JerryScript kayıtları
jerryscript üreticisine ait 98 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 4
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-617 Reachable Assertion40
- CWE-787 Out-of-bounds Write20
- CWE-125 Out-of-bounds Read8
- CWE-416 Use After Free5
- CWE-476 NULL Pointer Dereference5
- CWE-400 Uncontrolled Resource Consumption4
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
98 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2019-1010176İstismar yok | JerryScript commit 4e58ccf68070671e1fff5cd6673f0c1d5b80b166 is affected by: Buffer Overflow.jerryscript · jerryscript · CWE-787 | Kritik9,8 | — | %2,5 | 25 Tem 2019 |
40Planlayın | CVE-2023-36109Kavram kanıtı | Buffer Overflow vulnerability in JerryScript version 3.0, allows remote attackers to execute arbitrary code via ecma_stringbuilder_append_rajerryscript · jerryscript · CWE-120 | Kritik9,8 | — | %2,4 | 20 Eyl 2023 |
40Planlayın | CVE-2017-18212İstismar yok | An issue was discovered in JerryScript 1.0.jerryscript · jerryscript · CWE-125 | Kritik9,8 | — | %1,8 | 1 Mar 2018 |
40Planlayın | CVE-2021-42863İstismar yok | A buffer overflow in ecma_builtin_typedarray_prototype_filter() in JerryScript version fe3a5c0 allows an attacker to construct a fake objectjerryscript · jerryscript · CWE-120 | Kritik9,8 | — | %1,7 | 12 May 2022 |
39İzleyin | CVE-2018-11419İstismar yok | An issue was discovered in JerryScript 1.0.jerryscript · jerryscript · CWE-125 | Kritik9,8 | — | %1,6 | 24 May 2018 |
39İzleyin | CVE-2018-11418İstismar yok | An issue was discovered in JerryScript 1.0.jerryscript · jerryscript · CWE-125 | Kritik9,8 | — | %1,6 | 24 May 2018 |
39İzleyin | CVE-2023-38961İstismar yok | Buffer Overflwo vulnerability in JerryScript Project jerryscript v.3.0.0 allows a remote attacker to execute arbitrary code via the scanner_jerryscript · jerryscript · CWE-787 | Kritik9,8 | — | %1,5 | 21 Ağu 2023 |
39İzleyin | CVE-2020-23303İstismar yok | There is a heap-buffer-overflow at jmem-poolman.c:165 in jmem_pools_collect_empty in JerryScript 2.2.0.jerryscript · jerryscript · CWE-787 | Kritik9,8 | — | %1,3 | 10 Haz 2021 |
39İzleyin | CVE-2020-22597İstismar yok | An issue in Jerrscript- project Jerryscrip v.jerryscript · jerryscript | Kritik9,8 | — | %1,3 | 3 Tem 2023 |
39İzleyin | CVE-2020-23321İstismar yok | There is a heap-buffer-overflow at lit-strings.c:431 in lit_read_code_unit_from_utf8 in JerryScript 2.2.0.jerryscript · jerryscript · CWE-787 | Kritik9,8 | — | %1,3 | 10 Haz 2021 |
39İzleyin | CVE-2020-23323İstismar yok | There is a heap-buffer-overflow at re-parser.c in re_parse_char_escape in JerryScript 2.2.0.jerryscript · jerryscript · CWE-787 | Kritik9,8 | — | %1,3 | 10 Haz 2021 |
39İzleyin | CVE-2020-23306İstismar yok | There is a stack-overflow at ecma-regexp-object.c:535 in ecma_regexp_match in JerryScript 2.2.0.jerryscript · jerryscript · CWE-787 | Kritik9,8 | — | %1,3 | 10 Haz 2021 |
39İzleyin | CVE-2020-23302İstismar yok | There is a heap-use-after-free at ecma-helpers-string.c:772 in ecma_ref_ecma_string in JerryScript 2.2.0jerryscript · jerryscript · CWE-416 | Kritik9,8 | — | %1,3 | 10 Haz 2021 |
39İzleyin | CVE-2021-43453İstismar yok | A Heap-based Buffer Overflow vulnerability exists in JerryScript 2.4.0 and prior versions via an out-of-bounds read in parser_parse_for_statjerryscript · jerryscript · CWE-125 | Kritik9,8 | — | %1,3 | 7 Nis 2022 |
39İzleyin | CVE-2021-41751İstismar yok | Buffer overflow vulnerability in file ecma-builtin-array-prototype.c:909 in function ecma_builtin_array_prototype_object_slice in Jerryscripjerryscript · jerryscript · CWE-120 | Kritik9,8 | — | %1,2 | 5 Nis 2022 |
