Записи Cesanta
145 опубликованных записей вендора cesanta.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 13
- С записью об исправлении
- 26,9 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-787 Out-of-bounds Write18
- CWE-674 Uncontrolled Recursion12
- CWE-476 NULL Pointer Dereference12
- CWE-416 Use After Free9
- CWE-125 Out-of-bounds Read8
- CWE-823 Use of Out-of-range Pointer Offset7
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
145 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
51В плане | CVE-2019-19307Эксплойта нет | An integer overflow in parse_mqtt in mongoose.c in Cesanta Mongoose 6.16 allows an attacker to achieve remote DoS (infinite loop), or possibcesanta · mongoose · CWE-125 | Критическая9,8 | — | 41,6 % | 26 нояб. 2019 г. |
48В плане | CVE-2017-2894Эксплойта нет | An exploitable stack buffer overflow vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8.cesanta · mongoose · CWE-787 | Критическая9,8 | — | 31,0 % | 7 нояб. 2017 г. |
40В плане | CVE-2018-20353Эксплойта нет | An invalid read of 8 bytes due to a use-after-free vulnerability during a "NULL test" in the mg_http_get_proto_data function in mongoose.c icesanta · mongoose · CWE-416 | Критическая9,8 | — | 3,6 % | 10 июн. 2019 г. |
40В плане | CVE-2018-20355Эксплойта нет | An invalid write of 8 bytes due to a use-after-free vulnerability in the mg_http_free_proto_data_cgi function call in mongoose.c in Cesanta cesanta · mongoose · CWE-416 | Критическая9,8 | — | 3,6 % | 10 июн. 2019 г. |
40В плане | CVE-2018-20356Эксплойта нет | An invalid read of 8 bytes due to a use-after-free vulnerability in the mg_http_free_proto_data_cgi function call in mongoose.c in Cesanta Mcesanta · mongoose · CWE-416 | Критическая9,8 | — | 3,6 % | 10 июн. 2019 г. |
40В плане | CVE-2018-20354Эксплойта нет | An invalid read of 8 bytes due to a use-after-free vulnerability during a "return" in the mg_http_get_proto_data function in mongoose.c in Ccesanta · mongoose · CWE-416 | Критическая9,8 | — | 3,6 % | 10 июн. 2019 г. |
40В плане | CVE-2017-2892Эксплойта нет | An exploitable arbitrary memory read vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8.cesanta · mongoose · CWE-190 | Критическая9,8 | — | 3,0 % | 7 нояб. 2017 г. |
40В плане | CVE-2017-2891Эксплойта нет | An exploitable use-after-free vulnerability exists in the HTTP server implementation of Cesanta Mongoose 6.8.cesanta · mongoose · CWE-416 | Критическая9,8 | — | 2,8 % | 7 нояб. 2017 г. |
40В плане | CVE-2017-2922Эксплойта нет | An exploitable memory corruption vulnerability exists in the Websocket protocol implementation of Cesanta Mongoose 6.8.cesanta · mongoose · CWE-416 | Критическая9,8 | — | 2,6 % | 7 нояб. 2017 г. |
40В плане | CVE-2017-2921Эксплойта нет | An exploitable memory corruption vulnerability exists in the Websocket protocol implementation of Cesanta Mongoose 6.8.cesanta · mongoose · CWE-190 | Критическая9,8 | — | 2,4 % | 7 нояб. 2017 г. |
40В плане | CVE-2021-31875Эксплойта нет | In mjs_json.c in Cesanta MongooseOS mJS 1.26, a maliciously formed JSON string can trigger an off-by-one heap-based buffer overflow in mjs_jcesanta · mongooseos mjs · CWE-193 | Критическая9,8 | — | 2,2 % | 28 апр. 2021 г. |
40В плане | CVE-2019-12951Эксплойта нет | An issue was discovered in Mongoose before 6.15.cesanta · mongoose · CWE-787 | Критическая9,8 | — | 2,0 % | 24 июн. 2019 г. |
40В плане | CVE-2021-27425Эксплойта нет | Cesanta Software Mongoose-OS Integer Overflow or Wraparoundcesanta · mongoose os · CWE-190 | Критическая9,8 | — | 1,7 % | 3 мая 2022 г. |
39Наблюдать | CVE-2020-25756Эксплойта нет | A buffer overflow vulnerability exists in the mg_get_http_header function in Cesanta Mongoose 6.18 due to a lack of bounds checking.cesanta · mongoose · CWE-120 | Критическая9,8 | — | 1,6 % | 18 сент. 2020 г. |
