Search CVE reports
1 – 10 of 96 results
CVE-2024-33260
Medium priorityJerryscript commit cefd391 was discovered to contain a segmentation violation via the component parser_parse_class at jerry-core/parser/js/js-parser-expr.c
1 affected package
iotjs
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
iotjs | Not in release | Needs evaluation | Not in release | Needs evaluation | — |
CVE-2024-33259
Medium priorityJerryscript commit cefd391 was discovered to contain a segmentation violation via the component scanner_seek at jerry-core/parser/js/js-scanner-util.c.
1 affected package
iotjs
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
iotjs | Not in release | Needs evaluation | Not in release | Needs evaluation | — |
CVE-2024-33258
Medium priorityJerryscript commit ff9ff8f was discovered to contain a segmentation violation via the component vm_loop at jerry-core/vm/vm.c.
1 affected package
iotjs
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
iotjs | Not in release | Needs evaluation | Not in release | Needs evaluation | — |
CVE-2024-33255
Medium priorityJerryscript commit cefd391 was discovered to contain an Assertion Failure via ECMA_STRING_IS_REF_EQUALS_TO_ONE (string_p) in ecma_free_string_list.
1 affected package
iotjs
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
iotjs | Not in release | Needs evaluation | Not in release | Needs evaluation | — |
CVE-2024-29489
Medium priorityJerryscript 2.4.0 has SEGV at ./jerry-core/ecma/base/ecma-helpers.c:238:58 in ecma_get_object_type.
1 affected package
iotjs
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
iotjs | Not in release | Needs evaluation | Not in release | Needs evaluation | — |
CVE-2023-36109
Medium priorityBuffer Overflow vulnerability in JerryScript version 3.0, allows remote attackers to execute arbitrary code via ecma_stringbuilder_append_raw component at /jerry-core/ecma/base/ecma-helpers-string.c.
1 affected package
iotjs
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
iotjs | Not in release | Needs evaluation | Not in release | Needs evaluation | Ignored |
CVE-2023-38961
Medium priorityBuffer Overflwo vulnerability in JerryScript Project jerryscript v.3.0.0 allows a remote attacker to execute arbitrary code via the scanner_is_context_needed component in js-scanner-until.c.
1 affected package
iotjs
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
iotjs | Not in release | Needs evaluation | Not in release | Needs evaluation | Ignored |
CVE-2020-24187
Medium priorityAn issue was discovered in ecma-helpers.c in jerryscript version 2.3.0, allows local attackers to cause a denial of service (DoS) (Null Pointer Dereference).
1 affected package
iotjs
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
iotjs | Not in release | Needs evaluation | Not in release | Needs evaluation | Ignored |
CVE-2023-36201
Medium priorityAn issue in JerryscriptProject jerryscript v.3.0.0 allows an attacker to obtain sensitive information via a crafted script to the arrays.
1 affected package
iotjs
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
iotjs | Not in release | Needs evaluation | Not in release | Needs evaluation | Ignored |
CVE-2020-22597
Medium priorityAn issue in Jerrscript- project Jerryscrip v. 2.3.0 allows a remote attacker to execute arbitrary code via the ecma_builtin_array_prototype_object_slice parameter.
1 affected package
iotjs
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
iotjs | Not in release | Needs evaluation | Not in release | Needs evaluation | Ignored |