39İzleyin | CVE-2021-41752İstismar yok | Stack overflow vulnerability in Jerryscript before commit e1ce7dd7271288be8c0c8136eea9107df73a8ce2 on Oct 20, 2021 due to an unbounded recurjerryscript · jerryscript · CWE-674 | Kritik9,8 | — | %1,2 | 5 Nis 2022 |
36İzleyin | CVE-2020-29657İstismar yok | In JerryScript 2.3.0, there is an out-of-bounds read in main_print_unhandled_exception in the main-utils.c file.jerryscript · jerryscript · CWE-125 | Kritik9,1 | — | %1,2 | 9 Ara 2020 |
35İzleyin | CVE-2021-26195İstismar yok | An issue was discovered in JerryScript 2.4.0.jerryscript · jerryscript · CWE-787 | Yüksek8,8 | — | %1,1 | 10 Haz 2021 |
32İzleyin | CVE-2017-14749İstismar yok | JerryScript 1.0 allows remote attackers to cause a denial of service (jmem_heap_alloc_block_internal heap memory corruption) or possibly exejerryscript · jerryscript · CWE-119 | Yüksek7,8 | — | %2,1 | 26 Eyl 2017 |
31İzleyin | CVE-2017-9250İstismar yok | The lexer_process_char_literal function in jerry-core/parser/js/js-lexer.c in JerryScript 1.0 does not skip memory allocation for empty strijerryscript · jerryscript · CWE-476 | Yüksek7,5 | — | %2,5 | 28 May 2017 |
31İzleyin | CVE-2020-13991İstismar yok | vm/opcodes.c in JerryScript 2.2.0 allows attackers to hijack the flow of control by controlling a register.jerryscript · jerryscript | Yüksek7,5 | — | %2,4 | 24 Eyl 2020 |
31İzleyin | CVE-2020-13649İstismar yok | parser/js/js-scanner.c in JerryScript 2.2.0 mishandles errors during certain out-of-memory conditions, as demonstrated by a scanner_reverse_jerryscript · jerryscript · CWE-476 | Yüksek7,5 | — | %2,1 | 28 May 2020 |
31İzleyin | CVE-2021-44988İstismar yok | Jerryscript v3.0.0 and below was discovered to contain a stack overflow via ecma_find_named_property in ecma-helpers.c.jerryscript · jerryscript · CWE-770 | Yüksek7,8 | — | %1,1 | 24 Oca 2022 |
31İzleyin | CVE-2022-22895İstismar yok | Jerryscript 3.0.0 was discovered to contain a heap-buffer-overflow via ecma_utf8_string_to_number_by_radix in /jerry-core/ecma/base/ecma-heljerryscript · jerryscript · CWE-787 | Yüksek7,8 | — | %0,8 | 20 Oca 2022 |
31İzleyin | CVE-2020-24345İstismar yok | JerryScript through 2.3.0 allows stack consumption via function a(){new new Proxy(a,{})}JSON.parse("[]",a).jerryscript · jerryscript · CWE-787 | Yüksek7,8 | — | %0,8 | 13 Ağu 2020 |
- CVE-2019-101017640Planlayın
JerryScript commit 4e58ccf68070671e1fff5cd6673f0c1d5b80b166 is affected by: Buffer Overflow.
KritikCVSS 9,8İstismar yokEPSS %3jerryscript · jerryscript25 Tem 2019
- CVE-2023-3610940Planlayın
Buffer Overflow vulnerability in JerryScript version 3.0, allows remote attackers to execute arbitrary code via ecma_stringbuilder_append_ra
KritikCVSS 9,8Kavram kanıtıEPSS %2jerryscript · jerryscript20 Eyl 2023
- CVE-2017-1821240Planlayın
An issue was discovered in JerryScript 1.0.
KritikCVSS 9,8İstismar yokEPSS %2jerryscript · jerryscript1 Mar 2018
- CVE-2021-4286340Planlayın
A buffer overflow in ecma_builtin_typedarray_prototype_filter() in JerryScript version fe3a5c0 allows an attacker to construct a fake object
KritikCVSS 9,8İstismar yokEPSS %2jerryscript · jerryscript12 May 2022
- CVE-2018-1141939İzleyin
An issue was discovered in JerryScript 1.0.
KritikCVSS 9,8İstismar yokEPSS %2jerryscript · jerryscript24 May 2018
- CVE-2018-1141839İzleyin
An issue was discovered in JerryScript 1.0.
KritikCVSS 9,8İstismar yokEPSS %2jerryscript · jerryscript24 May 2018
- CVE-2023-3896139İzleyin
Buffer Overflwo vulnerability in JerryScript Project jerryscript v.3.0.0 allows a remote attacker to execute arbitrary code via the scanner_
KritikCVSS 9,8İstismar yokEPSS %1jerryscript · jerryscript21 Ağu 2023
- CVE-2020-2330339İzleyin
There is a heap-buffer-overflow at jmem-poolman.c:165 in jmem_pools_collect_empty in JerryScript 2.2.0.
