CVE-2017-2921
- EPSS 2.15%
- Veröffentlicht 07.11.2017 16:29:01
- Zuletzt bearbeitet 20.04.2025 01:37:25
An exploitable memory corruption vulnerability exists in the Websocket protocol implementation of Cesanta Mongoose 6.8. A specially crafted websocket packet can cause an integer overflow, leading to a heap buffer overflow and resulting in denial of s...
CVE-2017-2891
- EPSS 2.94%
- Veröffentlicht 07.11.2017 16:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
An exploitable use-after-free vulnerability exists in the HTTP server implementation of Cesanta Mongoose 6.8. An ordinary HTTP POST request with a CGI target can cause a reuse of previously freed pointer potentially resulting in remote code execution...
CVE-2017-2909
- EPSS 0.37%
- Veröffentlicht 07.11.2017 16:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
An infinite loop programming error exists in the DNS server functionality of Cesanta Mongoose 6.8 library. A specially crafted DNS request can cause an infinite loop resulting in high CPU usage and Denial Of Service. An attacker can send a packet ove...
CVE-2017-2895
- EPSS 0.38%
- Veröffentlicht 07.11.2017 16:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
An exploitable arbitrary memory read vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8. A specially crafted MQTT SUBSCRIBE packet can cause an arbitrary out-of-bounds memory read potentially resulting in informatio...
CVE-2017-2894
- EPSS 5.09%
- Veröffentlicht 07.11.2017 16:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
An exploitable stack buffer overflow vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8. A specially crafted MQTT SUBSCRIBE packet can cause a stack buffer overflow resulting in remote code execution. An attacker ne...
CVE-2017-2893
- EPSS 5.27%
- Veröffentlicht 07.11.2017 16:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
An exploitable NULL pointer dereference vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8. An MQTT SUBSCRIBE packet can cause a NULL pointer dereference leading to server crash and denial of service. An attacker ne...
CVE-2017-2892
- EPSS 2.48%
- Veröffentlicht 07.11.2017 16:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
An exploitable arbitrary memory read vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8. A specially crafted MQTT packet can cause an arbitrary out-of-bounds memory read and write potentially resulting in informatio...