Espruino

Espruino

22 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.75%
  • Veröffentlicht 20.01.2022 22:15:08
  • Zuletzt bearbeitet 21.11.2024 06:33:53

Espruino 2v10.246 was discovered to contain a stack buffer overflow via src/jsutils.c in vcbprintf.

Exploit
  • EPSS 0.62%
  • Veröffentlicht 20.01.2022 22:15:08
  • Zuletzt bearbeitet 21.11.2024 06:33:53

Espruino 2v11.251 was discovered to contain a SEGV vulnerability via src/jsinteractive.c in jsiGetDeviceFromClass.

Exploit
  • EPSS 2.83%
  • Veröffentlicht 13.07.2021 15:15:08
  • Zuletzt bearbeitet 21.11.2024 05:13:28

Buffer overflow vulnerability in function jsvGetStringChars in Espruino before RELEASE_2V09, allows remote attackers to execute arbitrary code.

Exploit
  • EPSS 1.01%
  • Veröffentlicht 31.05.2018 16:29:00
  • Zuletzt bearbeitet 21.11.2024 03:43:40

Espruino before 1.99 allows attackers to cause a denial of service (application crash) with a user crafted input file via an integer overflow during syntax parsing. This was addressed by fixing stack size detection on Linux in jsutils.c.

Exploit
  • EPSS 1.29%
  • Veröffentlicht 31.05.2018 16:29:00
  • Zuletzt bearbeitet 21.11.2024 03:43:41

Espruino before 1.99 allows attackers to cause a denial of service (application crash) and a potential Information Disclosure with user crafted input files via a Buffer Overflow or Out-of-bounds Read during syntax parsing of certain for loops in jspa...

  • EPSS 0.81%
  • Veröffentlicht 31.05.2018 16:29:00
  • Zuletzt bearbeitet 21.11.2024 03:43:41

Espruino before 1.99 allows attackers to cause a denial of service (application crash) with a user crafted input file via a Buffer Overflow during syntax parsing because of a missing check for stack exhaustion with many '{' characters in jsparse.c.

  • EPSS 0.81%
  • Veröffentlicht 31.05.2018 16:29:00
  • Zuletzt bearbeitet 21.11.2024 03:43:41

Espruino before 1.99 allows attackers to cause a denial of service (application crash) with a user crafted input file via a Buffer Overflow during syntax parsing because a check for '\0' is made for the wrong array element in jsvar.c.

Exploit
  • EPSS 1.3%
  • Veröffentlicht 31.05.2018 16:29:00
  • Zuletzt bearbeitet 21.11.2024 03:43:41

Espruino before 1.99 allows attackers to cause a denial of service (application crash) and a potential Escalation of Privileges with a user crafted input file via a Buffer Overflow during syntax parsing, because strncat is misused.

Exploit
  • EPSS 1.12%
  • Veröffentlicht 31.05.2018 16:29:00
  • Zuletzt bearbeitet 21.11.2024 03:43:41

Espruino before 1.99 allows attackers to cause a denial of service (application crash) with a user crafted input file via a Buffer Overflow during syntax parsing of "VOID" tokens in jsparse.c.

Exploit
  • EPSS 1.23%
  • Veröffentlicht 31.05.2018 16:29:00
  • Zuletzt bearbeitet 21.11.2024 03:43:41

Espruino before 1.99 allows attackers to cause a denial of service (application crash) and potential Information Disclosure with a user crafted input file via a Buffer Overflow during syntax parsing because strncpy is misused in jslex.c.