JerryScript records
98 published records for vendor jerryscript.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 4
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-617 Reachable Assertion40
- CWE-787 Out-of-bounds Write20
- CWE-125 Out-of-bounds Read8
- CWE-416 Use After Free5
- CWE-476 NULL Pointer Dereference5
- CWE-400 Uncontrolled Resource Consumption4
The weakness classes this vendor ships most often: where to look.
CWEAll records
98 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2019-1010176No exploit | JerryScript commit 4e58ccf68070671e1fff5cd6673f0c1d5b80b166 is affected by: Buffer Overflow.jerryscript · jerryscript · CWE-787 | Critical9.8 | — | 2.5% | Jul 25, 2019 |
40Plan | CVE-2023-36109Proof of concept | Buffer Overflow vulnerability in JerryScript version 3.0, allows remote attackers to execute arbitrary code via ecma_stringbuilder_append_rajerryscript · jerryscript · CWE-120 | Critical9.8 | — | 2.4% | Sep 20, 2023 |
40Plan | CVE-2017-18212No exploit | An issue was discovered in JerryScript 1.0.jerryscript · jerryscript · CWE-125 | Critical9.8 | — | 1.8% | Mar 1, 2018 |
40Plan | CVE-2021-42863No exploit | A buffer overflow in ecma_builtin_typedarray_prototype_filter() in JerryScript version fe3a5c0 allows an attacker to construct a fake objectjerryscript · jerryscript · CWE-120 | Critical9.8 | — | 1.7% | May 12, 2022 |
39Monitor | CVE-2018-11419No exploit | An issue was discovered in JerryScript 1.0.jerryscript · jerryscript · CWE-125 | Critical9.8 | — | 1.6% | May 24, 2018 |
39Monitor | CVE-2018-11418No exploit | An issue was discovered in JerryScript 1.0.jerryscript · jerryscript · CWE-125 | Critical9.8 | — | 1.6% | May 24, 2018 |
39Monitor | CVE-2023-38961No exploit | Buffer Overflwo vulnerability in JerryScript Project jerryscript v.3.0.0 allows a remote attacker to execute arbitrary code via the scanner_jerryscript · jerryscript · CWE-787 | Critical9.8 | — | 1.5% | Aug 21, 2023 |
39Monitor | CVE-2020-23303No exploit | There is a heap-buffer-overflow at jmem-poolman.c:165 in jmem_pools_collect_empty in JerryScript 2.2.0.jerryscript · jerryscript · CWE-787 | Critical9.8 | — | 1.3% | Jun 10, 2021 |
39Monitor | CVE-2020-22597No exploit | An issue in Jerrscript- project Jerryscrip v.jerryscript · jerryscript | Critical9.8 | — | 1.3% | Jul 3, 2023 |
39Monitor | CVE-2020-23321No exploit | There is a heap-buffer-overflow at lit-strings.c:431 in lit_read_code_unit_from_utf8 in JerryScript 2.2.0.jerryscript · jerryscript · CWE-787 | Critical9.8 | — | 1.3% | Jun 10, 2021 |
39Monitor | CVE-2020-23323No exploit | There is a heap-buffer-overflow at re-parser.c in re_parse_char_escape in JerryScript 2.2.0.jerryscript · jerryscript · CWE-787 | Critical9.8 | — | 1.3% | Jun 10, 2021 |
39Monitor | CVE-2020-23306No exploit | There is a stack-overflow at ecma-regexp-object.c:535 in ecma_regexp_match in JerryScript 2.2.0.jerryscript · jerryscript · CWE-787 | Critical9.8 | — | 1.3% | Jun 10, 2021 |
39Monitor | CVE-2020-23302No exploit | There is a heap-use-after-free at ecma-helpers-string.c:772 in ecma_ref_ecma_string in JerryScript 2.2.0jerryscript · jerryscript · CWE-416 | Critical9.8 | — | 1.3% | Jun 10, 2021 |
39Monitor | CVE-2021-43453No exploit | A Heap-based Buffer Overflow vulnerability exists in JerryScript 2.4.0 and prior versions via an out-of-bounds read in parser_parse_for_statjerryscript · jerryscript · CWE-125 | Critical9.8 | — | 1.3% | Apr 7, 2022 |
39Monitor | CVE-2021-41751No exploit | Buffer overflow vulnerability in file ecma-builtin-array-prototype.c:909 in function ecma_builtin_array_prototype_object_slice in Jerryscripjerryscript · jerryscript · CWE-120 | Critical9.8 | — | 1.2% | Apr 5, 2022 |
