Cesanta kayıtları
cesanta üreticisine ait 145 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 13
- Düzeltme kaydı olan
- %26,9
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-787 Out-of-bounds Write18
- CWE-674 Uncontrolled Recursion12
- CWE-476 NULL Pointer Dereference12
- CWE-416 Use After Free9
- CWE-125 Out-of-bounds Read8
- CWE-823 Use of Out-of-range Pointer Offset7
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
145 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
51Planlayın | CVE-2019-19307İstismar yok | An integer overflow in parse_mqtt in mongoose.c in Cesanta Mongoose 6.16 allows an attacker to achieve remote DoS (infinite loop), or possibcesanta · mongoose · CWE-125 | Kritik9,8 | — | %41,6 | 26 Kas 2019 |
48Planlayın | CVE-2017-2894İstismar yok | An exploitable stack buffer overflow vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8.cesanta · mongoose · CWE-787 | Kritik9,8 | — | %31,0 | 7 Kas 2017 |
40Planlayın | CVE-2018-20353İstismar yok | An invalid read of 8 bytes due to a use-after-free vulnerability during a "NULL test" in the mg_http_get_proto_data function in mongoose.c icesanta · mongoose · CWE-416 | Kritik9,8 | — | %3,6 | 10 Haz 2019 |
40Planlayın | CVE-2018-20355İstismar yok | An invalid write of 8 bytes due to a use-after-free vulnerability in the mg_http_free_proto_data_cgi function call in mongoose.c in Cesanta cesanta · mongoose · CWE-416 | Kritik9,8 | — | %3,6 | 10 Haz 2019 |
40Planlayın | CVE-2018-20356İstismar yok | An invalid read of 8 bytes due to a use-after-free vulnerability in the mg_http_free_proto_data_cgi function call in mongoose.c in Cesanta Mcesanta · mongoose · CWE-416 | Kritik9,8 | — | %3,6 | 10 Haz 2019 |
40Planlayın | CVE-2018-20354İstismar yok | An invalid read of 8 bytes due to a use-after-free vulnerability during a "return" in the mg_http_get_proto_data function in mongoose.c in Ccesanta · mongoose · CWE-416 | Kritik9,8 | — | %3,6 | 10 Haz 2019 |
40Planlayın | CVE-2017-2892İstismar yok | An exploitable arbitrary memory read vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8.cesanta · mongoose · CWE-190 | Kritik9,8 | — | %3,0 | 7 Kas 2017 |
40Planlayın | CVE-2017-2891İstismar yok | An exploitable use-after-free vulnerability exists in the HTTP server implementation of Cesanta Mongoose 6.8.cesanta · mongoose · CWE-416 | Kritik9,8 | — | %2,8 | 7 Kas 2017 |
40Planlayın | CVE-2017-2922İstismar yok | An exploitable memory corruption vulnerability exists in the Websocket protocol implementation of Cesanta Mongoose 6.8.cesanta · mongoose · CWE-416 | Kritik9,8 | — | %2,6 | 7 Kas 2017 |
40Planlayın | CVE-2017-2921İstismar yok | An exploitable memory corruption vulnerability exists in the Websocket protocol implementation of Cesanta Mongoose 6.8.cesanta · mongoose · CWE-190 | Kritik9,8 | — | %2,4 | 7 Kas 2017 |
40Planlayın | CVE-2021-31875İstismar yok | In mjs_json.c in Cesanta MongooseOS mJS 1.26, a maliciously formed JSON string can trigger an off-by-one heap-based buffer overflow in mjs_jcesanta · mongooseos mjs · CWE-193 | Kritik9,8 | — | %2,2 | 28 Nis 2021 |
40Planlayın | CVE-2019-12951İstismar yok | An issue was discovered in Mongoose before 6.15.cesanta · mongoose · CWE-787 | Kritik9,8 | — | %2,0 | 24 Haz 2019 |
40Planlayın | CVE-2021-27425İstismar yok | Cesanta Software Mongoose-OS Integer Overflow or Wraparoundcesanta · mongoose os · CWE-190 | Kritik9,8 | — | %1,7 | 3 May 2022 |
39İzleyin | CVE-2020-25756İstismar yok | A buffer overflow vulnerability exists in the mg_get_http_header function in Cesanta Mongoose 6.18 due to a lack of bounds checking.cesanta · mongoose · CWE-120 | Kritik9,8 | — | %1,6 | 18 Eyl 2020 |
39İzleyin | CVE-2023-43338İstismar yok | Cesanta mjs v2.20.0 was discovered to contain a function pointer hijacking vulnerability via the function mjs_get_ptr().cesanta · mjs · CWE-787 | Kritik9,8 | — | %1,0 | 22 Eyl 2023 |
