Nginx NJS v0.7.2 was discovered to contain a heap-use-after-free bug caused by illegal memory copy in the function njsjsonparseiteratorcall at njsjson.c.
DISPUTED Nginx NJS v0.7.2 to v0.7.4 was discovered to contain a segmentation violation via njsscopevalidvalue at njsscope.h. NOTE: the vendor disputes the significance of this report because NJS does not operate on untrusted input.
Nginx NJS v0.7.2 was discovered to contain a segmentation violation in the function njsvmcodeinterpreter at src/njsvmcode.c.
Nginx NJS v0.7.2 was discovered to contain a segmentation violation in the function njsarrayconverttoslowarray at src/njsarray.c.
Nginx NJS v0.7.2 was discovered to contain a segmentation violation in the function njsstringoffset at src/njsstring.c.
Nginx NJS v0.7.2 was discovered to contain a segmentation violation via njslvlhshbucketfind at njslvlhsh.c.
NGINX NJS 0.7.2 was discovered to contain a NULL pointer dereference via the component njsvmcodearray at /src/njsvmcode.c.
nginx njs 0.7.2 is affected suffers from Use-after-free in njsfunctionframealloc() when it try to invoke from a restored frame saved with njsfunctionframesave().
nginx njs 0.7.2 is vulnerable to Buffer Overflow. Type confused in Array.prototype.concat() when a slow array appended element is fast array.