Search CVE reports


Toggle filters

31 – 40 of 96 results


CVE-2021-41959

Medium priority
Vulnerable

JerryScript Git version 14ff5bf does not sufficiently track and release allocated memory via jerry-core/ecma/operations/ecma-regexp-object.c after RegExp, which causes a memory leak.

2 affected packages

git, iotjs

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
git Not affected Not affected Not affected Not affected Not affected
iotjs Not in release Vulnerable Not affected
Show less packages

CVE-2021-43453

Medium priority
Needs evaluation

A Heap-based Buffer Overflow vulnerability exists in JerryScript 2.4.0 and prior versions via an out-of-bounds read in parser_parse_for_statement_start in the js-parser-statm.c file. This issue is similar to CVE-2020-29657.

1 affected package

iotjs

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
iotjs Not in release Needs evaluation Needs evaluation Ignored
Show less packages

CVE-2021-41752

Medium priority
Needs evaluation

Stack overflow vulnerability in Jerryscript before commit e1ce7dd7271288be8c0c8136eea9107df73a8ce2 on Oct 20, 2021 due to an unbounded recursive call to the new opt() function.

1 affected package

iotjs

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
iotjs Not in release Needs evaluation Needs evaluation Ignored
Show less packages

CVE-2021-41751

Medium priority
Needs evaluation

Buffer overflow vulnerability in file ecma-builtin-array-prototype.c:909 in function ecma_builtin_array_prototype_object_slice in Jerryscript before commit e1ce7dd7271288be8c0c8136eea9107df73a8ce2 on Oct 20, 2021.

1 affected package

iotjs

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
iotjs Not in release Needs evaluation Needs evaluation Ignored
Show less packages

CVE-2022-22901

Medium priority
Not affected

There is an Assertion in 'context_p->next_scanner_info_p->type == SCANNER_TYPE_FUNCTION' failed at parser_parse_function_arguments in /js/js-parser.c of JerryScript commit a6ab5e9.

1 affected package

iotjs

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
iotjs Not affected Not in release Not affected Ignored
Show less packages

CVE-2021-44994

Medium priority
Needs evaluation

There is an Assertion ''JERRY_CONTEXT (jmem_heap_allocated_size) == 0'' failed at /jerry-core/jmem/jmem-heap.c in Jerryscript 3.0.0.

1 affected package

iotjs

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
iotjs Not in release Needs evaluation Not affected Ignored
Show less packages

CVE-2021-44993

Medium priority
Vulnerable

There is an Assertion ''ecma_is_value_boolean (base_value)'' failed at /jerry-core/ecma/operations/ecma-get-put-value.c in Jerryscript 3.0.0.

1 affected package

iotjs

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
iotjs Not in release Needs evaluation Vulnerable Ignored
Show less packages

CVE-2021-44992

Medium priority
Needs evaluation

There is an Assertion ''ecma_object_is_typedarray (obj_p)'' failed at /jerry-core/ecma/operations/ecma-typedarray-object.c in Jerryscript 3.0.0.

1 affected package

iotjs

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
iotjs Not in release Needs evaluation Not affected Ignored
Show less packages

CVE-2021-44988

Medium priority
Needs evaluation

Jerryscript v3.0.0 and below was discovered to contain a stack overflow via ecma_find_named_property in ecma-helpers.c.

1 affected package

iotjs

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
iotjs Not in release Needs evaluation Not affected Ignored
Show less packages

CVE-2022-22895

Medium priority
Needs evaluation

Jerryscript 3.0.0 was discovered to contain a heap-buffer-overflow via ecma_utf8_string_to_number_by_radix in /jerry-core/ecma/base/ecma-helpers-conversion.c.

1 affected package

iotjs

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
iotjs Not in release Needs evaluation Needs evaluation Ignored
Show less packages