Cesanta mjs v2.20.0 was discovered to contain a function pointer hijacking vulnerability via the function mjsgetptr(). This vulnerability allows attackers to execute arbitrary code via a crafted input.
Cesanta MJS 2.20.0 has a getpropbuiltinforeign out-of-bounds read if a Built-in API name occurs in a substring of an input string.
Cesanta MJS v2.20.0 was discovered to contain a heap buffer overflow via /usr/lib/x8664-linux-gnu/libasan.so.4+0xaff53.
Cesanta MJS v2.20.0 was discovered to contain a heap buffer overflow via mjsjprintf at src/mjsutil.c.
Cesanta MJS v2.20.0 was discovered to contain a global buffer overflow via snquote at src/mjsjson.c.
Cesanta MJS v2.20.0 was discovered to contain a heap buffer overflow via snquote at mjs/src/mjsjson.c.
Cesanta MJS v2.20.0 was discovered to contain a heap buffer overflow via mjsgetcstring at src/mjsstring.c.
Cesanta MJS v2.20.0 was discovered to contain a global buffer overflow via mjsmkstring at mjs/src/mjsstring.c.
Cesanta MJS v2.20.0 was discovered to contain a heap buffer overflow via mjsdisown at src/mjscore.c.
Cesanta MJS v2.20.0 was discovered to contain a heap buffer overflow via mjsarraylength at src/mjsarray.c.
Cesanta MJS v2.20.0 was discovered to contain a global buffer overflow via cvsnprintf at mjs/src/common/strutil.c.
Cesanta MJS v2.20.0 was discovered to contain a heap buffer overflow via tojsonordebug at mjs/src/mjsjson.c.
Cesanta MJS v2.20.0 was discovered to contain a heap-use-after-free via mjsapply at src/mjsexec.c.
Cesanta MJS v2.20.0 was discovered to contain a stack overflow via snquote at mjs/src/mjsjson.c.
An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs+0x4ec508 component.
An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjsopjsonparse function in the msj.c file.
An Out of Bounds Write in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjsopjsonstringify function in the msj.c file.
An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjsdestroy function in the msj.c file.
An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjsdogc function in the mjs.c file.
An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjsarraylength function in the mjs.c file.
A vulnerability was determined in Cesanta mJS up to 1.26. Affected is the function skipspacesandcomments of the file src/mjstok.c. Executing a manipulation can lead to heap-based buffer overflow. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.
Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via mjssetinternal at src/mjsobject.c. This vulnerability can lead to a Denial of Service (DoS).
Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via gccompactstrings at src/mjsgc.c. This vulnerability can lead to a Denial of Service (DoS).
Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via /usr/local/bin/mjs+0x2c6ae. This vulnerability can lead to a Denial of Service (DoS).
Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via addlinenomapitem at src/mjsbcode.c. This vulnerability can lead to a Denial of Service (DoS).
Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via /lib/x8664-linux-gnu/libc.so.6+0x18e810. This vulnerability can lead to a Denial of Service (DoS).
Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via /lib/x8664-linux-gnu/libc.so.6+0x4b44b. This vulnerability can lead to a Denial of Service (DoS).
Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via freejsonframe at src/mjsjson.c. This vulnerability can lead to a Denial of Service (DoS).
Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via /lib/x8664-linux-gnu/libc.so.6+0x45a1f. This vulnerability can lead to a Denial of Service (DoS).
Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via mjsprint at src/mjsbuiltin.c. This vulnerability can lead to a Denial of Service (DoS).