moddable records
25 published records for vendor moddable.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-787 Out-of-bounds Write11
- CWE-125 Out-of-bounds Read2
- CWE-476 NULL Pointer Dereference2
- CWE-770 Allocation of Resources Without Limits or Throttling2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-843 Access of Resource Using Incompatible Type ('Type Confusion')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
25 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2020-25462No exploit | Heap buffer overflow in the fxCheckArrowFunction function at moddable/xs/sources/xsSyntaxical.c:3562 in Moddable SDK before OS200903.moddable · moddable · CWE-787 | Critical9.8 | — | 2.0% | Dec 4, 2020 |
39Monitor | CVE-2019-16366No exploit | In XS 9.0.0 in Moddable SDK OS180329, there is a heap-based buffer overflow in fxBeginHost in xsAPI.c when called from fxRunDefine in xsRun.moddable · moddable · CWE-787 | Critical9.8 | — | 1.4% | Sep 16, 2019 |
31Monitor | CVE-2021-46332No exploit | Moddable SDK v11.5.0 was discovered to contain a heap-buffer-overflow via xs/sources/xsDataView.c in fxUint8Getter.moddable · moddable sdk · CWE-787 | High7.8 | — | 1.0% | Jan 20, 2022 |
31Monitor | CVE-2021-46326No exploit | Moddable SDK v11.5.0 was discovered to contain a heap-buffer-overflow via the component __asan_memcpy.moddable · moddable sdk · CWE-787 | High7.8 | — | 0.9% | Jan 20, 2022 |
31Monitor | CVE-2021-46334No exploit | Moddable SDK v11.5.0 was discovered to contain a stack buffer overflow via the component __interceptor_strcat.moddable · moddable sdk · CWE-787 | High7.8 | — | 0.8% | Jan 20, 2022 |
31Monitor | CVE-2021-46328No exploit | Moddable SDK v11.5.0 was discovered to contain a heap-buffer-overflow via the component __libc_start_main.moddable · moddable sdk · CWE-787 | High7.8 | — | 0.8% | Jan 20, 2022 |
31Monitor | CVE-2021-29329No exploit | OpenSource Moddable v10.5.0 was discovered to contain a stack overflow in the fxBinaryExpressionNodeDistribute function at /moddable/xs/sourmoddable · moddable · CWE-770 | High7.8 | — | 0.8% | Nov 19, 2021 |
31Monitor | CVE-2021-29325No exploit | OpenSource Moddable v10.5.0 was discovered to contain a heap buffer overflow in the fx_String_prototype_repeat function at /moddable/xs/sourmoddable · moddable · CWE-787 | High7.8 | — | 0.8% | Nov 19, 2021 |
31Monitor | CVE-2021-29327No exploit | OpenSource Moddable v10.5.0 was discovered to contain a heap buffer overflow in the fx_ArrayBuffer function at /moddable/xs/sources/xsDataVimoddable · moddable · CWE-787 | High7.8 | — | 0.8% | Nov 19, 2021 |
31Monitor | CVE-2021-29324No exploit | OpenSource Moddable v10.5.0 was discovered to contain a stack overflow via the component /moddable/xs/sources/xsScript.c.moddable · moddable · CWE-770 | High7.8 | — | 0.8% | Nov 19, 2021 |
31Monitor | CVE-2021-29326No exploit | OpenSource Moddable v10.5.0 was discovered to contain a heap buffer overflow in the fxIDToString function at /moddable/xs/sources/xsSymbol.cmoddable · moddable · CWE-787 | High7.8 | — | 0.8% | Nov 19, 2021 |
30Monitor | CVE-2020-25465No exploit | Null Pointer Dereference.moddable · moddable · CWE-476 | High7.5 | — | 1.6% | Dec 4, 2020 |
30Monitor | CVE-2020-25463No exploit | Invalid Memory Access in fxUTF8Decode at moddable/xs/sources/xsCommon.c:916 in Moddable SDK before OS200908 causes a denial of service (SEGVmoddable · moddable | High7.5 | — | 1.3% | Dec 4, 2020 |
30Monitor | CVE-2020-25461No exploit | Invalid Memory Access in the fxProxyGetter function in moddable/xs/sources/xsProxy.c in Moddable SDK before OS200908 causes a denial of servmoddable · moddable | High7.5 | — | 1.3% | Dec 4, 2020 |
