Количество 2
Количество 2
CVE-2021-24044
By passing invalid javascript code where await and yield were called upon non-async and non-generator getter/setter functions, Hermes would invoke generator functions and error out on invalid await/yield positions. This could result in segmentation fault as a consequence of type confusion error, with a low chance of RCE. This issue affects Hermes versions prior to v0.10.0.
GHSA-7mhc-prgv-r3q4
Access of Resource Using Incompatible Type in Hermes
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2021-24044 By passing invalid javascript code where await and yield were called upon non-async and non-generator getter/setter functions, Hermes would invoke generator functions and error out on invalid await/yield positions. This could result in segmentation fault as a consequence of type confusion error, with a low chance of RCE. This issue affects Hermes versions prior to v0.10.0. | CVSS3: 9.8 | 1% Низкий | около 4 лет назад | |
GHSA-7mhc-prgv-r3q4 Access of Resource Using Incompatible Type in Hermes | CVSS3: 9.8 | 1% Низкий | около 4 лет назад |
Уязвимостей на страницу