İçeriğe atla
Noroxi

Cesanta kayıtları

cesanta üreticisine ait 145 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
13
Düzeltme kaydı olan
%26,9
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

145 kayıt
  • CVE-2019-19307
    51Planlayın

    An integer overflow in parse_mqtt in mongoose.c in Cesanta Mongoose 6.16 allows an attacker to achieve remote DoS (infinite loop), or possib

    KritikCVSS 9,8İstismar yokEPSS %42

    cesanta · mongoose26 Kas 2019

  • CVE-2017-2894
    48Planlayın

    An exploitable stack buffer overflow vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8.

    KritikCVSS 9,8İstismar yokEPSS %31

    cesanta · mongoose7 Kas 2017

  • CVE-2018-20353
    40Planlayın

    An invalid read of 8 bytes due to a use-after-free vulnerability during a "NULL test" in the mg_http_get_proto_data function in mongoose.c i

    KritikCVSS 9,8İstismar yokEPSS %4

    cesanta · mongoose10 Haz 2019

  • CVE-2018-20355
    40Planlayın

    An invalid write of 8 bytes due to a use-after-free vulnerability in the mg_http_free_proto_data_cgi function call in mongoose.c in Cesanta

    KritikCVSS 9,8İstismar yokEPSS %4

    cesanta · mongoose10 Haz 2019

  • CVE-2018-20356
    40Planlayın

    An invalid read of 8 bytes due to a use-after-free vulnerability in the mg_http_free_proto_data_cgi function call in mongoose.c in Cesanta M

    KritikCVSS 9,8İstismar yokEPSS %4

    cesanta · mongoose10 Haz 2019

  • CVE-2018-20354
    40Planlayın

    An invalid read of 8 bytes due to a use-after-free vulnerability during a "return" in the mg_http_get_proto_data function in mongoose.c in C

    KritikCVSS 9,8İstismar yokEPSS %4

    cesanta · mongoose10 Haz 2019

  • CVE-2017-2892
    40Planlayın

    An exploitable arbitrary memory read vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8.

    KritikCVSS 9,8İstismar yokEPSS %3

    cesanta · mongoose7 Kas 2017

  • CVE-2017-2891
    40Planlayın

    An exploitable use-after-free vulnerability exists in the HTTP server implementation of Cesanta Mongoose 6.8.

    KritikCVSS 9,8İstismar yokEPSS %3

    cesanta · mongoose7 Kas 2017

  • CVE-2017-2922
    40Planlayın

    An exploitable memory corruption vulnerability exists in the Websocket protocol implementation of Cesanta Mongoose 6.8.

    KritikCVSS 9,8İstismar yokEPSS %3

    cesanta · mongoose7 Kas 2017

  • CVE-2017-2921
    40Planlayın

    An exploitable memory corruption vulnerability exists in the Websocket protocol implementation of Cesanta Mongoose 6.8.

    KritikCVSS 9,8İstismar yokEPSS %2

    cesanta · mongoose7 Kas 2017

  • CVE-2021-31875
    40Planlayın

    In mjs_json.c in Cesanta MongooseOS mJS 1.26, a maliciously formed JSON string can trigger an off-by-one heap-based buffer overflow in mjs_j

    KritikCVSS 9,8İstismar yokEPSS %2

    cesanta · mongooseos mjs28 Nis 2021

  • CVE-2019-12951
    40Planlayın

    An issue was discovered in Mongoose before 6.15.

    KritikCVSS 9,8İstismar yokEPSS %2

    cesanta · mongoose24 Haz 2019

  • CVE-2021-27425
    40Planlayın

    Cesanta Software Mongoose-OS Integer Overflow or Wraparound

    KritikCVSS 9,8İstismar yokEPSS %2

    cesanta · mongoose os3 May 2022

  • CVE-2020-25756
    39İzleyin

    A buffer overflow vulnerability exists in the mg_get_http_header function in Cesanta Mongoose 6.18 due to a lack of bounds checking.

    KritikCVSS 9,8İstismar yokEPSS %2

    cesanta · mongoose18 Eyl 2020

  • CVE-2023-43338
    39İzleyin

    Cesanta mjs v2.20.0 was discovered to contain a function pointer hijacking vulnerability via the function mjs_get_ptr().

    KritikCVSS 9,8İstismar yokEPSS %1

    cesanta · mjs22 Eyl 2023

  • CVE-2023-50044
    39İzleyin

    Cesanta MJS 2.20.0 has a getprop_builtin_foreign out-of-bounds read if a Built-in API name occurs in a substring of an input string.

    KritikCVSS 9,8İstismar yokEPSS %1

    cesanta · mjs20 Ara 2023

  • CVE-2024-42383
    39İzleyin

    Use of Out-of-range Pointer Offset in Mongoose Web Server library

    KritikCVSS 9,8İstismar yokEPSS %0

    cesanta · mongoose18 Kas 2024

  • CVE-2017-2893
    37İzleyin

    An exploitable NULL pointer dereference vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8.

    YüksekCVSS 7,5İstismar yokEPSS %25

    cesanta · mongoose7 Kas 2017

  • CVE-2018-18765
    37İzleyin

    An exploitable arbitrary memory read vulnerability exists in the MQTT packet-parsing functionality of Cesanta Mongoose 6.13.

    KritikCVSS 9,1İstismar yokEPSS %2

    cesanta · mongoose29 Eki 2018

  • CVE-2018-18764
    37İzleyin

    An exploitable arbitrary memory read vulnerability exists in the MQTT packet-parsing functionality of Cesanta Mongoose 6.13.

    KritikCVSS 9,1İstismar yokEPSS %2

    cesanta · mongoose29 Eki 2018

  • CVE-2026-73251
    37İzleyin

    Mongoose Built-in TLS: CA-bundle certificate chain accepted without any signature verification

    KritikCVSS 9,3İstismar yokEPSS %0

    cesanta · mongoose20 Ağu 2026

  • CVE-2017-11567
    36İzleyin

    Cross-site request forgery (CSRF) vulnerability in Mongoose Web Server before 6.9 allows remote attackers to hijack the authentication of us

    YüksekCVSS 8,8Kavram kanıtıEPSS %4

    cesanta · mongoose embedded web server library7 Eyl 2017

  • CVE-2018-20352
    36İzleyin

    Use-after-free vulnerability in the mg_cgi_ev_handler function in mongoose.c in Cesanta Mongoose Embedded Web Server Library 6.13 and earlie

    YüksekCVSS 8,8İstismar yokEPSS %3

    cesanta · mongoose embedded web server library10 Haz 2019

  • CVE-2021-26529
    36İzleyin

    The mg_tls_init function in Cesanta Mongoose HTTPS server 7.0 and 6.7-6.18 (compiled with mbedTLS support) is vulnerable to remote OOB write

    KritikCVSS 9,1İstismar yokEPSS %1

    cesanta · mongoose8 Şub 2021

  • CVE-2021-26528
    36İzleyin

    The mg_http_serve_file function in Cesanta Mongoose HTTP server 7.0 is vulnerable to remote OOB write attack via connection request after ex

    KritikCVSS 9,1İstismar yokEPSS %1

    cesanta · mongoose8 Şub 2021