VYPR

Espruino

by Espruino

Source repositories

CVEs (23)

  • CVE-2018-11590MedMay 31, 2018
    risk 0.36cvss 5.5epss 0.01

    Espruino before 1.99 allows attackers to cause a denial of service (application crash) with a user crafted input file via an integer overflow during syntax parsing. This was addressed by fixing stack size detection on Linux in jsutils.c.

  • CVE-2026-88389MedSep 25, 2026
    risk 0.33cvss 6.2epss 0.00

    Espruino 2v29 (commit bffc6d0) contains a NULL pointer dereference vulnerability in jslGetRawString() in src/jslex.c. Crafted raw/binary string input can cause the lexer to pass a NULL iterator target to jsvLockAgain(). In RELEASE/NO_ASSERT builds, the missing assertion guard…

  • CVE-2022-25044HigMar 5, 2022
    risk 0.00cvss 7.8epss 0.01

    Espruino 2v11.251 was discovered to contain a stack buffer overflow via src/jsvar.c in jsvNewFromString.

Page 2 of 2