39Наблюдать | CVE-2023-43338Эксплойта нет | Cesanta mjs v2.20.0 was discovered to contain a function pointer hijacking vulnerability via the function mjs_get_ptr().cesanta · mjs · CWE-787 | Критическая9,8 | — | 1,0 % | 22 сент. 2023 г. |
39Наблюдать | CVE-2023-50044Эксплойта нет | Cesanta MJS 2.20.0 has a getprop_builtin_foreign out-of-bounds read if a Built-in API name occurs in a substring of an input string.cesanta · mjs · CWE-120 | Критическая9,8 | — | 0,9 % | 20 дек. 2023 г. |
39Наблюдать | CVE-2024-42383Эксплойта нет | Use of Out-of-range Pointer Offset in Mongoose Web Server librarycesanta · mongoose · CWE-823 | Критическая9,8 | — | 0,3 % | 18 нояб. 2024 г. |
37Наблюдать | CVE-2017-2893Эксплойта нет | An exploitable NULL pointer dereference vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8.cesanta · mongoose · CWE-476 | Высокая7,5 | — | 24,9 % | 7 нояб. 2017 г. |
37Наблюдать | CVE-2018-18765Эксплойта нет | An exploitable arbitrary memory read vulnerability exists in the MQTT packet-parsing functionality of Cesanta Mongoose 6.13.cesanta · mongoose · CWE-125 | Критическая9,1 | — | 1,8 % | 29 окт. 2018 г. |
37Наблюдать | CVE-2018-18764Эксплойта нет | An exploitable arbitrary memory read vulnerability exists in the MQTT packet-parsing functionality of Cesanta Mongoose 6.13.cesanta · mongoose · CWE-125 | Критическая9,1 | — | 1,8 % | 29 окт. 2018 г. |
37Наблюдать | CVE-2026-73251Эксплойта нет | Mongoose Built-in TLS: CA-bundle certificate chain accepted without any signature verificationcesanta · mongoose · CWE-295 | Критическая9,3 | — | 0,3 % | 20 авг. 2026 г. |
36Наблюдать | CVE-2017-11567Proof of concept | Cross-site request forgery (CSRF) vulnerability in Mongoose Web Server before 6.9 allows remote attackers to hijack the authentication of uscesanta · mongoose embedded web server library · CWE-352 | Высокая8,8 | — | 4,1 % | 7 сент. 2017 г. |
36Наблюдать | CVE-2018-20352Эксплойта нет | Use-after-free vulnerability in the mg_cgi_ev_handler function in mongoose.c in Cesanta Mongoose Embedded Web Server Library 6.13 and earliecesanta · mongoose embedded web server library · CWE-416 | Высокая8,8 | — | 2,7 % | 10 июн. 2019 г. |
36Наблюдать | CVE-2021-26529Эксплойта нет | The mg_tls_init function in Cesanta Mongoose HTTPS server 7.0 and 6.7-6.18 (compiled with mbedTLS support) is vulnerable to remote OOB writecesanta · mongoose · CWE-787 | Критическая9,1 | — | 1,5 % | 8 февр. 2021 г. |
36Наблюдать | CVE-2021-26528Эксплойта нет | The mg_http_serve_file function in Cesanta Mongoose HTTP server 7.0 is vulnerable to remote OOB write attack via connection request after excesanta · mongoose · CWE-787 | Критическая9,1 | — | 1,5 % | 8 февр. 2021 г. |
- CVE-2019-1930751В плане
An integer overflow in parse_mqtt in mongoose.c in Cesanta Mongoose 6.16 allows an attacker to achieve remote DoS (infinite loop), or possib
КритическаяCVSS 9,8Эксплойта нетEPSS 42 %cesanta · mongoose26 нояб. 2019 г.
- CVE-2017-289448В плане
An exploitable stack buffer overflow vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8.
КритическаяCVSS 9,8Эксплойта нетEPSS 31 %cesanta · mongoose7 нояб. 2017 г.
- CVE-2018-2035340В плане
An invalid read of 8 bytes due to a use-after-free vulnerability during a "NULL test" in the mg_http_get_proto_data function in mongoose.c i
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %cesanta · mongoose10 июн. 2019 г.
- CVE-2018-2035540В плане
An invalid write of 8 bytes due to a use-after-free vulnerability in the mg_http_free_proto_data_cgi function call in mongoose.c in Cesanta
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %cesanta · mongoose10 июн. 2019 г.
- CVE-2018-2035640В плане
An invalid read of 8 bytes due to a use-after-free vulnerability in the mg_http_free_proto_data_cgi function call in mongoose.c in Cesanta M
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %cesanta · mongoose10 июн. 2019 г.
