Cesanta

Mongoose

49 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 1.36%
  • Veröffentlicht 19.06.2018 21:29:00
  • Zuletzt bearbeitet 21.11.2024 03:42:21

The mg_handle_cgi function in mongoose.c in Mongoose 6.11 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash, or NULL pointer dereference) via an HTTP request, related to the mbuf_insert function.

Exploit
  • EPSS 2.63%
  • Veröffentlicht 07.11.2017 16:29:01
  • Zuletzt bearbeitet 13.05.2026 00:24:29

An exploitable memory corruption vulnerability exists in the Websocket protocol implementation of Cesanta Mongoose 6.8. A specially crafted websocket packet can cause a buffer to be allocated while leaving stale pointers which leads to a use-after-fr...

Exploit
  • EPSS 2.42%
  • Veröffentlicht 07.11.2017 16:29:01
  • Zuletzt bearbeitet 13.05.2026 00:24:29

An exploitable memory corruption vulnerability exists in the Websocket protocol implementation of Cesanta Mongoose 6.8. A specially crafted websocket packet can cause an integer overflow, leading to a heap buffer overflow and resulting in denial of s...

Exploit
  • EPSS 2.76%
  • Veröffentlicht 07.11.2017 16:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

An exploitable use-after-free vulnerability exists in the HTTP server implementation of Cesanta Mongoose 6.8. An ordinary HTTP POST request with a CGI target can cause a reuse of previously freed pointer potentially resulting in remote code execution...

  • EPSS 1.43%
  • Veröffentlicht 07.11.2017 16:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

An infinite loop programming error exists in the DNS server functionality of Cesanta Mongoose 6.8 library. A specially crafted DNS request can cause an infinite loop resulting in high CPU usage and Denial Of Service. An attacker can send a packet ove...

  • EPSS 1.31%
  • Veröffentlicht 07.11.2017 16:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

An exploitable arbitrary memory read vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8. A specially crafted MQTT SUBSCRIBE packet can cause an arbitrary out-of-bounds memory read potentially resulting in informatio...

Exploit
  • EPSS 31.05%
  • Veröffentlicht 07.11.2017 16:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

An exploitable stack buffer overflow vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8. A specially crafted MQTT SUBSCRIBE packet can cause a stack buffer overflow resulting in remote code execution. An attacker ne...

Exploit
  • EPSS 26.58%
  • Veröffentlicht 07.11.2017 16:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

An exploitable NULL pointer dereference vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8. An MQTT SUBSCRIBE packet can cause a NULL pointer dereference leading to server crash and denial of service. An attacker ne...

  • EPSS 2.4%
  • Veröffentlicht 07.11.2017 16:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

An exploitable arbitrary memory read vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8. A specially crafted MQTT packet can cause an arbitrary out-of-bounds memory read and write potentially resulting in informatio...