Записи mathjs
4 опубликованных записей вендора mathjs.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-915 Improperly Controlled Modification of Dynamically-Determined Object Attributes2
- CWE-1321 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEПрофиль атаки
Все записи
4 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2017-1001002Эксплойта нет | math.js before 3.17.0 had an arbitrary code execution in the JavaScript engine.mathjs · math.js · CWE-94 | Критическая9,8 | — | 2,4 % | 27 нояб. 2017 г. |
35Наблюдать | CVE-2026-41139Эксплойта нет | Unsafe array index getter in mathjsmathjs · mathjs · CWE-915 | Высокая8,8 | — | 0,8 % | 7 мая 2026 г. |
35Наблюдать | CVE-2026-40897Proof of concept | Math.js: Unsafe object property setter in mathjsmathjs · mathjs · CWE-915 | Высокая8,8 | — | 0,8 % | 24 апр. 2026 г. |
30Наблюдать | CVE-2020-7743Эксплойта нет | The package mathjs before 7.5.1 are vulnerable to Prototype Pollution via the deepExtend function that runs upon configuration updates.mathjs · mathjs · CWE-1321 | Высокая7,3 | — | 3,9 % | 13 окт. 2020 г. |
- CVE-2017-100100240В плане
math.js before 3.17.0 had an arbitrary code execution in the JavaScript engine.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %mathjs · math.js27 нояб. 2017 г.
- CVE-2026-4113935Наблюдать
Unsafe array index getter in mathjs
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %mathjs · mathjs7 мая 2026 г.
- CVE-2026-4089735Наблюдать
Math.js: Unsafe object property setter in mathjs
ВысокаяCVSS 8,8Proof of conceptEPSS 1 %mathjs · mathjs24 апр. 2026 г.
- CVE-2020-774330Наблюдать
The package mathjs before 7.5.1 are vulnerable to Prototype Pollution via the deepExtend function that runs upon configuration updates.
ВысокаяCVSS 7,3Эксплойта нетEPSS 4 %mathjs · mathjs13 окт. 2020 г.