CVE-2026-88389
- EPSS 0.15%
- Veröffentlicht 25.09.2026 00:00:00
- Zuletzt bearbeitet 30.09.2026 17:32:07
Espruino 2v29 (commit bffc6d0) contains a NULL pointer dereference vulnerability in jslGetRawString() in src/jslex.c. Crafted raw/binary string input can cause the lexer to pass a NULL iterator target to jsvLockAgain(). In RELEASE/NO_ASSERT builds, t...
CVE-2026-88388
- EPSS 0.32%
- Veröffentlicht 24.09.2026 00:00:00
- Zuletzt bearbeitet 25.09.2026 16:17:29
Espruino 2v29 (commit bffc6d0) contains a stack-based buffer overflow vulnerability in the JavaScript error stack-trace handling path on 64-bit builds. A remote attacker can supply JavaScript input that triggers an exception and reaches jslPrintToken...
CVE-2026-88390
- EPSS 0.17%
- Veröffentlicht 24.09.2026 00:00:00
- Zuletzt bearbeitet 24.09.2026 21:08:55
An out-of-bounds write vulnerability in jslGetTokenValueAsString() in Espruino 2v29 (commit bffc6d0) allows crafted JavaScript input containing an overlong token to trigger a one-byte write beyond the JsLex.token buffer in RELEASE/NO_ASSERT builds. T...
CVE-2024-25201
- EPSS 0.7%
- Veröffentlicht 07.02.2024 14:15:53
- Zuletzt bearbeitet 17.06.2025 20:15:30
Espruino 2v20 (commit fcc9ba4) was discovered to contain an Out-of-bounds Read via jsvStringIteratorPrintfCallback at src/jsvar.c.
CVE-2024-25200
- EPSS 0.71%
- Veröffentlicht 07.02.2024 14:15:53
- Zuletzt bearbeitet 21.11.2024 09:00:26
Espruino 2v20 (commit fcc9ba4) was discovered to contain a Stack Overflow via the jspeFactorFunctionCall at src/jsparse.c.
CVE-2020-23257
- EPSS 0.87%
- Veröffentlicht 04.04.2023 15:15:08
- Zuletzt bearbeitet 13.02.2025 17:15:26
Buffer Overflow vulnerability found in Espruino 2v05.41 allows an attacker to cause a denial of service via the function jsvGarbageCollectMarkUsed in file src/jsvar.c.
CVE-2020-19693
- EPSS 0.84%
- Veröffentlicht 04.04.2023 15:15:07
- Zuletzt bearbeitet 18.02.2025 17:15:11
An issue found in Espruino Espruino 6ea4c0a allows an attacker to execute arbitrrary code via oldFunc parameter of the jswrap_object.c:jswrap_function_replacewith endpoint.
CVE-2022-25465
- EPSS 0.73%
- Veröffentlicht 05.03.2022 02:15:06
- Zuletzt bearbeitet 21.11.2024 06:52:14
Espruino 2v11 release was discovered to contain a stack buffer overflow via src/jsvar.c in jsvGetNextSibling.
CVE-2022-25044
- EPSS 0.88%
- Veröffentlicht 05.03.2022 02:15:06
- Zuletzt bearbeitet 21.11.2024 06:51:34
Espruino 2v11.251 was discovered to contain a stack buffer overflow via src/jsvar.c in jsvNewFromString.
CVE-2021-46324
- EPSS 0.74%
- Veröffentlicht 20.01.2022 22:15:08
- Zuletzt bearbeitet 21.11.2024 06:33:53
Espruino 2v11.251 was discovered to contain a stack buffer overflow via src/jsvar.c in jsvNewFromString.