Where
AND
-Infinity
0
Severity
9.8
AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L

Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows to write a NULL byte value beyond the memory space dedicated for the hostname field.

Remedy

It is suggested to update the Mongoose Web Server library to v7.15.
First published (updated )
Severity
8.2
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H

Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and produce a segmentation fault on the application.

Remedy

It is suggested to update the Mongoose Web Server library to v7.15.
First published (updated )
Severity
7.5
AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:H

Improper Neutralization of Delimiters vulnerability in Cesanta Mongoose Web Server v7.14 allows to trigger an infinite loop bug if the input string contains unexpected characters.

Remedy

It is suggested to update the Mongoose Web Server library to v7.15.
First published (updated )
Severity
7
AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:H

Improper Neutralization of Delimiters vulnerability in Cesanta Mongoose Web Server v7.14 allows to trigger an out-of-bound memory write if the PEM certificate contains unexpected characters.

Remedy

It is suggested to update the Mongoose Web Server library to v7.15.
First published (updated )
Severity
5.3
AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space.

Remedy

It is suggested to update the Mongoose Web Server library to v7.15.
First published (updated )
Severity
5.3
AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space.

Remedy

It is suggested to update the Mongoose Web Server library to v7.15.
First published (updated )
Severity
5.3
AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space.

Remedy

It is suggested to update the Mongoose Web Server library to v7.15.
First published (updated )
Severity
5.3
AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space.

Remedy

It is suggested to update the Mongoose Web Server library to v7.15.
First published (updated )
Severity
5.3
AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space.

Remedy

It is suggested to update the Mongoose Web Server library to v7.15.
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203