- CVE-2018-2035440В плане
An invalid read of 8 bytes due to a use-after-free vulnerability during a "return" in the mg_http_get_proto_data function in mongoose.c in C
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %cesanta · mongoose10 июн. 2019 г.
- CVE-2017-289240В плане
An exploitable arbitrary memory read vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %cesanta · mongoose7 нояб. 2017 г.
- CVE-2017-289140В плане
An exploitable use-after-free vulnerability exists in the HTTP server implementation of Cesanta Mongoose 6.8.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %cesanta · mongoose7 нояб. 2017 г.
- CVE-2017-292240В плане
An exploitable memory corruption vulnerability exists in the Websocket protocol implementation of Cesanta Mongoose 6.8.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %cesanta · mongoose7 нояб. 2017 г.
- CVE-2017-292140В плане
An exploitable memory corruption vulnerability exists in the Websocket protocol implementation of Cesanta Mongoose 6.8.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %cesanta · mongoose7 нояб. 2017 г.
- CVE-2021-3187540В плане
In mjs_json.c in Cesanta MongooseOS mJS 1.26, a maliciously formed JSON string can trigger an off-by-one heap-based buffer overflow in mjs_j
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %cesanta · mongooseos mjs28 апр. 2021 г.
- CVE-2019-1295140В плане
An issue was discovered in Mongoose before 6.15.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %cesanta · mongoose24 июн. 2019 г.
- CVE-2021-2742540В плане
Cesanta Software Mongoose-OS Integer Overflow or Wraparound
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %cesanta · mongoose os3 мая 2022 г.
- CVE-2020-2575639Наблюдать
A buffer overflow vulnerability exists in the mg_get_http_header function in Cesanta Mongoose 6.18 due to a lack of bounds checking.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %cesanta · mongoose18 сент. 2020 г.
- CVE-2023-4333839Наблюдать
Cesanta mjs v2.20.0 was discovered to contain a function pointer hijacking vulnerability via the function mjs_get_ptr().
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %cesanta · mjs22 сент. 2023 г.
- CVE-2023-5004439Наблюдать
Cesanta MJS 2.20.0 has a getprop_builtin_foreign out-of-bounds read if a Built-in API name occurs in a substring of an input string.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %cesanta · mjs20 дек. 2023 г.
- CVE-2024-4238339Наблюдать
Use of Out-of-range Pointer Offset in Mongoose Web Server library
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %cesanta · mongoose18 нояб. 2024 г.
- CVE-2017-289337Наблюдать
An exploitable NULL pointer dereference vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8.
ВысокаяCVSS 7,5Эксплойта нетEPSS 25 %cesanta · mongoose7 нояб. 2017 г.
- CVE-2018-1876537Наблюдать
An exploitable arbitrary memory read vulnerability exists in the MQTT packet-parsing functionality of Cesanta Mongoose 6.13.
КритическаяCVSS 9,1Эксплойта нетEPSS 2 %cesanta · mongoose29 окт. 2018 г.
- CVE-2018-1876437Наблюдать
An exploitable arbitrary memory read vulnerability exists in the MQTT packet-parsing functionality of Cesanta Mongoose 6.13.
КритическаяCVSS 9,1Эксплойта нетEPSS 2 %cesanta · mongoose29 окт. 2018 г.
- CVE-2026-7325137Наблюдать
Mongoose Built-in TLS: CA-bundle certificate chain accepted without any signature verification
КритическаяCVSS 9,3Эксплойта нетEPSS 0 %cesanta · mongoose20 авг. 2026 г.
- CVE-2017-1156736Наблюдать
Cross-site request forgery (CSRF) vulnerability in Mongoose Web Server before 6.9 allows remote attackers to hijack the authentication of us
ВысокаяCVSS 8,8Proof of conceptEPSS 4 %cesanta · mongoose embedded web server library7 сент. 2017 г.
- CVE-2018-2035236Наблюдать
Use-after-free vulnerability in the mg_cgi_ev_handler function in mongoose.c in Cesanta Mongoose Embedded Web Server Library 6.13 and earlie
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %cesanta · mongoose embedded web server library10 июн. 2019 г.
- CVE-2021-2652936Наблюдать
The mg_tls_init function in Cesanta Mongoose HTTPS server 7.0 and 6.7-6.18 (compiled with mbedTLS support) is vulnerable to remote OOB write
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %cesanta · mongoose8 февр. 2021 г.
- CVE-2021-2652836Наблюдать
The mg_http_serve_file function in Cesanta Mongoose HTTP server 7.0 is vulnerable to remote OOB write attack via connection request after ex
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %cesanta · mongoose8 февр. 2021 г.