VYPR

Quickjs

by Quickjs Ng

Source repositories

CVEs (23)

  • CVE-2025-46687MedApr 27, 2025
    risk 0.00cvss 5.6epss 0.00

    quickjs-ng through 0.9.0 has a missing length check in JS_ReadString for a string, leading to a heap-based buffer overflow. QuickJS before 2025-04-26 is also affected.

  • CVE-2024-13903MedMar 21, 2025
    risk 0.00cvss 4.3epss 0.01

    A vulnerability was found in quickjs-ng QuickJS up to 0.8.0. It has been declared as problematic. Affected by this vulnerability is the function JS_GetRuntime of the file quickjs.c of the component qjs. The manipulation leads to stack-based buffer overflow. The attack can be…

  • CVE-2023-48183HigApr 23, 2024
    risk 0.00cvss 7.5epss 0.01

    QuickJS before c4cdd61 has a build_for_in_iterator NULL pointer dereference because of an erroneous lexical scope of "this" with eval.

Page 2 of 2