VYPR

Vendor CVEs

Cesanta

All CVEs

141 total · sorted by risk
  • CVE-2021-46510MedJan 27, 2022
    risk 0.36cvss 5.5epss 0.01

    There is an Assertion `s < mjs->owned_strings.buf + mjs->owned_strings.len' failed at src/mjs_gc.c in Cesanta MJS v2.20.0.

  • CVE-2021-46508MedJan 27, 2022
    risk 0.36cvss 5.5epss 0.01

    There is an Assertion `i < parts_cnt' failed at src/mjs_bcode.c in Cesanta MJS v2.20.0.

  • CVE-2020-36375MedMay 28, 2021
    risk 0.36cvss 5.5epss 0.01

    Stack overflow vulnerability in parse_equality Cesanta MJS 1.20.1, allows remote attackers to cause a Denial of Service (DoS) via a crafted file.

  • CVE-2020-36374MedMay 28, 2021
    risk 0.36cvss 5.5epss 0.01

    Stack overflow vulnerability in parse_comparison Cesanta MJS 1.20.1, allows remote attackers to cause a Denial of Service (DoS) via a crafted file.

  • CVE-2020-36373MedMay 28, 2021
    risk 0.36cvss 5.5epss 0.01

    Stack overflow vulnerability in parse_shifts Cesanta MJS 1.20.1, allows remote attackers to cause a Denial of Service (DoS) via a crafted file.

  • CVE-2020-36372MedMay 28, 2021
    risk 0.36cvss 5.5epss 0.01

    Stack overflow vulnerability in parse_plus_minus Cesanta MJS 1.20.1, allows remote attackers to cause a Denial of Service (DoS) via a crafted file.

  • CVE-2020-36371MedMay 28, 2021
    risk 0.36cvss 5.5epss 0.01

    Stack overflow vulnerability in parse_mul_div_rem Cesanta MJS 1.20.1, allows remote attackers to cause a Denial of Service (DoS) via a crafted file.

  • CVE-2020-36370MedMay 28, 2021
    risk 0.36cvss 5.5epss 0.01

    Stack overflow vulnerability in parse_unary Cesanta MJS 1.20.1, allows remote attackers to cause a Denial of Service (DoS) via a crafted file.

  • CVE-2020-36369MedMay 28, 2021
    risk 0.36cvss 5.5epss 0.01

    Stack overflow vulnerability in parse_statement_list Cesanta MJS 1.20.1, allows remote attackers to cause a Denial of Service (DoS) via a crafted file.

  • CVE-2020-36368MedMay 28, 2021
    risk 0.36cvss 5.5epss 0.01

    Stack overflow vulnerability in parse_statement Cesanta MJS 1.20.1, allows remote attackers to cause a Denial of Service (DoS) via a crafted file.

  • CVE-2020-36367MedMay 28, 2021
    risk 0.36cvss 5.5epss 0.01

    Stack overflow vulnerability in parse_block Cesanta MJS 1.20.1, allows remote attackers to cause a Denial of Service (DoS) via a crafted file.

  • CVE-2020-36366MedMay 28, 2021
    risk 0.36cvss 5.5epss 0.01

    Stack overflow vulnerability in parse_value Cesanta MJS 1.20.1, allows remote attackers to cause a Denial of Service (DoS) via a crafted file.

  • CVE-2020-18392MedMay 28, 2021
    risk 0.36cvss 5.5epss 0.01

    Stack overflow vulnerability in parse_array Cesanta MJS 1.20.1, allows remote attackers to cause a Denial of Service (DoS) via a crafted file.

  • CVE-2025-0696MedJan 27, 2025
    risk 0.34cvss 5.3epss 0.00

    A NULL Pointer Dereference vulnerability in Cesanta Frozen versions less than 1.7 allows an attacker to induce a crash of the component embedding the library by supplying a maliciously crafted JSON as input.

  • CVE-2025-0695MedJan 27, 2025
    risk 0.34cvss 5.3epss 0.00

    An Allocation of Resources Without Limits or Throttling vulnerability in Cesanta Frozen versions less than 1.7 allows an attacker to induce a crash of the component embedding the library by supplying a maliciously crafted JSON as input.

  • CVE-2024-42389MedNov 18, 2024
    risk 0.34cvss 5.3epss 0.00

    Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space.

  • CVE-2024-42388MedNov 18, 2024
    risk 0.34cvss 5.3epss 0.00

    Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space.

  • CVE-2024-42387MedNov 18, 2024
    risk 0.34cvss 5.3epss 0.00

    Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space.

  • CVE-2026-5246MedApr 2, 2026
    risk 0.29cvss 5.6epss 0.01

    A vulnerability was determined in Cesanta Mongoose up to 7.20. Affected is the function mg_tls_verify_cert_signature of the file mongoose.c of the component P-384 Public Key Handler. Executing a manipulation can lead to authorization bypass. The attack can be executed remotely.…

  • CVE-2026-5245MedApr 2, 2026
    risk 0.29cvss 5.6epss 0.01

    A vulnerability was found in Cesanta Mongoose up to 7.20. This impacts the function handle_mdns_record of the file mongoose.c of the component mDNS Record Handler. Performing a manipulation of the argument buf results in stack-based buffer overflow. Remote exploitation of the…

  • CVE-2024-42391MedNov 18, 2024
    risk 0.28cvss 4.3epss 0.00

    Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space.

  • CVE-2024-42390MedNov 18, 2024
    risk 0.28cvss 4.3epss 0.00

    Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space.

  • CVE-2024-35385MedMay 21, 2024
    risk 0.28cvss 4.3epss 0.01

    An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_mk_ffi_sig function in the mjs.c file.

