Jsish records
53 published records for vendor jsish.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 4
- With a fix record
- 5.7%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-416 Use After Free15
- CWE-787 Out-of-bounds Write12
- CWE-476 NULL Pointer Dereference5
- CWE-617 Reachable Assertion3
- CWE-674 Uncontrolled Recursion2
- CWE-125 Out-of-bounds Read2
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
53 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2020-22875No exploit | Integer overflow vulnerability in function Jsi_ObjSetLength in jsish before 3.0.6, allows remote attackers to execute arbitrary code.jsish · jsish · CWE-190 | Critical9.8 | — | 3.3% | Jul 13, 2021 |
40Plan | CVE-2020-22874No exploit | Integer overflow vulnerability in function Jsi_ObjArraySizer in jsish before 3.0.8, allows remote attackers to execute arbitrary code.jsish · jsish · CWE-190 | Critical9.8 | — | 3.3% | Jul 13, 2021 |
40Plan | CVE-2020-22873No exploit | Buffer overflow vulnerability in function NumberToPrecisionCmd in jsish before 3.0.7, allows remote attackers to execute arbitrary code.jsish · jsish · CWE-120 | Critical9.8 | — | 2.3% | Jul 13, 2021 |
40Plan | CVE-2019-1010177No exploit | Jsish 2.4.70 2.047 is affected by: Use After Free.jsish · jsish · CWE-416 | Critical9.8 | — | 2.1% | Jul 24, 2019 |
39Monitor | CVE-2024-24186No exploit | Jsish v3.5.0 (commit 42c694c) was discovered to contain a stack-overflow via the component IterGetKeysCallback at /jsish/src/jsiValue.c.jsish · jsish · CWE-787 | Critical9.8 | — | 0.9% | Feb 7, 2024 |
39Monitor | CVE-2024-24188No exploit | Jsish v3.5.0 was discovered to contain a heap-buffer-overflow in ./src/jsiUtils.c.jsish · jsish · CWE-787 | Critical9.8 | — | 0.8% | Feb 7, 2024 |
39Monitor | CVE-2024-24189No exploit | Jsish v3.5.0 (commit 42c694c) was discovered to contain a use-after-free via the SplitChar at ./src/jsiUtils.c.jsish · jsish · CWE-416 | Critical9.8 | — | 0.7% | Feb 7, 2024 |
39Monitor | CVE-2025-65570No exploit | A type confusion in jsish 2.0 allows incorrect control flow during execution of the OP_NEXT opcode.jsish · jsish · CWE-843 | Critical9.8 | — | 0.5% | Dec 29, 2025 |
31Monitor | CVE-2021-46482No exploit | Jsish v3.5.0 was discovered to contain a heap buffer overflow via NumberConstructor at src/jsiNumber.c.jsish · jsish · CWE-787 | High7.8 | — | 0.8% | Jan 24, 2022 |
31Monitor | CVE-2021-46483No exploit | Jsish v3.5.0 was discovered to contain a heap buffer overflow via BooleanConstructor at src/jsiBool.c.jsish · jsish · CWE-787 | High7.8 | — | 0.8% | Jan 24, 2022 |
30Monitor | CVE-2020-22907No exploit | Stack overflow vulnerability in function jsi_evalcode_sub in jsish before 3.0.18, allows remote attackers to cause a Denial of Service via ajsish · jsish · CWE-787 | High7.5 | — | 1.6% | Jul 13, 2021 |
30Monitor | CVE-2019-1010169No exploit | Jsish 2.4.77 2.0477 is affected by: Out-of-bounds Read.jsish · jsish · CWE-125 | High7.5 | — | 1.4% | Jul 23, 2019 |
30Monitor | CVE-2019-1010172No exploit | Jsish 2.4.84 2.0484 is affected by: Uncontrolled Resource Consumption.jsish · jsish · CWE-400 | High7.5 | — | 1.3% | Jul 25, 2019 |
30Monitor | CVE-2019-1010170No exploit | Jsish 2.4.77 2.0477 is affected by: Use After Free.jsish · jsish · CWE-416 | High7.5 | — | 1.1% | Jul 23, 2019 |
30Monitor | CVE-2019-1010173No exploit | Jsish 2.4.84 2.0484 is affected by: Reachable Assertion.jsish · jsish · CWE-617 | High7.5 | — | 1.1% | Jul 23, 2019 |
