Логотип exploitDog
bind:CVE-2022-35289
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-35289

Количество 3

Количество 3

nvd логотип

CVE-2022-35289

больше 3 лет назад

A write-what-where condition in hermes caused by an integer overflow, prior to commit 5b6255ae049fa4641791e47fad994e8e8c4da374 allows attackers to potentially execute arbitrary code via crafted JavaScript. Note that this is only exploitable if the application using Hermes permits evaluation of untrusted JavaScript. Hence, most React Native applications are not affected.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-mc36-3fhx-66vv

больше 3 лет назад

A write-what-where condition in hermes caused by an integer overflow, prior to commit 5b6255ae049fa4641791e47fad994e8e8c4da374 allows attackers to potentially execute arbitrary code via crafted JavaScript. Note that this is only exploitable if the application using Hermes permits evaluation of untrusted JavaScript. Hence, most React Native applications are not affected.

CVSS3: 9.8
EPSS: Низкий
fstec логотип

BDU:2022-06219

больше 3 лет назад

Уязвимость JavaScript-движка Hermes JS, связана с переполнением буфера, позволяющая нарушителю выполнить произвольный код

CVSS3: 7.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-35289

A write-what-where condition in hermes caused by an integer overflow, prior to commit 5b6255ae049fa4641791e47fad994e8e8c4da374 allows attackers to potentially execute arbitrary code via crafted JavaScript. Note that this is only exploitable if the application using Hermes permits evaluation of untrusted JavaScript. Hence, most React Native applications are not affected.

CVSS3: 9.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-mc36-3fhx-66vv

A write-what-where condition in hermes caused by an integer overflow, prior to commit 5b6255ae049fa4641791e47fad994e8e8c4da374 allows attackers to potentially execute arbitrary code via crafted JavaScript. Note that this is only exploitable if the application using Hermes permits evaluation of untrusted JavaScript. Hence, most React Native applications are not affected.

CVSS3: 9.8
2%
Низкий
больше 3 лет назад
fstec логотип
BDU:2022-06219

Уязвимость JavaScript-движка Hermes JS, связана с переполнением буфера, позволяющая нарушителю выполнить произвольный код

CVSS3: 7.3
2%
Низкий
больше 3 лет назад

Уязвимостей на страницу