CVE-2026-86716
- EPSS 0.35%
- Veröffentlicht 08.09.2026 19:20:17
- Zuletzt bearbeitet 08.09.2026 20:18:53
A vulnerability was determined in Cesanta mJS up to 1.26. Affected is the function skip_spaces_and_comments of the file src/mjs_tok.c. Executing a manipulation can lead to heap-based buffer overflow. The attack can be launched remotely. The exploit h...
CVE-2024-35386
- EPSS 0.6%
- Veröffentlicht 21.05.2024 14:15:12
- Zuletzt bearbeitet 05.05.2025 17:15:55
An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_do_gc function in the mjs.c file.
CVE-2024-35385
- EPSS 0.53%
- Veröffentlicht 21.05.2024 14:15:12
- Zuletzt bearbeitet 05.05.2025 17:19:06
An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_mk_ffi_sig function in the mjs.c file.
CVE-2024-35384
- EPSS 0.34%
- Veröffentlicht 21.05.2024 14:15:12
- Zuletzt bearbeitet 05.05.2025 17:20:11
An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_array_length function in the mjs.c file.
CVE-2023-49553
- EPSS 0.86%
- Veröffentlicht 02.01.2024 23:15:12
- Zuletzt bearbeitet 03.06.2025 15:15:44
An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_destroy function in the msj.c file.
CVE-2023-49552
- EPSS 0.76%
- Veröffentlicht 02.01.2024 23:15:12
- Zuletzt bearbeitet 17.04.2025 19:15:57
An Out of Bounds Write in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_op_json_stringify function in the msj.c file.
CVE-2023-49551
- EPSS 0.77%
- Veröffentlicht 02.01.2024 23:15:12
- Zuletzt bearbeitet 21.11.2024 08:33:32
An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_op_json_parse function in the msj.c file.
CVE-2023-49550
- EPSS 0.76%
- Veröffentlicht 02.01.2024 23:15:12
- Zuletzt bearbeitet 16.05.2025 18:16:01
An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs+0x4ec508 component.
CVE-2023-49549
- EPSS 0.76%
- Veröffentlicht 02.01.2024 23:15:12
- Zuletzt bearbeitet 16.06.2025 20:15:25
An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_getretvalpos function in the msj.c file.
CVE-2023-50044
- EPSS 0.86%
- Veröffentlicht 20.12.2023 09:15:07
- Zuletzt bearbeitet 21.11.2024 08:36:29
Cesanta MJS 2.20.0 has a getprop_builtin_foreign out-of-bounds read if a Built-in API name occurs in a substring of an input string.