Описание
Espruino before 1.99 allows attackers to cause a denial of service (application crash) and a potential Information Disclosure with user crafted input files via a Buffer Overflow or Out-of-bounds Read during syntax parsing of certain for loops in jsparse.c.
Ссылки
- PatchVendor Advisory
- ExploitVendor Advisory
- ExploitVendor Advisory
- ExploitVendor Advisory
- Issue TrackingVendor Advisory
- PatchVendor Advisory
- ExploitVendor Advisory
- ExploitVendor Advisory
- ExploitVendor Advisory
- Issue TrackingVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.99 (исключая)
cpe:2.3:o:espruino:espruino:*:*:*:*:*:*:*:*
EPSS
Процентиль: 51%
0.0028
Низкий
7.1 High
CVSS3
5.8 Medium
CVSS2
Дефекты
CWE-125
Связанные уязвимости
CVSS3: 7.1
github
больше 3 лет назад
Espruino before 1.99 allows attackers to cause a denial of service (application crash) and a potential Information Disclosure with user crafted input files via a Buffer Overflow or Out-of-bounds Read during syntax parsing of certain for loops in jsparse.c.
EPSS
Процентиль: 51%
0.0028
Низкий
7.1 High
CVSS3
5.8 Medium
CVSS2
Дефекты
CWE-125