Search CVE reports
21 – 30 of 96 results
CVE-2023-31907
Medium priorityJerryscript 3.0.0 was discovered to contain a heap-buffer-overflow via the component scanner_literal_is_created at /jerry-core/parser/js/js-scanner-util.c.
1 affected package
iotjs
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
iotjs | Not in release | Needs evaluation | Not in release | Needs evaluation | Ignored |
CVE-2023-31906
Medium priorityJerryscript 3.0.0(commit 1a2c047) was discovered to contain a heap-buffer-overflow via the component lexer_compare_identifier_to_chars at /jerry-core/parser/js/js-lexer.c.
1 affected package
iotjs
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
iotjs | Not in release | Needs evaluation | Not in release | Needs evaluation | Ignored |
CVE-2023-30414
Medium priorityJerryscript commit 1a2c047 was discovered to contain a stack overflow via the component vm_loop at /jerry-core/vm/vm.c.
1 affected package
iotjs
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
iotjs | Not in release | Needs evaluation | Not in release | Needs evaluation | Ignored |
CVE-2023-30410
Medium priorityJerryscript commit 1a2c047 was discovered to contain a stack overflow via the component ecma_op_function_construct at /operations/ecma-function-object.c.
1 affected package
iotjs
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
iotjs | Not in release | Needs evaluation | Not in release | Needs evaluation | Ignored |
CVE-2023-30408
Medium priorityJerryscript commit 1a2c047 was discovered to contain a segmentation violation via the component build/bin/jerry.
1 affected package
iotjs
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
iotjs | Not in release | Needs evaluation | Not in release | Needs evaluation | Ignored |
CVE-2023-30406
Medium priorityJerryscript commit 1a2c047 was discovered to contain a segmentation violation via the component ecma_find_named_property at /base/ecma-helpers.c.
1 affected package
iotjs
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
iotjs | Not in release | Needs evaluation | Not in release | Needs evaluation | Ignored |
CVE-2022-32117
Medium priorityJerryscript v2.4.0 was discovered to contain a stack buffer overflow via the function jerryx_print_unhandled_exception in /util/print.c.
1 affected package
iotjs
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
iotjs | — | Not affected | Not in release | Not affected | Ignored |
CVE-2021-41683
Medium priorityThere is a stack-overflow at ecma-helpers.c:326 in ecma_get_lex_env_type in JerryScript 2.4.0
1 affected package
iotjs
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
iotjs | Not in release | Needs evaluation | — | Needs evaluation | — |
CVE-2021-41682
Medium priorityThere is a heap-use-after-free at ecma-helpers-string.c:1940 in ecma_compare_ecma_non_direct_strings in JerryScript 2.4.0
1 affected package
iotjs
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
iotjs | Not in release | Needs evaluation | — | Needs evaluation | — |
CVE-2021-42863
Medium priorityA buffer overflow in ecma_builtin_typedarray_prototype_filter() in JerryScript version fe3a5c0 allows an attacker to construct a fake object or a fake arraybuffer with unlimited size.
1 affected package
iotjs
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
iotjs | Not in release | Needs evaluation | — | Needs evaluation | — |