39Monitor | CVE-2021-41752No exploit | Stack overflow vulnerability in Jerryscript before commit e1ce7dd7271288be8c0c8136eea9107df73a8ce2 on Oct 20, 2021 due to an unbounded recurjerryscript · jerryscript · CWE-674 | Critical9.8 | — | 1.2% | Apr 5, 2022 |
36Monitor | CVE-2020-29657No exploit | In JerryScript 2.3.0, there is an out-of-bounds read in main_print_unhandled_exception in the main-utils.c file.jerryscript · jerryscript · CWE-125 | Critical9.1 | — | 1.2% | Dec 9, 2020 |
35Monitor | CVE-2021-26195No exploit | An issue was discovered in JerryScript 2.4.0.jerryscript · jerryscript · CWE-787 | High8.8 | — | 1.1% | Jun 10, 2021 |
32Monitor | CVE-2017-14749No exploit | JerryScript 1.0 allows remote attackers to cause a denial of service (jmem_heap_alloc_block_internal heap memory corruption) or possibly exejerryscript · jerryscript · CWE-119 | High7.8 | — | 2.1% | Sep 26, 2017 |
31Monitor | CVE-2017-9250No exploit | The lexer_process_char_literal function in jerry-core/parser/js/js-lexer.c in JerryScript 1.0 does not skip memory allocation for empty strijerryscript · jerryscript · CWE-476 | High7.5 | — | 2.5% | May 28, 2017 |
31Monitor | CVE-2020-13991No exploit | vm/opcodes.c in JerryScript 2.2.0 allows attackers to hijack the flow of control by controlling a register.jerryscript · jerryscript | High7.5 | — | 2.4% | Sep 24, 2020 |
31Monitor | CVE-2020-13649No exploit | parser/js/js-scanner.c in JerryScript 2.2.0 mishandles errors during certain out-of-memory conditions, as demonstrated by a scanner_reverse_jerryscript · jerryscript · CWE-476 | High7.5 | — | 2.1% | May 28, 2020 |
31Monitor | CVE-2021-44988No exploit | Jerryscript v3.0.0 and below was discovered to contain a stack overflow via ecma_find_named_property in ecma-helpers.c.jerryscript · jerryscript · CWE-770 | High7.8 | — | 1.1% | Jan 24, 2022 |
31Monitor | CVE-2022-22895No exploit | Jerryscript 3.0.0 was discovered to contain a heap-buffer-overflow via ecma_utf8_string_to_number_by_radix in /jerry-core/ecma/base/ecma-heljerryscript · jerryscript · CWE-787 | High7.8 | — | 0.8% | Jan 20, 2022 |
31Monitor | CVE-2020-24345No exploit | JerryScript through 2.3.0 allows stack consumption via function a(){new new Proxy(a,{})}JSON.parse("[]",a).jerryscript · jerryscript · CWE-787 | High7.8 | — | 0.8% | Aug 13, 2020 |
- CVE-2019-101017640Plan
JerryScript commit 4e58ccf68070671e1fff5cd6673f0c1d5b80b166 is affected by: Buffer Overflow.
CriticalCVSS 9.8No exploitEPSS 3%jerryscript · jerryscriptJul 25, 2019
- CVE-2023-3610940Plan
Buffer Overflow vulnerability in JerryScript version 3.0, allows remote attackers to execute arbitrary code via ecma_stringbuilder_append_ra
CriticalCVSS 9.8Proof of conceptEPSS 2%jerryscript · jerryscriptSep 20, 2023
- CVE-2017-1821240Plan
An issue was discovered in JerryScript 1.0.
CriticalCVSS 9.8No exploitEPSS 2%jerryscript · jerryscriptMar 1, 2018
- CVE-2021-4286340Plan
A buffer overflow in ecma_builtin_typedarray_prototype_filter() in JerryScript version fe3a5c0 allows an attacker to construct a fake object
CriticalCVSS 9.8No exploitEPSS 2%jerryscript · jerryscriptMay 12, 2022
- CVE-2018-1141939Monitor
An issue was discovered in JerryScript 1.0.
CriticalCVSS 9.8No exploitEPSS 2%jerryscript · jerryscriptMay 24, 2018
- CVE-2018-1141839Monitor
An issue was discovered in JerryScript 1.0.
CriticalCVSS 9.8No exploitEPSS 2%jerryscript · jerryscriptMay 24, 2018
- CVE-2023-3896139Monitor
Buffer Overflwo vulnerability in JerryScript Project jerryscript v.3.0.0 allows a remote attacker to execute arbitrary code via the scanner_
CriticalCVSS 9.8No exploitEPSS 1%jerryscript · jerryscriptAug 21, 2023
- CVE-2020-2330339Monitor
There is a heap-buffer-overflow at jmem-poolman.c:165 in jmem_pools_collect_empty in JerryScript 2.2.0.
