VYPR
Critical severity9.8NVD Advisory· Published Jul 24, 2019· Updated Jun 17, 2026

CVE-2019-1010177

CVE-2019-1010177

Description

Jsish 2.4.70 2.047 is affected by: Use After Free. The impact is: denial of service and possibly arbitrary code execution. The component is: function Jsi_RegExpNew (jsi/jsiRegexp.c:39). The attack vector is: executing crafted javascript code. The fixed version is: after commit 48a66c798d.

Affected products

3
  • Jsish/Jsiv5
    Range: 2.4.70 2.047 [fixed: after commit 48a66c798d]
  • Jsish/Jsishllm-fuzzy2 versions
    <=2.4.70 2.047+ 1 more
    • (no CPE)range: <=2.4.70 2.047
    • cpe:2.3:a:jsish:jsish:2.4.70_2.047:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.