Cesanta

Mongoose

47 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 2.15%
  • Veröffentlicht 07.11.2017 16:29:01
  • Zuletzt bearbeitet 20.04.2025 01:37:25

An exploitable memory corruption vulnerability exists in the Websocket protocol implementation of Cesanta Mongoose 6.8. A specially crafted websocket packet can cause an integer overflow, leading to a heap buffer overflow and resulting in denial of s...

Exploit
  • EPSS 2.94%
  • Veröffentlicht 07.11.2017 16:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

An exploitable use-after-free vulnerability exists in the HTTP server implementation of Cesanta Mongoose 6.8. An ordinary HTTP POST request with a CGI target can cause a reuse of previously freed pointer potentially resulting in remote code execution...

  • EPSS 0.37%
  • Veröffentlicht 07.11.2017 16:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

An infinite loop programming error exists in the DNS server functionality of Cesanta Mongoose 6.8 library. A specially crafted DNS request can cause an infinite loop resulting in high CPU usage and Denial Of Service. An attacker can send a packet ove...

  • EPSS 0.38%
  • Veröffentlicht 07.11.2017 16:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

An exploitable arbitrary memory read vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8. A specially crafted MQTT SUBSCRIBE packet can cause an arbitrary out-of-bounds memory read potentially resulting in informatio...

Exploit
  • EPSS 5.09%
  • Veröffentlicht 07.11.2017 16:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

An exploitable stack buffer overflow vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8. A specially crafted MQTT SUBSCRIBE packet can cause a stack buffer overflow resulting in remote code execution. An attacker ne...

Exploit
  • EPSS 5.27%
  • Veröffentlicht 07.11.2017 16:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

An exploitable NULL pointer dereference vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8. An MQTT SUBSCRIBE packet can cause a NULL pointer dereference leading to server crash and denial of service. An attacker ne...

  • EPSS 2.48%
  • Veröffentlicht 07.11.2017 16:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

An exploitable arbitrary memory read vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8. A specially crafted MQTT packet can cause an arbitrary out-of-bounds memory read and write potentially resulting in informatio...