30Monitor | CVE-2019-1010171No exploit | Jsish 2.4.83 2.0483 is affected by: Nullpointer dereference.jsish · jsish · CWE-476 | High7.5 | — | 1.1% | Jul 23, 2019 |
30Monitor | CVE-2020-23258No exploit | An issue found in Jsish v.3.0.11 allows a remote attacker to cause a denial of service via the Jsi_ValueIsNumber function in ./src/jsiValue.jsish · jsish · CWE-787 | High7.5 | — | 1.0% | Apr 4, 2023 |
30Monitor | CVE-2020-23260No exploit | An issue found in Jsish v.3.0.11 and before allows an attacker to cause a denial of service via the StringReplaceCmd function in the src/jsijsish · jsish · CWE-787 | High7.5 | — | 0.8% | Apr 4, 2023 |
30Monitor | CVE-2020-23259No exploit | An issue found in Jsish v.3.0.11 and before allows an attacker to cause a denial of service via the Jsi_Strlen function in the src/jsiChar.cjsish · jsish · CWE-476 | High7.5 | — | 0.8% | Apr 4, 2023 |
26Monitor | CVE-2018-1000655No exploit | Jsish version 2.4.65 contains a CWE-476: NULL Pointer Dereference vulnerability in Function jsi_ValueCopyMove from jsiValue.c:240 that can rjsish · jsish · CWE-476 | Medium6.5 | — | 0.9% | Aug 20, 2018 |
26Monitor | CVE-2018-1000661No exploit | jsish version 2.4.67 contains a CWE-476: NULL Pointer Dereference vulnerability in Jsi_LogMsg (jsiUtils.c:196) that can result in Crash due jsish · jsish · CWE-476 | Medium6.5 | — | 0.9% | Sep 6, 2018 |
26Monitor | CVE-2018-1000668No exploit | jsish version 2.4.70 2.047 contains a CWE-125: Out-of-bounds Read vulnerability in function jsi_ObjArrayLookup (jsiObj.c:274) that can resuljsish · jsish · CWE-125 | Medium6.5 | — | 0.9% | Sep 6, 2018 |
26Monitor | CVE-2018-1000663No exploit | jsish version 2.4.70 2.047 contains a Buffer Overflow vulnerability in function _jsi_evalcode from jsiEval.c that can result in Crash due tojsish · jsish · CWE-119 | Medium6.5 | — | 0.9% | Sep 6, 2018 |
22Monitor | CVE-2019-1010162No exploit | jsish 2.4.74 2.0474 is affected by: CWE-476: NULL Pointer Dereference.jsish · jsish · CWE-476 | Medium5.5 | — | 0.8% | Jul 23, 2019 |
22Monitor | CVE-2021-46481No exploit | Jsish v3.5.0 was discovered to contain a memory leak via linenoise at src/linenoise.c.jsish · jsish · CWE-401 | Medium5.5 | — | 0.7% | Jan 24, 2022 |
- CVE-2020-2287540Plan
Integer overflow vulnerability in function Jsi_ObjSetLength in jsish before 3.0.6, allows remote attackers to execute arbitrary code.
CriticalCVSS 9.8No exploitEPSS 3%jsish · jsishJul 13, 2021
- CVE-2020-2287440Plan
Integer overflow vulnerability in function Jsi_ObjArraySizer in jsish before 3.0.8, allows remote attackers to execute arbitrary code.
CriticalCVSS 9.8No exploitEPSS 3%jsish · jsishJul 13, 2021
- CVE-2020-2287340Plan
Buffer overflow vulnerability in function NumberToPrecisionCmd in jsish before 3.0.7, allows remote attackers to execute arbitrary code.
CriticalCVSS 9.8No exploitEPSS 2%jsish · jsishJul 13, 2021
- CVE-2019-101017740Plan
Jsish 2.4.70 2.047 is affected by: Use After Free.
CriticalCVSS 9.8No exploitEPSS 2%jsish · jsishJul 24, 2019
- CVE-2024-2418639Monitor
Jsish v3.5.0 (commit 42c694c) was discovered to contain a stack-overflow via the component IterGetKeysCallback at /jsish/src/jsiValue.c.
CriticalCVSS 9.8No exploitEPSS 1%jsish · jsishFeb 7, 2024
- CVE-2024-2418839Monitor
Jsish v3.5.0 was discovered to contain a heap-buffer-overflow in ./src/jsiUtils.c.
CriticalCVSS 9.8No exploitEPSS 1%jsish · jsishFeb 7, 2024
- CVE-2024-2418939Monitor
Jsish v3.5.0 (commit 42c694c) was discovered to contain a use-after-free via the SplitChar at ./src/jsiUtils.c.