30Monitor | CVE-2020-22882No exploit | Issue was discovered in the fxParserTree function in moddable, allows attackers to cause denial of service via a crafted payload.moddable · moddable · CWE-843 | High7.5 | — | 1.2% | Jul 13, 2021 |
30Monitor | CVE-2020-25464No exploit | Heap buffer overflow at moddable/xs/sources/xsDebug.c in Moddable SDK before before 20200903.moddable · moddable · CWE-787 | High7.5 | — | 1.1% | Dec 4, 2020 |
28Monitor | CVE-2022-29368No exploit | Moddable commit before 135aa9a4a6a9b49b60aa730ebc3bcc6247d75c45 was discovered to contain an out-of-bounds read via the function fxUint8Gettmoddable · moddable · CWE-125 | High7.1 | — | 0.9% | May 12, 2022 |
28Monitor | CVE-2021-29328No exploit | OpenSource Moddable v10.5.0 was discovered to contain buffer over-read in the fxDebugThrow function at /moddable/xs/sources/xsDebug.c.moddable · moddable · CWE-125 | High7.1 | — | 0.7% | Nov 19, 2021 |
22Monitor | CVE-2021-46335No exploit | Moddable SDK v11.5.0 was discovered to contain a NULL pointer dereference in the component fx_Function_prototype_hasInstance.moddable · moddable sdk · CWE-476 | Medium5.5 | — | 0.8% | Jan 20, 2022 |
22Monitor | CVE-2021-46331No exploit | Moddable SDK v11.5.0 was discovered to contain a SEGV vulnerability via xs/sources/xsProxy.c in fxProxyGetPrototype.moddable · moddable sdk | Medium5.5 | — | 0.7% | Jan 20, 2022 |
22Monitor | CVE-2021-46327No exploit | Moddable SDK v11.5.0 was discovered to contain a SEGV vulnerability via xs/sources/xsArray.c in fx_Array_prototype_sort.moddable · moddable sdk | Medium5.5 | — | 0.7% | Jan 20, 2022 |
22Monitor | CVE-2021-46333No exploit | Moddable SDK v11.5.0 was discovered to contain an invalid memory access vulnerability via the component __asan_memmove.moddable · moddable sdk · CWE-119 | Medium5.5 | — | 0.7% | Jan 20, 2022 |
22Monitor | CVE-2021-46329No exploit | Moddable SDK v11.5.0 was discovered to contain a SEGV vulnerability via the component _fini.moddable · moddable sdk | Medium5.5 | — | 0.7% | Jan 20, 2022 |
22Monitor | CVE-2021-46330No exploit | Moddable SDK v11.5.0 was discovered to contain a SEGV vulnerability via xs/sources/xsDataView.c in fx_ArrayBuffer_prototype_concat.moddable · moddable sdk | Medium5.5 | — | 0.7% | Jan 20, 2022 |
22Monitor | CVE-2021-29323No exploit | OpenSource Moddable v10.5.0 was discovered to contain a heap buffer overflow via the component /modules/network/wifi/esp/modwifi.c.moddable · moddable · CWE-787 | Medium5.5 | — | 0.6% | Nov 19, 2021 |
- CVE-2020-2546240Plan
Heap buffer overflow in the fxCheckArrowFunction function at moddable/xs/sources/xsSyntaxical.c:3562 in Moddable SDK before OS200903.
CriticalCVSS 9.8No exploitEPSS 2%moddable · moddableDec 4, 2020
- CVE-2019-1636639Monitor
In XS 9.0.0 in Moddable SDK OS180329, there is a heap-based buffer overflow in fxBeginHost in xsAPI.c when called from fxRunDefine in xsRun.
CriticalCVSS 9.8No exploitEPSS 1%moddable · moddableSep 16, 2019
- CVE-2021-4633231Monitor
Moddable SDK v11.5.0 was discovered to contain a heap-buffer-overflow via xs/sources/xsDataView.c in fxUint8Getter.
HighCVSS 7.8No exploitEPSS 1%moddable · moddable sdkJan 20, 2022
- CVE-2021-4632631Monitor
Moddable SDK v11.5.0 was discovered to contain a heap-buffer-overflow via the component __asan_memcpy.
HighCVSS 7.8No exploitEPSS 1%moddable · moddable sdkJan 20, 2022
- CVE-2021-4633431Monitor
Moddable SDK v11.5.0 was discovered to contain a stack buffer overflow via the component __interceptor_strcat.
HighCVSS 7.8No exploitEPSS 1%moddable · moddable sdkJan 20, 2022
- CVE-2021-4632831Monitor
Moddable SDK v11.5.0 was discovered to contain a heap-buffer-overflow via the component __libc_start_main.