39İzleyin | CVE-2023-50044İstismar yok | Cesanta MJS 2.20.0 has a getprop_builtin_foreign out-of-bounds read if a Built-in API name occurs in a substring of an input string.cesanta · mjs · CWE-120 | Kritik9,8 | — | %0,9 | 20 Ara 2023 |
39İzleyin | CVE-2024-42383İstismar yok | Use of Out-of-range Pointer Offset in Mongoose Web Server librarycesanta · mongoose · CWE-823 | Kritik9,8 | — | %0,3 | 18 Kas 2024 |
37İzleyin | CVE-2017-2893İstismar yok | An exploitable NULL pointer dereference vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8.cesanta · mongoose · CWE-476 | Yüksek7,5 | — | %24,9 | 7 Kas 2017 |
37İzleyin | CVE-2018-18765İstismar yok | An exploitable arbitrary memory read vulnerability exists in the MQTT packet-parsing functionality of Cesanta Mongoose 6.13.cesanta · mongoose · CWE-125 | Kritik9,1 | — | %1,8 | 29 Eki 2018 |
37İzleyin | CVE-2018-18764İstismar yok | An exploitable arbitrary memory read vulnerability exists in the MQTT packet-parsing functionality of Cesanta Mongoose 6.13.cesanta · mongoose · CWE-125 | Kritik9,1 | — | %1,8 | 29 Eki 2018 |
37İzleyin | CVE-2026-73251İstismar yok | Mongoose Built-in TLS: CA-bundle certificate chain accepted without any signature verificationcesanta · mongoose · CWE-295 | Kritik9,3 | — | %0,3 | 20 Ağu 2026 |
36İzleyin | CVE-2017-11567Kavram kanıtı | Cross-site request forgery (CSRF) vulnerability in Mongoose Web Server before 6.9 allows remote attackers to hijack the authentication of uscesanta · mongoose embedded web server library · CWE-352 | Yüksek8,8 | — | %4,1 | 7 Eyl 2017 |
36İzleyin | CVE-2018-20352İstismar yok | Use-after-free vulnerability in the mg_cgi_ev_handler function in mongoose.c in Cesanta Mongoose Embedded Web Server Library 6.13 and earliecesanta · mongoose embedded web server library · CWE-416 | Yüksek8,8 | — | %2,7 | 10 Haz 2019 |
36İzleyin | CVE-2021-26529İstismar yok | The mg_tls_init function in Cesanta Mongoose HTTPS server 7.0 and 6.7-6.18 (compiled with mbedTLS support) is vulnerable to remote OOB writecesanta · mongoose · CWE-787 | Kritik9,1 | — | %1,5 | 8 Şub 2021 |
36İzleyin | CVE-2021-26528İstismar yok | The mg_http_serve_file function in Cesanta Mongoose HTTP server 7.0 is vulnerable to remote OOB write attack via connection request after excesanta · mongoose · CWE-787 | Kritik9,1 | — | %1,5 | 8 Şub 2021 |
- CVE-2019-1930751Planlayın
An integer overflow in parse_mqtt in mongoose.c in Cesanta Mongoose 6.16 allows an attacker to achieve remote DoS (infinite loop), or possib
KritikCVSS 9,8İstismar yokEPSS %42cesanta · mongoose26 Kas 2019
- CVE-2017-289448Planlayın
An exploitable stack buffer overflow vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8.
KritikCVSS 9,8İstismar yokEPSS %31cesanta · mongoose7 Kas 2017
- CVE-2018-2035340Planlayın
An invalid read of 8 bytes due to a use-after-free vulnerability during a "NULL test" in the mg_http_get_proto_data function in mongoose.c i
KritikCVSS 9,8İstismar yokEPSS %4cesanta · mongoose10 Haz 2019
- CVE-2018-2035540Planlayın
An invalid write of 8 bytes due to a use-after-free vulnerability in the mg_http_free_proto_data_cgi function call in mongoose.c in Cesanta
KritikCVSS 9,8İstismar yokEPSS %4cesanta · mongoose10 Haz 2019
- CVE-2018-2035640Planlayın
An invalid read of 8 bytes due to a use-after-free vulnerability in the mg_http_free_proto_data_cgi function call in mongoose.c in Cesanta M
KritikCVSS 9,8İstismar yokEPSS %4cesanta · mongoose10 Haz 2019
- CVE-2018-2035440Planlayın
An invalid read of 8 bytes due to a use-after-free vulnerability during a "return" in the mg_http_get_proto_data function in mongoose.c in C
KritikCVSS 9,8İstismar yokEPSS %4cesanta · mongoose10 Haz 2019
- CVE-2017-289240Planlayın
An exploitable arbitrary memory read vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8.
