QuickJS Project kayıtları
quickjs project üreticisine ait 14 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %71,4
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-416 Use After Free3
- CWE-125 Out-of-bounds Read2
- CWE-190 Integer Overflow or Wraparound1
- CWE-191 Integer Underflow (Wrap or Wraparound)1
- CWE-400 Uncontrolled Resource Consumption1
- CWE-476 NULL Pointer Dereference1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
14 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
35İzleyin | CVE-2025-62491İstismar yok | Use-after-free in js_std_promise_rejection_check in QuickJSquickjs project · quickjs · CWE-416 | Yüksek8,8 | — | %0,4 | 16 Eki 2025 |
35İzleyin | CVE-2025-62490İstismar yok | Use-after-free in js_print_object in QuickJSquickjs project · quickjs · CWE-416 | Yüksek8,8 | — | %0,4 | 16 Eki 2025 |
33İzleyin | CVE-2025-46688İstismar yok | quickjs-ng through 0.9.0 has an incorrect size calculation in JS_ReadBigInt for a BigInt, leading to a heap-based buffer overflow.quickjs-ng · quickjs · CWE-131 | Yüksek8,4 | — | %0,3 | 27 Nis 2025 |
30İzleyin | CVE-2020-22876İstismar yok | Buffer Overflow vulnerability in quickjs.c in QuickJS, allows remote attackers to cause denial of service.quickjs project · quickjs · CWE-120 | Yüksek7,5 | — | %1,6 | 13 Tem 2021 |
30İzleyin | CVE-2023-31922İstismar yok | QuickJS commit 2788d71 was discovered to contain a stack-overflow via the component js_proxy_isArray at quickjs.c.quickjs project · quickjs · CWE-787 | Yüksek7,5 | — | %0,7 | 12 May 2023 |
30İzleyin | CVE-2023-48183İstismar yok | QuickJS before c4cdd61 has a build_for_in_iterator NULL pointer dereference because of an erroneous lexical scope of "this" with eval.quickjs project · quickjs · CWE-476 | Yüksek7,5 | — | %0,6 | 23 Nis 2024 |
30İzleyin | CVE-2025-69654İstismar yok | A crafted JavaScript input executed with the QuickJS release 2025-09-13, fixed in commit fcd33c1afa7b3028531f53cd1190a3877454f6b3 (2025-12-1quickjs project · quickjs · CWE-400 | Yüksek7,5 | — | %0,3 | 6 Mar 2026 |
28İzleyin | CVE-2025-62494İstismar yok | Type confusion in string addition in QuickJSquickjs project · quickjs · CWE-704 | Yüksek7,1 | — | %0,5 | 16 Eki 2025 |
28İzleyin | CVE-2025-62496İstismar yok | Integer overflow in js_bigint_from_string in QuickJSquickjs project · quickjs · CWE-190 | Yüksek7,1 | — | %0,5 | 16 Eki 2025 |
28İzleyin | CVE-2025-62495İstismar yok | Type confusion in string addition in QuickJSquickjs project · quickjs · CWE-191 | Yüksek7,1 | — | %0,5 | 16 Eki 2025 |
26İzleyin | CVE-2025-69653İstismar yok | A crafted JavaScript input can trigger an internal assertion failure in QuickJS release 2025-09-13, fixed in commit 1dbba8a88eaa40d15a8a9b70quickjs project · quickjs · CWE-617 | Orta6,5 | — | %0,2 | 6 Mar 2026 |
23İzleyin | CVE-2025-62492İstismar yok | Heap out-of-bounds read in js_typed_array_indexOf in QuickJSquickjs project · quickjs · CWE-125 | Orta5,9 | — | %0,4 | 16 Eki 2025 |
23İzleyin | CVE-2025-62493İstismar yok | Heap out-of-bounds read in js_bigint_to_string1 in QuickJSquickjs project · quickjs · CWE-125 | Orta5,9 | — | %0,4 | 16 Eki 2025 |
15İzleyin | CVE-2023-48184İstismar yok | QuickJS before 7414e5f has a quickjs.h JS_FreeValueRT use-after-free because of incorrect garbage collection of async functions with closurequickjs project · quickjs · CWE-416 | Düşük3,9 | — | %0,3 | 23 Nis 2024 |
- CVE-2025-6249135İzleyin
Use-after-free in js_std_promise_rejection_check in QuickJS
YüksekCVSS 8,8İstismar yokEPSS %0quickjs project · quickjs16 Eki 2025
- CVE-2025-6249035İzleyin
Use-after-free in js_print_object in QuickJS
YüksekCVSS 8,8İstismar yokEPSS %0quickjs project · quickjs16 Eki 2025
- CVE-2025-4668833İzleyin
quickjs-ng through 0.9.0 has an incorrect size calculation in JS_ReadBigInt for a BigInt, leading to a heap-based buffer overflow.