  • CVE-2026-6985MedApr 25, 2026
    risk 0.27cvss 5.3epss 0.01

    A weakness has been identified in Cesanta Mongoose up to 7.20. This vulnerability affects the function handle_opt of the file /src/net_builtin.c of the component TCP Option Handler. This manipulation of the argument optlen causes infinite loop. The attack is possible to be…

  • CVE-2024-42383MedNov 18, 2024
    risk 0.27cvss 4.2epss 0.00

    Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows to write a NULL byte value beyond the memory space dedicated for the hostname field.

  • CVE-2024-42392MedNov 18, 2024
    risk 0.26cvss 4.0epss 0.00

    Improper Neutralization of Delimiters vulnerability in Cesanta Mongoose Web Server v7.14 allows to trigger an infinite loop bug if the input string contains unexpected characters.

  • CVE-2024-42385MedNov 18, 2024
    risk 0.26cvss 4.0epss 0.00

    Improper Neutralization of Delimiters vulnerability in Cesanta Mongoose Web Server v7.14 allows to trigger an out-of-bound memory write if the PEM certificate contains unexpected characters.

  • CVE-2026-2968LowFeb 23, 2026
    risk 0.24cvss 3.7epss 0.00

    A vulnerability was detected in Cesanta Mongoose up to 7.20. This impacts the function mg_chacha20_poly1305_decrypt of the file /src/tls_chacha20.c of the component Poly1305 Authentication Tag Handler. The manipulation results in improper verification of cryptographic signature.…

  • CVE-2026-2967LowFeb 23, 2026
    risk 0.24cvss 3.7epss 0.00

    A security vulnerability has been detected in Cesanta Mongoose up to 7.20. This affects the function getpeer of the file /src/net_builtin.c of the component TCP Sequence Number Handler. The manipulation leads to improper verification of source of a communication channel. The…

  • CVE-2026-2966LowFeb 23, 2026
    risk 0.24cvss 3.7epss 0.00

    A weakness has been identified in Cesanta Mongoose up to 7.20. The impacted element is the function mg_sendnsreq of the file /src/dns.c of the component DNS Transaction ID Handler. Executing a manipulation of the argument random can lead to insufficiently random values. The…

  • CVE-2023-30421LowApr 19, 2025
    risk 0.19cvss 2.9epss 0.00

    mystrtod in mjson 1.2.7 requires more than a billion iterations during processing of certain digit strings such as 8891110122900e913013935755114.

  • CVE-2026-6986LowApr 25, 2026
    risk 0.17cvss 3.7epss 0.00

    A security vulnerability has been detected in Cesanta Mongoose up to 7.20. This issue affects the function mg_aes_gcm_decrypt of the file /src/tls_aes128.c of the component GCM Authentication Tag Handler. Such manipulation leads to improper verification of cryptographic…

  • CVE-2025-65502MedNov 24, 2025
    risk 0.00cvss 4.3epss 0.00

    Null pointer dereference in add_ca_certs() in Cesanta Mongoose before 7.2 allows remote attackers to cause a denial of service via TLS initialization where SSL_CTX_get_cert_store() returns NULL.

  • CVE-2025-51495HigSep 29, 2025
    risk 0.00cvss 7.5epss 0.00

    An integer overflow vulnerability exists in the WebSocket component of Mongoose 7.5 thru 7.17. By sending a specially crafted WebSocket request, an attacker can cause the application to crash. If downstream vendors integrate this component improperly, the issue may lead to a…

  • CVE-2023-50044CriDec 20, 2023
    risk 0.00cvss 9.8epss 0.01

    Cesanta MJS 2.20.0 has a getprop_builtin_foreign out-of-bounds read if a Built-in API name occurs in a substring of an input string.

  • CVE-2023-2905HigAug 9, 2023
    risk 0.00cvss 8.8epss 0.01

    Due to a failure in validating the length of a provided MQTT_CMD_PUBLISH parsed message with a variable length header, Cesanta Mongoose, an embeddable web server, version 7.10 is susceptible to a heap-based buffer overflow vulnerability in the default configuration. Version…

  • CVE-2023-34188HigJun 23, 2023
    risk 0.00cvss 7.5epss 0.01

    The HTTP server in Mongoose before 7.10 accepts requests containing negative Content-Length headers. By sending a single attack payload over TCP, an attacker can cause an infinite loop in which the server continuously reparses that payload, and does not respond to any other…

  • CVE-2022-25299CriFeb 18, 2022
    risk 0.00cvss 9.8epss 0.01

    This affects the package cesanta/mongoose before 7.6. The unsafe handling of file names during upload using mg_http_upload() method may enable attackers to write files to arbitrary locations outside the designated target folder.

  • CVE-2021-31875CriApr 29, 2021
    risk 0.00cvss 9.8epss 0.02

    In mjs_json.c in Cesanta MongooseOS mJS 1.26, a maliciously formed JSON string can trigger an off-by-one heap-based buffer overflow in mjs_json_parse, which can potentially lead to redirection of control flow. NOTE: the original reporter disputes the significance of this finding…

  • CVE-2019-13503HigJul 11, 2019
    risk 0.00cvss 7.5epss 0.01

    mq_parse_http in mongoose.c in Mongoose 6.15 has a heap-based buffer over-read.

  • CVE-2019-12951CriJun 24, 2019
    risk 0.00cvss 9.8epss 0.02

    An issue was discovered in Mongoose before 6.15. The parse_mqtt() function in mg_mqtt.c has a critical heap-based buffer overflow.

Page 3 of 3