QuickJS Project records
14 published records for vendor quickjs project.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 71.4%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-416 Use After Free3
- CWE-125 Out-of-bounds Read2
- CWE-190 Integer Overflow or Wraparound1
- CWE-191 Integer Underflow (Wrap or Wraparound)1
- CWE-400 Uncontrolled Resource Consumption1
- CWE-476 NULL Pointer Dereference1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
14 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2025-62491No exploit | Use-after-free in js_std_promise_rejection_check in QuickJSquickjs project · quickjs · CWE-416 | High8.8 | — | 0.4% | Oct 16, 2025 |
35Monitor | CVE-2025-62490No exploit | Use-after-free in js_print_object in QuickJSquickjs project · quickjs · CWE-416 | High8.8 | — | 0.4% | Oct 16, 2025 |
33Monitor | CVE-2025-46688No exploit | quickjs-ng through 0.9.0 has an incorrect size calculation in JS_ReadBigInt for a BigInt, leading to a heap-based buffer overflow.quickjs-ng · quickjs · CWE-131 | High8.4 | — | 0.3% | Apr 27, 2025 |
30Monitor | CVE-2020-22876No exploit | Buffer Overflow vulnerability in quickjs.c in QuickJS, allows remote attackers to cause denial of service.quickjs project · quickjs · CWE-120 | High7.5 | — | 1.6% | Jul 13, 2021 |
30Monitor | CVE-2023-31922No exploit | QuickJS commit 2788d71 was discovered to contain a stack-overflow via the component js_proxy_isArray at quickjs.c.quickjs project · quickjs · CWE-787 | High7.5 | — | 0.7% | May 12, 2023 |
30Monitor | CVE-2023-48183No exploit | QuickJS before c4cdd61 has a build_for_in_iterator NULL pointer dereference because of an erroneous lexical scope of "this" with eval.quickjs project · quickjs · CWE-476 | High7.5 | — | 0.6% | Apr 23, 2024 |
30Monitor | CVE-2025-69654No exploit | A crafted JavaScript input executed with the QuickJS release 2025-09-13, fixed in commit fcd33c1afa7b3028531f53cd1190a3877454f6b3 (2025-12-1quickjs project · quickjs · CWE-400 | High7.5 | — | 0.3% | Mar 6, 2026 |
28Monitor | CVE-2025-62494No exploit | Type confusion in string addition in QuickJSquickjs project · quickjs · CWE-704 | High7.1 | — | 0.5% | Oct 16, 2025 |
28Monitor | CVE-2025-62496No exploit | Integer overflow in js_bigint_from_string in QuickJSquickjs project · quickjs · CWE-190 | High7.1 | — | 0.5% | Oct 16, 2025 |
28Monitor | CVE-2025-62495No exploit | Type confusion in string addition in QuickJSquickjs project · quickjs · CWE-191 | High7.1 | — | 0.5% | Oct 16, 2025 |
26Monitor | CVE-2025-69653No exploit | A crafted JavaScript input can trigger an internal assertion failure in QuickJS release 2025-09-13, fixed in commit 1dbba8a88eaa40d15a8a9b70quickjs project · quickjs · CWE-617 | Medium6.5 | — | 0.2% | Mar 6, 2026 |
23Monitor | CVE-2025-62492No exploit | Heap out-of-bounds read in js_typed_array_indexOf in QuickJSquickjs project · quickjs · CWE-125 | Medium5.9 | — | 0.4% | Oct 16, 2025 |
23Monitor | CVE-2025-62493No exploit | Heap out-of-bounds read in js_bigint_to_string1 in QuickJSquickjs project · quickjs · CWE-125 | Medium5.9 | — | 0.4% | Oct 16, 2025 |
15Monitor | CVE-2023-48184No exploit | QuickJS before 7414e5f has a quickjs.h JS_FreeValueRT use-after-free because of incorrect garbage collection of async functions with closurequickjs project · quickjs · CWE-416 | Low3.9 | — | 0.3% | Apr 23, 2024 |
- CVE-2025-6249135Monitor
Use-after-free in js_std_promise_rejection_check in QuickJS
HighCVSS 8.8No exploitEPSS 0%quickjs project · quickjsOct 16, 2025
- CVE-2025-6249035Monitor
Use-after-free in js_print_object in QuickJS
HighCVSS 8.8No exploitEPSS 0%quickjs project · quickjsOct 16, 2025
- CVE-2025-4668833Monitor
quickjs-ng through 0.9.0 has an incorrect size calculation in JS_ReadBigInt for a BigInt, leading to a heap-based buffer overflow.
HighCVSS 8.4No exploitEPSS 0%quickjs-ng · quickjsApr 27, 2025
- CVE-2020-2287630Monitor
Buffer Overflow vulnerability in quickjs.c in QuickJS, allows remote attackers to cause denial of service.
HighCVSS 7.5No exploitEPSS 2%quickjs project · quickjsJul 13, 2021
- CVE-2023-3192230Monitor
QuickJS commit 2788d71 was discovered to contain a stack-overflow via the component js_proxy_isArray at quickjs.c.
HighCVSS 7.5No exploitEPSS 1%quickjs project · quickjsMay 12, 2023
- CVE-2023-4818330Monitor
QuickJS before c4cdd61 has a build_for_in_iterator NULL pointer dereference because of an erroneous lexical scope of "this" with eval.
HighCVSS 7.5No exploitEPSS 1%quickjs project · quickjsApr 23, 2024
- CVE-2025-6965430Monitor
A crafted JavaScript input executed with the QuickJS release 2025-09-13, fixed in commit fcd33c1afa7b3028531f53cd1190a3877454f6b3 (2025-12-1
HighCVSS 7.5No exploitEPSS 0%quickjs project · quickjsMar 6, 2026
- CVE-2025-6249428Monitor
Type confusion in string addition in QuickJS
HighCVSS 7.1No exploitEPSS 1%quickjs project · quickjsOct 16, 2025
- CVE-2025-6249628Monitor
Integer overflow in js_bigint_from_string in QuickJS
HighCVSS 7.1No exploitEPSS 0%quickjs project · quickjsOct 16, 2025
- CVE-2025-6249528Monitor
Type confusion in string addition in QuickJS
HighCVSS 7.1No exploitEPSS 0%quickjs project · quickjsOct 16, 2025
- CVE-2025-6965326Monitor
A crafted JavaScript input can trigger an internal assertion failure in QuickJS release 2025-09-13, fixed in commit 1dbba8a88eaa40d15a8a9b70
MediumCVSS 6.5No exploitEPSS 0%quickjs project · quickjsMar 6, 2026
- CVE-2025-6249223Monitor
Heap out-of-bounds read in js_typed_array_indexOf in QuickJS
MediumCVSS 5.9No exploitEPSS 0%quickjs project · quickjsOct 16, 2025
- CVE-2025-6249323Monitor
Heap out-of-bounds read in js_bigint_to_string1 in QuickJS
MediumCVSS 5.9No exploitEPSS 0%quickjs project · quickjsOct 16, 2025
- CVE-2023-4818415Monitor
QuickJS before 7414e5f has a quickjs.h JS_FreeValueRT use-after-free because of incorrect garbage collection of async functions with closure
LowCVSS 3.9No exploitEPSS 0%quickjs project · quickjsApr 23, 2024