implementation of Cesanta Mongoose 6.8.

    CriticalCVSS 9.8No exploitEPSS 3%

    cesanta · mongooseNov 7, 2017

  • An exploitable memory corruption vulnerability exists in the Websocket protocol implementation of Cesanta Mongoose 6.8.

    CriticalCVSS 9.8No exploitEPSS 3%

    cesanta · mongooseNov 7, 2017

  • An exploitable memory corruption vulnerability exists in the Websocket protocol implementation of Cesanta Mongoose 6.8.

    CriticalCVSS 9.8No exploitEPSS 2%

    cesanta · mongooseNov 7, 2017

  • In mjs_json.c in Cesanta MongooseOS mJS 1.26, a maliciously formed JSON string can trigger an off-by-one heap-based buffer overflow in mjs_j

    CriticalCVSS 9.8No exploitEPSS 2%

    cesanta · mongooseos mjsApr 28, 2021

  • An issue was discovered in Mongoose before 6.15.

    CriticalCVSS 9.8No exploitEPSS 2%

    cesanta · mongooseJun 24, 2019

  • Cesanta Software Mongoose-OS Integer Overflow or Wraparound

    CriticalCVSS 9.8No exploitEPSS 2%

    cesanta · mongoose osMay 3, 2022

  • A buffer overflow vulnerability exists in the mg_get_http_header function in Cesanta Mongoose 6.18 due to a lack of bounds checking.

    CriticalCVSS 9.8No exploitEPSS 2%

    cesanta · mongooseSep 18, 2020

  • Cesanta mjs v2.20.0 was discovered to contain a function pointer hijacking vulnerability via the function mjs_get_ptr().

    CriticalCVSS 9.8No exploitEPSS 1%

    cesanta · mjsSep 22, 2023

  • Cesanta MJS 2.20.0 has a getprop_builtin_foreign out-of-bounds read if a Built-in API name occurs in a substring of an input string.

    CriticalCVSS 9.8No exploitEPSS 1%

    cesanta · mjsDec 20, 2023

  • Use of Out-of-range Pointer Offset in Mongoose Web Server library

    CriticalCVSS 9.8No exploitEPSS 0%

    cesanta · mongooseNov 18, 2024

  • CVE-2017-2893
    37Monitor

    An exploitable NULL pointer dereference vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8.

    HighCVSS 7.5No exploitEPSS 25%

    cesanta · mongooseNov 7, 2017

  • An exploitable arbitrary memory read vulnerability exists in the MQTT packet-parsing functionality of Cesanta Mongoose 6.13.

    CriticalCVSS 9.1No exploitEPSS 2%

    cesanta · mongooseOct 29, 2018

  • An exploitable arbitrary memory read vulnerability exists in the MQTT packet-parsing functionality of Cesanta Mongoose 6.13.

    CriticalCVSS 9.1No exploitEPSS 2%

    cesanta · mongooseOct 29, 2018

  • Mongoose Built-in TLS: CA-bundle certificate chain accepted without any signature verification

    CriticalCVSS 9.3No exploitEPSS 0%

    cesanta · mongooseAug 20, 2026

  • Cross-site request forgery (CSRF) vulnerability in Mongoose Web Server before 6.9 allows remote attackers to hijack the authentication of us

    HighCVSS 8.8Proof of conceptEPSS 4%

    cesanta · mongoose embedded web server librarySep 7, 2017

  • Use-after-free vulnerability in the mg_cgi_ev_handler function in mongoose.c in Cesanta Mongoose Embedded Web Server Library 6.13 and earlie

    HighCVSS 8.8No exploitEPSS 3%

    cesanta · mongoose embedded web server libraryJun 10, 2019

  • The mg_tls_init function in Cesanta Mongoose HTTPS server 7.0 and 6.7-6.18 (compiled with mbedTLS support) is vulnerable to remote OOB write

    CriticalCVSS 9.1No exploitEPSS 1%

    cesanta · mongooseFeb 8, 2021

  • The mg_http_serve_file function in Cesanta Mongoose HTTP server 7.0 is vulnerable to remote OOB write attack via connection request after ex

    CriticalCVSS 9.1No exploitEPSS 1%

    cesanta · mongooseFeb 8, 2021