Записи QuickJS Project
14 опубликованных записей вендора quickjs project.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 71,4 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-416 Use After Free3
- CWE-125 Out-of-bounds Read2
- CWE-190 Integer Overflow or Wraparound1
- CWE-191 Integer Underflow (Wrap or Wraparound)1
- CWE-400 Uncontrolled Resource Consumption1
- CWE-476 NULL Pointer Dereference1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
14 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
35Наблюдать | CVE-2025-62491Эксплойта нет | Use-after-free in js_std_promise_rejection_check in QuickJSquickjs project · quickjs · CWE-416 | Высокая8,8 | — | 0,4 % | 16 окт. 2025 г. |
35Наблюдать | CVE-2025-62490Эксплойта нет | Use-after-free in js_print_object in QuickJSquickjs project · quickjs · CWE-416 | Высокая8,8 | — | 0,4 % | 16 окт. 2025 г. |
33Наблюдать | CVE-2025-46688Эксплойта нет | quickjs-ng through 0.9.0 has an incorrect size calculation in JS_ReadBigInt for a BigInt, leading to a heap-based buffer overflow.quickjs-ng · quickjs · CWE-131 | Высокая8,4 | — | 0,3 % | 27 апр. 2025 г. |
30Наблюдать | CVE-2020-22876Эксплойта нет | Buffer Overflow vulnerability in quickjs.c in QuickJS, allows remote attackers to cause denial of service.quickjs project · quickjs · CWE-120 | Высокая7,5 | — | 1,6 % | 13 июл. 2021 г. |
30Наблюдать | CVE-2023-31922Эксплойта нет | QuickJS commit 2788d71 was discovered to contain a stack-overflow via the component js_proxy_isArray at quickjs.c.quickjs project · quickjs · CWE-787 | Высокая7,5 | — | 0,7 % | 12 мая 2023 г. |
30Наблюдать | CVE-2023-48183Эксплойта нет | QuickJS before c4cdd61 has a build_for_in_iterator NULL pointer dereference because of an erroneous lexical scope of "this" with eval.quickjs project · quickjs · CWE-476 | Высокая7,5 | — | 0,6 % | 23 апр. 2024 г. |
30Наблюдать | CVE-2025-69654Эксплойта нет | A crafted JavaScript input executed with the QuickJS release 2025-09-13, fixed in commit fcd33c1afa7b3028531f53cd1190a3877454f6b3 (2025-12-1quickjs project · quickjs · CWE-400 | Высокая7,5 | — | 0,3 % | 6 мар. 2026 г. |
28Наблюдать | CVE-2025-62494Эксплойта нет | Type confusion in string addition in QuickJSquickjs project · quickjs · CWE-704 | Высокая7,1 | — | 0,5 % | 16 окт. 2025 г. |
28Наблюдать | CVE-2025-62496Эксплойта нет | Integer overflow in js_bigint_from_string in QuickJSquickjs project · quickjs · CWE-190 | Высокая7,1 | — | 0,5 % | 16 окт. 2025 г. |
28Наблюдать | CVE-2025-62495Эксплойта нет | Type confusion in string addition in QuickJSquickjs project · quickjs · CWE-191 | Высокая7,1 | — | 0,5 % | 16 окт. 2025 г. |
26Наблюдать | CVE-2025-69653Эксплойта нет | A crafted JavaScript input can trigger an internal assertion failure in QuickJS release 2025-09-13, fixed in commit 1dbba8a88eaa40d15a8a9b70quickjs project · quickjs · CWE-617 | Средняя6,5 | — | 0,2 % | 6 мар. 2026 г. |
23Наблюдать | CVE-2025-62492Эксплойта нет | Heap out-of-bounds read in js_typed_array_indexOf in QuickJSquickjs project · quickjs · CWE-125 | Средняя5,9 | — | 0,4 % | 16 окт. 2025 г. |
23Наблюдать | CVE-2025-62493Эксплойта нет | Heap out-of-bounds read in js_bigint_to_string1 in QuickJSquickjs project · quickjs · CWE-125 | Средняя5,9 | — | 0,4 % | 16 окт. 2025 г. |
15Наблюдать | CVE-2023-48184Эксплойта нет | QuickJS before 7414e5f has a quickjs.h JS_FreeValueRT use-after-free because of incorrect garbage collection of async functions with closurequickjs project · quickjs · CWE-416 | Низкая3,9 | — | 0,3 % | 23 апр. 2024 г. |
- CVE-2025-6249135Наблюдать
Use-after-free in js_std_promise_rejection_check in QuickJS
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %quickjs project · quickjs16 окт. 2025 г.
- CVE-2025-6249035Наблюдать
Use-after-free in js_print_object in QuickJS
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %quickjs project · quickjs16 окт. 2025 г.
- CVE-2025-4668833Наблюдать
quickjs-ng through 0.9.0 has an incorrect size calculation in JS_ReadBigInt for a BigInt, leading to a heap-based buffer overflow.
ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %quickjs-ng · quickjs27 апр. 2025 г.
- CVE-2020-2287630Наблюдать
Buffer Overflow vulnerability in quickjs.c in QuickJS, allows remote attackers to cause denial of service.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %quickjs project · quickjs13 июл. 2021 г.
- CVE-2023-3192230Наблюдать
QuickJS commit 2788d71 was discovered to contain a stack-overflow via the component js_proxy_isArray at quickjs.c.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %quickjs project · quickjs12 мая 2023 г.
- CVE-2023-4818330Наблюдать
QuickJS before c4cdd61 has a build_for_in_iterator NULL pointer dereference because of an erroneous lexical scope of "this" with eval.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %quickjs project · quickjs23 апр. 2024 г.
- CVE-2025-6965430Наблюдать
A crafted JavaScript input executed with the QuickJS release 2025-09-13, fixed in commit fcd33c1afa7b3028531f53cd1190a3877454f6b3 (2025-12-1
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %quickjs project · quickjs6 мар. 2026 г.
- CVE-2025-6249428Наблюдать
Type confusion in string addition in QuickJS
ВысокаяCVSS 7,1Эксплойта нетEPSS 1 %quickjs project · quickjs16 окт. 2025 г.
- CVE-2025-6249628Наблюдать
Integer overflow in js_bigint_from_string in QuickJS
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %quickjs project · quickjs16 окт. 2025 г.
- CVE-2025-6249528Наблюдать
Type confusion in string addition in QuickJS
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %quickjs project · quickjs16 окт. 2025 г.
- CVE-2025-6965326Наблюдать
A crafted JavaScript input can trigger an internal assertion failure in QuickJS release 2025-09-13, fixed in commit 1dbba8a88eaa40d15a8a9b70
СредняяCVSS 6,5Эксплойта нетEPSS 0 %quickjs project · quickjs6 мар. 2026 г.
- CVE-2025-6249223Наблюдать
Heap out-of-bounds read in js_typed_array_indexOf in QuickJS
СредняяCVSS 5,9Эксплойта нетEPSS 0 %quickjs project · quickjs16 окт. 2025 г.
- CVE-2025-6249323Наблюдать
Heap out-of-bounds read in js_bigint_to_string1 in QuickJS
СредняяCVSS 5,9Эксплойта нетEPSS 0 %quickjs project · quickjs16 окт. 2025 г.
- CVE-2023-4818415Наблюдать
QuickJS before 7414e5f has a quickjs.h JS_FreeValueRT use-after-free because of incorrect garbage collection of async functions with closure
НизкаяCVSS 3,9Эксплойта нетEPSS 0 %quickjs project · quickjs23 апр. 2024 г.