CVE-2018-10945
- EPSS 1.36%
- Veröffentlicht 19.06.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:21
The mg_handle_cgi function in mongoose.c in Mongoose 6.11 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash, or NULL pointer dereference) via an HTTP request, related to the mbuf_insert function.
CVE-2017-2922
- EPSS 2.63%
- Veröffentlicht 07.11.2017 16:29:01
- Zuletzt bearbeitet 13.05.2026 00:24:29
An exploitable memory corruption vulnerability exists in the Websocket protocol implementation of Cesanta Mongoose 6.8. A specially crafted websocket packet can cause a buffer to be allocated while leaving stale pointers which leads to a use-after-fr...
CVE-2017-2921
- EPSS 2.42%
- Veröffentlicht 07.11.2017 16:29:01
- Zuletzt bearbeitet 13.05.2026 00:24:29
An exploitable memory corruption vulnerability exists in the Websocket protocol implementation of Cesanta Mongoose 6.8. A specially crafted websocket packet can cause an integer overflow, leading to a heap buffer overflow and resulting in denial of s...
CVE-2017-2891
- EPSS 2.76%
- Veröffentlicht 07.11.2017 16:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
An exploitable use-after-free vulnerability exists in the HTTP server implementation of Cesanta Mongoose 6.8. An ordinary HTTP POST request with a CGI target can cause a reuse of previously freed pointer potentially resulting in remote code execution...
CVE-2017-2909
- EPSS 1.43%
- Veröffentlicht 07.11.2017 16:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
An infinite loop programming error exists in the DNS server functionality of Cesanta Mongoose 6.8 library. A specially crafted DNS request can cause an infinite loop resulting in high CPU usage and Denial Of Service. An attacker can send a packet ove...
CVE-2017-2895
- EPSS 1.31%
- Veröffentlicht 07.11.2017 16:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
An exploitable arbitrary memory read vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8. A specially crafted MQTT SUBSCRIBE packet can cause an arbitrary out-of-bounds memory read potentially resulting in informatio...
CVE-2017-2894
- EPSS 31.05%
- Veröffentlicht 07.11.2017 16:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
An exploitable stack buffer overflow vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8. A specially crafted MQTT SUBSCRIBE packet can cause a stack buffer overflow resulting in remote code execution. An attacker ne...
CVE-2017-2893
- EPSS 26.58%
- Veröffentlicht 07.11.2017 16:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
An exploitable NULL pointer dereference vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8. An MQTT SUBSCRIBE packet can cause a NULL pointer dereference leading to server crash and denial of service. An attacker ne...
CVE-2017-2892
- EPSS 2.4%
- Veröffentlicht 07.11.2017 16:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
An exploitable arbitrary memory read vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8. A specially crafted MQTT packet can cause an arbitrary out-of-bounds memory read and write potentially resulting in informatio...