CriticalCVSS 9.8No exploitEPSS 1%jerryscript · jerryscriptJun 10, 2021
- CVE-2020-2259739Monitor
An issue in Jerrscript- project Jerryscrip v.
CriticalCVSS 9.8No exploitEPSS 1%jerryscript · jerryscriptJul 3, 2023
- CVE-2020-2332139Monitor
There is a heap-buffer-overflow at lit-strings.c:431 in lit_read_code_unit_from_utf8 in JerryScript 2.2.0.
CriticalCVSS 9.8No exploitEPSS 1%jerryscript · jerryscriptJun 10, 2021
- CVE-2020-2332339Monitor
There is a heap-buffer-overflow at re-parser.c in re_parse_char_escape in JerryScript 2.2.0.
CriticalCVSS 9.8No exploitEPSS 1%jerryscript · jerryscriptJun 10, 2021
- CVE-2020-2330639Monitor
There is a stack-overflow at ecma-regexp-object.c:535 in ecma_regexp_match in JerryScript 2.2.0.
CriticalCVSS 9.8No exploitEPSS 1%jerryscript · jerryscriptJun 10, 2021
- CVE-2020-2330239Monitor
There is a heap-use-after-free at ecma-helpers-string.c:772 in ecma_ref_ecma_string in JerryScript 2.2.0
CriticalCVSS 9.8No exploitEPSS 1%jerryscript · jerryscriptJun 10, 2021
- CVE-2021-4345339Monitor
A Heap-based Buffer Overflow vulnerability exists in JerryScript 2.4.0 and prior versions via an out-of-bounds read in parser_parse_for_stat
CriticalCVSS 9.8No exploitEPSS 1%jerryscript · jerryscriptApr 7, 2022
- CVE-2021-4175139Monitor
Buffer overflow vulnerability in file ecma-builtin-array-prototype.c:909 in function ecma_builtin_array_prototype_object_slice in Jerryscrip
CriticalCVSS 9.8No exploitEPSS 1%jerryscript · jerryscriptApr 5, 2022
- CVE-2021-4175239Monitor
Stack overflow vulnerability in Jerryscript before commit e1ce7dd7271288be8c0c8136eea9107df73a8ce2 on Oct 20, 2021 due to an unbounded recur
CriticalCVSS 9.8No exploitEPSS 1%jerryscript · jerryscriptApr 5, 2022
- CVE-2020-2965736Monitor
In JerryScript 2.3.0, there is an out-of-bounds read in main_print_unhandled_exception in the main-utils.c file.
CriticalCVSS 9.1No exploitEPSS 1%jerryscript · jerryscriptDec 9, 2020
- CVE-2021-2619535Monitor
An issue was discovered in JerryScript 2.4.0.
HighCVSS 8.8No exploitEPSS 1%jerryscript · jerryscriptJun 10, 2021
- CVE-2017-1474932Monitor
JerryScript 1.0 allows remote attackers to cause a denial of service (jmem_heap_alloc_block_internal heap memory corruption) or possibly exe
HighCVSS 7.8No exploitEPSS 2%jerryscript · jerryscriptSep 26, 2017
- CVE-2017-925031Monitor
The lexer_process_char_literal function in jerry-core/parser/js/js-lexer.c in JerryScript 1.0 does not skip memory allocation for empty stri
HighCVSS 7.5No exploitEPSS 2%jerryscript · jerryscriptMay 28, 2017
- CVE-2020-1399131Monitor
vm/opcodes.c in JerryScript 2.2.0 allows attackers to hijack the flow of control by controlling a register.
HighCVSS 7.5No exploitEPSS 2%jerryscript · jerryscriptSep 24, 2020
- CVE-2020-1364931Monitor
parser/js/js-scanner.c in JerryScript 2.2.0 mishandles errors during certain out-of-memory conditions, as demonstrated by a scanner_reverse_
HighCVSS 7.5No exploitEPSS 2%jerryscript · jerryscriptMay 28, 2020
- CVE-2021-4498831Monitor
Jerryscript v3.0.0 and below was discovered to contain a stack overflow via ecma_find_named_property in ecma-helpers.c.
HighCVSS 7.8No exploitEPSS 1%jerryscript · jerryscriptJan 24, 2022
- CVE-2022-2289531Monitor
Jerryscript 3.0.0 was discovered to contain a heap-buffer-overflow via ecma_utf8_string_to_number_by_radix in /jerry-core/ecma/base/ecma-hel
HighCVSS 7.8No exploitEPSS 1%jerryscript · jerryscriptJan 20, 2022
- CVE-2020-2434531Monitor
JerryScript through 2.3.0 allows stack consumption via function a(){new new Proxy(a,{})}JSON.parse("[]",a).
HighCVSS 7.8No exploitEPSS 1%jerryscript · jerryscriptAug 13, 2020