KritikCVSS 9,8İstismar yokEPSS %3cesanta · mongoose7 Kas 2017
- CVE-2017-289140Planlayın
An exploitable use-after-free vulnerability exists in the HTTP server implementation of Cesanta Mongoose 6.8.
KritikCVSS 9,8İstismar yokEPSS %3cesanta · mongoose7 Kas 2017
- CVE-2017-292240Planlayın
An exploitable memory corruption vulnerability exists in the Websocket protocol implementation of Cesanta Mongoose 6.8.
KritikCVSS 9,8İstismar yokEPSS %3cesanta · mongoose7 Kas 2017
- CVE-2017-292140Planlayın
An exploitable memory corruption vulnerability exists in the Websocket protocol implementation of Cesanta Mongoose 6.8.
KritikCVSS 9,8İstismar yokEPSS %2cesanta · mongoose7 Kas 2017
- CVE-2021-3187540Planlayın
In mjs_json.c in Cesanta MongooseOS mJS 1.26, a maliciously formed JSON string can trigger an off-by-one heap-based buffer overflow in mjs_j
KritikCVSS 9,8İstismar yokEPSS %2cesanta · mongooseos mjs28 Nis 2021
- CVE-2019-1295140Planlayın
An issue was discovered in Mongoose before 6.15.
KritikCVSS 9,8İstismar yokEPSS %2cesanta · mongoose24 Haz 2019
- CVE-2021-2742540Planlayın
Cesanta Software Mongoose-OS Integer Overflow or Wraparound
KritikCVSS 9,8İstismar yokEPSS %2cesanta · mongoose os3 May 2022
- CVE-2020-2575639İzleyin
A buffer overflow vulnerability exists in the mg_get_http_header function in Cesanta Mongoose 6.18 due to a lack of bounds checking.
KritikCVSS 9,8İstismar yokEPSS %2cesanta · mongoose18 Eyl 2020
- CVE-2023-4333839İzleyin
Cesanta mjs v2.20.0 was discovered to contain a function pointer hijacking vulnerability via the function mjs_get_ptr().
KritikCVSS 9,8İstismar yokEPSS %1cesanta · mjs22 Eyl 2023
- CVE-2023-5004439İzleyin
Cesanta MJS 2.20.0 has a getprop_builtin_foreign out-of-bounds read if a Built-in API name occurs in a substring of an input string.
KritikCVSS 9,8İstismar yokEPSS %1cesanta · mjs20 Ara 2023
- CVE-2024-4238339İzleyin
Use of Out-of-range Pointer Offset in Mongoose Web Server library
KritikCVSS 9,8İstismar yokEPSS %0cesanta · mongoose18 Kas 2024
- CVE-2017-289337İzleyin
An exploitable NULL pointer dereference vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8.
YüksekCVSS 7,5İstismar yokEPSS %25cesanta · mongoose7 Kas 2017
- CVE-2018-1876537İzleyin
An exploitable arbitrary memory read vulnerability exists in the MQTT packet-parsing functionality of Cesanta Mongoose 6.13.
KritikCVSS 9,1İstismar yokEPSS %2cesanta · mongoose29 Eki 2018
- CVE-2018-1876437İzleyin
An exploitable arbitrary memory read vulnerability exists in the MQTT packet-parsing functionality of Cesanta Mongoose 6.13.
KritikCVSS 9,1İstismar yokEPSS %2cesanta · mongoose29 Eki 2018
- CVE-2026-7325137İzleyin
Mongoose Built-in TLS: CA-bundle certificate chain accepted without any signature verification
KritikCVSS 9,3İstismar yokEPSS %0cesanta · mongoose20 Ağu 2026
- CVE-2017-1156736İzleyin
Cross-site request forgery (CSRF) vulnerability in Mongoose Web Server before 6.9 allows remote attackers to hijack the authentication of us
YüksekCVSS 8,8Kavram kanıtıEPSS %4cesanta · mongoose embedded web server library7 Eyl 2017
- CVE-2018-2035236İzleyin
Use-after-free vulnerability in the mg_cgi_ev_handler function in mongoose.c in Cesanta Mongoose Embedded Web Server Library 6.13 and earlie
YüksekCVSS 8,8İstismar yokEPSS %3cesanta · mongoose embedded web server library10 Haz 2019
- CVE-2021-2652936İzleyin
The mg_tls_init function in Cesanta Mongoose HTTPS server 7.0 and 6.7-6.18 (compiled with mbedTLS support) is vulnerable to remote OOB write
KritikCVSS 9,1İstismar yokEPSS %1cesanta · mongoose8 Şub 2021
- CVE-2021-2652836İzleyin
The mg_http_serve_file function in Cesanta Mongoose HTTP server 7.0 is vulnerable to remote OOB write attack via connection request after ex
KritikCVSS 9,1İstismar yokEPSS %1cesanta · mongoose8 Şub 2021