YüksekCVSS 8,4İstismar yokEPSS %0quickjs-ng · quickjs27 Nis 2025
- CVE-2020-2287630İzleyin
Buffer Overflow vulnerability in quickjs.c in QuickJS, allows remote attackers to cause denial of service.
YüksekCVSS 7,5İstismar yokEPSS %2quickjs project · quickjs13 Tem 2021
- CVE-2023-3192230İzleyin
QuickJS commit 2788d71 was discovered to contain a stack-overflow via the component js_proxy_isArray at quickjs.c.
YüksekCVSS 7,5İstismar yokEPSS %1quickjs project · quickjs12 May 2023
- CVE-2023-4818330İzleyin
QuickJS before c4cdd61 has a build_for_in_iterator NULL pointer dereference because of an erroneous lexical scope of "this" with eval.
YüksekCVSS 7,5İstismar yokEPSS %1quickjs project · quickjs23 Nis 2024
- CVE-2025-6965430İzleyin
A crafted JavaScript input executed with the QuickJS release 2025-09-13, fixed in commit fcd33c1afa7b3028531f53cd1190a3877454f6b3 (2025-12-1
YüksekCVSS 7,5İstismar yokEPSS %0quickjs project · quickjs6 Mar 2026
- CVE-2025-6249428İzleyin
Type confusion in string addition in QuickJS
YüksekCVSS 7,1İstismar yokEPSS %1quickjs project · quickjs16 Eki 2025
- CVE-2025-6249628İzleyin
Integer overflow in js_bigint_from_string in QuickJS
YüksekCVSS 7,1İstismar yokEPSS %0quickjs project · quickjs16 Eki 2025
- CVE-2025-6249528İzleyin
Type confusion in string addition in QuickJS
YüksekCVSS 7,1İstismar yokEPSS %0quickjs project · quickjs16 Eki 2025
- CVE-2025-6965326İzleyin
A crafted JavaScript input can trigger an internal assertion failure in QuickJS release 2025-09-13, fixed in commit 1dbba8a88eaa40d15a8a9b70
OrtaCVSS 6,5İstismar yokEPSS %0quickjs project · quickjs6 Mar 2026
- CVE-2025-6249223İzleyin
Heap out-of-bounds read in js_typed_array_indexOf in QuickJS
OrtaCVSS 5,9İstismar yokEPSS %0quickjs project · quickjs16 Eki 2025
- CVE-2025-6249323İzleyin
Heap out-of-bounds read in js_bigint_to_string1 in QuickJS
OrtaCVSS 5,9İstismar yokEPSS %0quickjs project · quickjs16 Eki 2025
- CVE-2023-4818415İzleyin
QuickJS before 7414e5f has a quickjs.h JS_FreeValueRT use-after-free because of incorrect garbage collection of async functions with closure
DüşükCVSS 3,9İstismar yokEPSS %0quickjs project · quickjs23 Nis 2024