VYPR

Jerryscript

by Jerryscript

Source repositories

CVEs (98)

  • CVE-2021-46345MedJan 20, 2022
    risk 0.36cvss 5.5epss 0.01

    There is an Assertion 'cesu8_cursor_p == cesu8_end_p' failed at /jerry-core/lit/lit-strings.c in JerryScript 3.0.0.

  • CVE-2021-46344MedJan 20, 2022
    risk 0.36cvss 5.5epss 0.01

    There is an Assertion 'flags & PARSER_PATTERN_HAS_REST_ELEMENT' failed at /jerry-core/parser/js/js-parser-expr.c in JerryScript 3.0.0.

  • CVE-2021-46343MedJan 20, 2022
    risk 0.36cvss 5.5epss 0.01

    There is an Assertion 'context_p->token.type == LEXER_LITERAL' failed at /jerry-core/parser/js/js-parser-expr.c in JerryScript 3.0.0.

  • CVE-2021-46342MedJan 20, 2022
    risk 0.36cvss 5.5epss 0.01

    There is an Assertion 'ecma_is_lexical_environment (obj_p) || !ecma_op_object_is_fast_array (obj_p)' failed at /jerry-core/ecma/base/ecma-helpers.c in JerryScript 3.0.0.

  • CVE-2021-46340MedJan 20, 2022
    risk 0.36cvss 5.5epss 0.01

    There is an Assertion 'context_p->stack_top_uint8 == SCAN_STACK_TRY_STATEMENT || context_p->stack_top_uint8 == SCAN_STACK_CATCH_STATEMENT' failed at /parser/js/js-scanner.c(scanner_scan_statement_end) in JerryScript 3.0.0.

  • CVE-2021-46339MedJan 20, 2022
    risk 0.36cvss 5.5epss 0.01

    There is an Assertion 'lit_is_valid_cesu8_string (string_p, string_size)' failed at /base/ecma-helpers-string.c(ecma_new_ecma_string_from_utf8) in JerryScript 3.0.0.

  • CVE-2021-46338MedJan 20, 2022
    risk 0.36cvss 5.5epss 0.01

    There is an Assertion 'ecma_is_lexical_environment (object_p)' failed at /base/ecma-helpers.c(ecma_get_lex_env_type) in JerryScript 3.0.0.

  • CVE-2021-46337MedJan 20, 2022
    risk 0.36cvss 5.5epss 0.01

    There is an Assertion 'page_p != NULL' failed at /parser/js/js-parser-mem.c(parser_list_get) in JerryScript 3.0.0.

  • CVE-2021-46336MedJan 20, 2022
    risk 0.36cvss 5.5epss 0.01

    There is an Assertion 'opts & PARSER_CLASS_LITERAL_CTOR_PRESENT' failed at /parser/js/js-parser-expr.c(parser_parse_class_body) in JerryScript 3.0.0.

  • CVE-2024-33260MedApr 26, 2024
    risk 0.33cvss 5.1epss 0.00

    Jerryscript commit cefd391 was discovered to contain a segmentation violation via the component parser_parse_class at jerry-core/parser/js/js-parser-expr.c

  • CVE-2024-29489MedMar 28, 2024
    risk 0.00cvss 5.5epss 0.00

    Jerryscript 2.4.0 has SEGV at ./jerry-core/ecma/base/ecma-helpers.c:238:58 in ecma_get_object_type.

  • CVE-2021-42863CriMay 12, 2022
    risk 0.00cvss 9.8epss 0.02

    A buffer overflow in ecma_builtin_typedarray_prototype_filter() in JerryScript version fe3a5c0 allows an attacker to construct a fake object or a fake arraybuffer with unlimited size.

  • CVE-2021-41959HigMay 3, 2022
    risk 0.00cvss 7.5epss 0.01

    JerryScript Git version 14ff5bf does not sufficiently track and release allocated memory via jerry-core/ecma/operations/ecma-regexp-object.c after RegExp, which causes a memory leak.

  • CVE-2021-41751CriApr 5, 2022
    risk 0.00cvss 9.8epss 0.01

    Buffer overflow vulnerability in file ecma-builtin-array-prototype.c:909 in function ecma_builtin_array_prototype_object_slice in Jerryscript before commit e1ce7dd7271288be8c0c8136eea9107df73a8ce2 on Oct 20, 2021.

  • CVE-2020-13991HigSep 24, 2020
    risk 0.00cvss 7.5epss 0.02

    vm/opcodes.c in JerryScript 2.2.0 allows attackers to hijack the flow of control by controlling a register.

  • CVE-2020-14163HigJun 15, 2020
    risk 0.00cvss 7.5epss 0.01

    An issue was discovered in ecma/operations/ecma-container-object.c in JerryScript 2.2.0. Operations with key/value pairs did not consider the case where garbage collection is triggered after the key operation but before the value operation, as demonstrated by improper read…

  • CVE-2020-13649HigMay 28, 2020
    risk 0.00cvss 7.5epss 0.02

    parser/js/js-scanner.c in JerryScript 2.2.0 mishandles errors during certain out-of-memory conditions, as demonstrated by a scanner_reverse_info_list NULL pointer dereference and a scanner_scan_all assertion failure.

  • CVE-2020-13622HigMay 27, 2020
    risk 0.00cvss 7.5epss 0.01

    JerryScript 2.2.0 allows attackers to cause a denial of service (assertion failure) because a property key query for a Proxy object returns unintended data.

Page 5 of 5