CriticalCVSS 9.8No exploitEPSS 1%jsish · jsishFeb 7, 2024
- CVE-2025-6557039Monitor
A type confusion in jsish 2.0 allows incorrect control flow during execution of the OP_NEXT opcode.
CriticalCVSS 9.8No exploitEPSS 1%jsish · jsishDec 29, 2025
- CVE-2021-4648231Monitor
Jsish v3.5.0 was discovered to contain a heap buffer overflow via NumberConstructor at src/jsiNumber.c.
HighCVSS 7.8No exploitEPSS 1%jsish · jsishJan 24, 2022
- CVE-2021-4648331Monitor
Jsish v3.5.0 was discovered to contain a heap buffer overflow via BooleanConstructor at src/jsiBool.c.
HighCVSS 7.8No exploitEPSS 1%jsish · jsishJan 24, 2022
- CVE-2020-2290730Monitor
Stack overflow vulnerability in function jsi_evalcode_sub in jsish before 3.0.18, allows remote attackers to cause a Denial of Service via a
HighCVSS 7.5No exploitEPSS 2%jsish · jsishJul 13, 2021
- CVE-2019-101016930Monitor
Jsish 2.4.77 2.0477 is affected by: Out-of-bounds Read.
HighCVSS 7.5No exploitEPSS 1%jsish · jsishJul 23, 2019
- CVE-2019-101017230Monitor
Jsish 2.4.84 2.0484 is affected by: Uncontrolled Resource Consumption.
HighCVSS 7.5No exploitEPSS 1%jsish · jsishJul 25, 2019
- CVE-2019-101017030Monitor
Jsish 2.4.77 2.0477 is affected by: Use After Free.
HighCVSS 7.5No exploitEPSS 1%jsish · jsishJul 23, 2019
- CVE-2019-101017330Monitor
Jsish 2.4.84 2.0484 is affected by: Reachable Assertion.
HighCVSS 7.5No exploitEPSS 1%jsish · jsishJul 23, 2019
- CVE-2019-101017130Monitor
Jsish 2.4.83 2.0483 is affected by: Nullpointer dereference.
HighCVSS 7.5No exploitEPSS 1%jsish · jsishJul 23, 2019
- CVE-2020-2325830Monitor
An issue found in Jsish v.3.0.11 allows a remote attacker to cause a denial of service via the Jsi_ValueIsNumber function in ./src/jsiValue.
HighCVSS 7.5No exploitEPSS 1%jsish · jsishApr 4, 2023
- CVE-2020-2326030Monitor
An issue found in Jsish v.3.0.11 and before allows an attacker to cause a denial of service via the StringReplaceCmd function in the src/jsi
HighCVSS 7.5No exploitEPSS 1%jsish · jsishApr 4, 2023
- CVE-2020-2325930Monitor
An issue found in Jsish v.3.0.11 and before allows an attacker to cause a denial of service via the Jsi_Strlen function in the src/jsiChar.c
HighCVSS 7.5No exploitEPSS 1%jsish · jsishApr 4, 2023
- CVE-2018-100065526Monitor
Jsish version 2.4.65 contains a CWE-476: NULL Pointer Dereference vulnerability in Function jsi_ValueCopyMove from jsiValue.c:240 that can r
MediumCVSS 6.5No exploitEPSS 1%jsish · jsishAug 20, 2018
- CVE-2018-100066126Monitor
jsish version 2.4.67 contains a CWE-476: NULL Pointer Dereference vulnerability in Jsi_LogMsg (jsiUtils.c:196) that can result in Crash due
MediumCVSS 6.5No exploitEPSS 1%jsish · jsishSep 6, 2018
- CVE-2018-100066826Monitor
jsish version 2.4.70 2.047 contains a CWE-125: Out-of-bounds Read vulnerability in function jsi_ObjArrayLookup (jsiObj.c:274) that can resul
MediumCVSS 6.5No exploitEPSS 1%jsish · jsishSep 6, 2018
- CVE-2018-100066326Monitor
jsish version 2.4.70 2.047 contains a Buffer Overflow vulnerability in function _jsi_evalcode from jsiEval.c that can result in Crash due to
MediumCVSS 6.5No exploitEPSS 1%jsish · jsishSep 6, 2018
- CVE-2019-101016222Monitor
jsish 2.4.74 2.0474 is affected by: CWE-476: NULL Pointer Dereference.
MediumCVSS 5.5No exploitEPSS 1%jsish · jsishJul 23, 2019
- CVE-2021-4648122Monitor
Jsish v3.5.0 was discovered to contain a memory leak via linenoise at src/linenoise.c.
MediumCVSS 5.5No exploitEPSS 1%jsish · jsishJan 24, 2022