KritikCVSS 9,8İstismar yokEPSS %1jerryscript · jerryscript10 Haz 2021
- CVE-2020-2259739İzleyin
An issue in Jerrscript- project Jerryscrip v.
KritikCVSS 9,8İstismar yokEPSS %1jerryscript · jerryscript3 Tem 2023
- CVE-2020-2332139İzleyin
There is a heap-buffer-overflow at lit-strings.c:431 in lit_read_code_unit_from_utf8 in JerryScript 2.2.0.
KritikCVSS 9,8İstismar yokEPSS %1jerryscript · jerryscript10 Haz 2021
- CVE-2020-2332339İzleyin
There is a heap-buffer-overflow at re-parser.c in re_parse_char_escape in JerryScript 2.2.0.
KritikCVSS 9,8İstismar yokEPSS %1jerryscript · jerryscript10 Haz 2021
- CVE-2020-2330639İzleyin
There is a stack-overflow at ecma-regexp-object.c:535 in ecma_regexp_match in JerryScript 2.2.0.
KritikCVSS 9,8İstismar yokEPSS %1jerryscript · jerryscript10 Haz 2021
- CVE-2020-2330239İzleyin
There is a heap-use-after-free at ecma-helpers-string.c:772 in ecma_ref_ecma_string in JerryScript 2.2.0
KritikCVSS 9,8İstismar yokEPSS %1jerryscript · jerryscript10 Haz 2021
- CVE-2021-4345339İzleyin
A Heap-based Buffer Overflow vulnerability exists in JerryScript 2.4.0 and prior versions via an out-of-bounds read in parser_parse_for_stat
KritikCVSS 9,8İstismar yokEPSS %1jerryscript · jerryscript7 Nis 2022
- CVE-2021-4175139İzleyin
Buffer overflow vulnerability in file ecma-builtin-array-prototype.c:909 in function ecma_builtin_array_prototype_object_slice in Jerryscrip
KritikCVSS 9,8İstismar yokEPSS %1jerryscript · jerryscript5 Nis 2022
- CVE-2021-4175239İzleyin
Stack overflow vulnerability in Jerryscript before commit e1ce7dd7271288be8c0c8136eea9107df73a8ce2 on Oct 20, 2021 due to an unbounded recur
KritikCVSS 9,8İstismar yokEPSS %1jerryscript · jerryscript5 Nis 2022
- CVE-2020-2965736İzleyin
In JerryScript 2.3.0, there is an out-of-bounds read in main_print_unhandled_exception in the main-utils.c file.
KritikCVSS 9,1İstismar yokEPSS %1jerryscript · jerryscript9 Ara 2020
- CVE-2021-2619535İzleyin
An issue was discovered in JerryScript 2.4.0.
YüksekCVSS 8,8İstismar yokEPSS %1jerryscript · jerryscript10 Haz 2021
- CVE-2017-1474932İzleyin
JerryScript 1.0 allows remote attackers to cause a denial of service (jmem_heap_alloc_block_internal heap memory corruption) or possibly exe
YüksekCVSS 7,8İstismar yokEPSS %2jerryscript · jerryscript26 Eyl 2017
- CVE-2017-925031İzleyin
The lexer_process_char_literal function in jerry-core/parser/js/js-lexer.c in JerryScript 1.0 does not skip memory allocation for empty stri
YüksekCVSS 7,5İstismar yokEPSS %2jerryscript · jerryscript28 May 2017
- CVE-2020-1399131İzleyin
vm/opcodes.c in JerryScript 2.2.0 allows attackers to hijack the flow of control by controlling a register.
YüksekCVSS 7,5İstismar yokEPSS %2jerryscript · jerryscript24 Eyl 2020
- CVE-2020-1364931İzleyin
parser/js/js-scanner.c in JerryScript 2.2.0 mishandles errors during certain out-of-memory conditions, as demonstrated by a scanner_reverse_
YüksekCVSS 7,5İstismar yokEPSS %2jerryscript · jerryscript28 May 2020
- CVE-2021-4498831İzleyin
Jerryscript v3.0.0 and below was discovered to contain a stack overflow via ecma_find_named_property in ecma-helpers.c.
YüksekCVSS 7,8İstismar yokEPSS %1jerryscript · jerryscript24 Oca 2022
- CVE-2022-2289531İzleyin
Jerryscript 3.0.0 was discovered to contain a heap-buffer-overflow via ecma_utf8_string_to_number_by_radix in /jerry-core/ecma/base/ecma-hel
YüksekCVSS 7,8İstismar yokEPSS %1jerryscript · jerryscript20 Oca 2022
- CVE-2020-2434531İzleyin
JerryScript through 2.3.0 allows stack consumption via function a(){new new Proxy(a,{})}JSON.parse("[]",a).
YüksekCVSS 7,8İstismar yokEPSS %1jerryscript · jerryscript13 Ağu 2020