HighCVSS 7.8No exploitEPSS 1%moddable · moddable sdkJan 20, 2022
- CVE-2021-2932931Monitor
OpenSource Moddable v10.5.0 was discovered to contain a stack overflow in the fxBinaryExpressionNodeDistribute function at /moddable/xs/sour
HighCVSS 7.8No exploitEPSS 1%moddable · moddableNov 19, 2021
- CVE-2021-2932531Monitor
OpenSource Moddable v10.5.0 was discovered to contain a heap buffer overflow in the fx_String_prototype_repeat function at /moddable/xs/sour
HighCVSS 7.8No exploitEPSS 1%moddable · moddableNov 19, 2021
- CVE-2021-2932731Monitor
OpenSource Moddable v10.5.0 was discovered to contain a heap buffer overflow in the fx_ArrayBuffer function at /moddable/xs/sources/xsDataVi
HighCVSS 7.8No exploitEPSS 1%moddable · moddableNov 19, 2021
- CVE-2021-2932431Monitor
OpenSource Moddable v10.5.0 was discovered to contain a stack overflow via the component /moddable/xs/sources/xsScript.c.
HighCVSS 7.8No exploitEPSS 1%moddable · moddableNov 19, 2021
- CVE-2021-2932631Monitor
OpenSource Moddable v10.5.0 was discovered to contain a heap buffer overflow in the fxIDToString function at /moddable/xs/sources/xsSymbol.c
HighCVSS 7.8No exploitEPSS 1%moddable · moddableNov 19, 2021
- CVE-2020-2546530Monitor
Null Pointer Dereference.
HighCVSS 7.5No exploitEPSS 2%moddable · moddableDec 4, 2020
- CVE-2020-2546330Monitor
Invalid Memory Access in fxUTF8Decode at moddable/xs/sources/xsCommon.c:916 in Moddable SDK before OS200908 causes a denial of service (SEGV
HighCVSS 7.5No exploitEPSS 1%moddable · moddableDec 4, 2020
- CVE-2020-2546130Monitor
Invalid Memory Access in the fxProxyGetter function in moddable/xs/sources/xsProxy.c in Moddable SDK before OS200908 causes a denial of serv
HighCVSS 7.5No exploitEPSS 1%moddable · moddableDec 4, 2020
- CVE-2020-2288230Monitor
Issue was discovered in the fxParserTree function in moddable, allows attackers to cause denial of service via a crafted payload.
HighCVSS 7.5No exploitEPSS 1%moddable · moddableJul 13, 2021
- CVE-2020-2546430Monitor
Heap buffer overflow at moddable/xs/sources/xsDebug.c in Moddable SDK before before 20200903.
HighCVSS 7.5No exploitEPSS 1%moddable · moddableDec 4, 2020
- CVE-2022-2936828Monitor
Moddable commit before 135aa9a4a6a9b49b60aa730ebc3bcc6247d75c45 was discovered to contain an out-of-bounds read via the function fxUint8Gett
HighCVSS 7.1No exploitEPSS 1%moddable · moddableMay 12, 2022
- CVE-2021-2932828Monitor
OpenSource Moddable v10.5.0 was discovered to contain buffer over-read in the fxDebugThrow function at /moddable/xs/sources/xsDebug.c.
HighCVSS 7.1No exploitEPSS 1%moddable · moddableNov 19, 2021
- CVE-2021-4633522Monitor
Moddable SDK v11.5.0 was discovered to contain a NULL pointer dereference in the component fx_Function_prototype_hasInstance.
MediumCVSS 5.5No exploitEPSS 1%moddable · moddable sdkJan 20, 2022
- CVE-2021-4633122Monitor
Moddable SDK v11.5.0 was discovered to contain a SEGV vulnerability via xs/sources/xsProxy.c in fxProxyGetPrototype.
MediumCVSS 5.5No exploitEPSS 1%moddable · moddable sdkJan 20, 2022
- CVE-2021-4632722Monitor
Moddable SDK v11.5.0 was discovered to contain a SEGV vulnerability via xs/sources/xsArray.c in fx_Array_prototype_sort.
MediumCVSS 5.5No exploitEPSS 1%moddable · moddable sdkJan 20, 2022
- CVE-2021-4633322Monitor
Moddable SDK v11.5.0 was discovered to contain an invalid memory access vulnerability via the component __asan_memmove.
MediumCVSS 5.5No exploitEPSS 1%moddable · moddable sdkJan 20, 2022
- CVE-2021-4632922Monitor
Moddable SDK v11.5.0 was discovered to contain a SEGV vulnerability via the component _fini.
MediumCVSS 5.5No exploitEPSS 1%moddable · moddable sdkJan 20, 2022
- CVE-2021-4633022Monitor
Moddable SDK v11.5.0 was discovered to contain a SEGV vulnerability via xs/sources/xsDataView.c in fx_ArrayBuffer_prototype_concat.
MediumCVSS 5.5No exploitEPSS 1%moddable · moddable sdkJan 20, 2022
- CVE-2021-2932322Monitor
OpenSource Moddable v10.5.0 was discovered to contain a heap buffer overflow via the component /modules/network/wifi/esp/modwifi.c.
MediumCVSS 5.5No exploitEPSS 1%moddable · moddableNov 19, 2021