Search CVE reports


Toggle filters

21 – 30 of 96 results


CVE-2023-31907

Medium priority
Needs evaluation

Jerryscript 3.0.0 was discovered to contain a heap-buffer-overflow via the component scanner_literal_is_created at /jerry-core/parser/js/js-scanner-util.c.

1 affected package

iotjs

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
iotjs Not in release Needs evaluation Not in release Needs evaluation Ignored
Show less packages

CVE-2023-31906

Medium priority
Needs evaluation

Jerryscript 3.0.0(commit 1a2c047) was discovered to contain a heap-buffer-overflow via the component lexer_compare_identifier_to_chars at /jerry-core/parser/js/js-lexer.c.

1 affected package

iotjs

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
iotjs Not in release Needs evaluation Not in release Needs evaluation Ignored
Show less packages

CVE-2023-30414

Medium priority
Needs evaluation

Jerryscript commit 1a2c047 was discovered to contain a stack overflow via the component vm_loop at /jerry-core/vm/vm.c.

1 affected package

iotjs

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
iotjs Not in release Needs evaluation Not in release Needs evaluation Ignored
Show less packages

CVE-2023-30410

Medium priority
Needs evaluation

Jerryscript commit 1a2c047 was discovered to contain a stack overflow via the component ecma_op_function_construct at /operations/ecma-function-object.c.

1 affected package

iotjs

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
iotjs Not in release Needs evaluation Not in release Needs evaluation Ignored
Show less packages

CVE-2023-30408

Medium priority
Needs evaluation

Jerryscript commit 1a2c047 was discovered to contain a segmentation violation via the component build/bin/jerry.

1 affected package

iotjs

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
iotjs Not in release Needs evaluation Not in release Needs evaluation Ignored
Show less packages

CVE-2023-30406

Medium priority
Needs evaluation

Jerryscript commit 1a2c047 was discovered to contain a segmentation violation via the component ecma_find_named_property at /base/ecma-helpers.c.

1 affected package

iotjs

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
iotjs Not in release Needs evaluation Not in release Needs evaluation Ignored
Show less packages

CVE-2022-32117

Medium priority
Not affected

Jerryscript v2.4.0 was discovered to contain a stack buffer overflow via the function jerryx_print_unhandled_exception in /util/print.c.

1 affected package

iotjs

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
iotjs Not affected Not in release Not affected Ignored
Show less packages

CVE-2021-41683

Medium priority
Needs evaluation

There is a stack-overflow at ecma-helpers.c:326 in ecma_get_lex_env_type in JerryScript 2.4.0

1 affected package

iotjs

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
iotjs Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2021-41682

Medium priority
Needs evaluation

There is a heap-use-after-free at ecma-helpers-string.c:1940 in ecma_compare_ecma_non_direct_strings in JerryScript 2.4.0

1 affected package

iotjs

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
iotjs Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2021-42863

Medium priority
Needs evaluation

A buffer overflow in ecma_builtin_typedarray_prototype_filter() in JerryScript version fe3a5c0 allows an attacker to construct a fake object or a fake arraybuffer with unlimited size.

1 affected package

iotjs

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
iotjs Not in release Needs evaluation Needs evaluation
Show less packages