VYPR
Vendor

Espruino

Products
1
CVEs
10
Across products
10
Status
Private

Products

1

Recent CVEs

10
  • CVE-2018-20201Dec 18, 2018
    risk 0.00cvss epss 0.00

    There is a stack-based buffer over-read in the jsfNameFromString function of jsflash.c in Espruino 2V00, leading to a denial of service or possibly unspecified other impact via a crafted js file.

  • CVE-2018-11590May 31, 2018
    risk 0.00cvss epss 0.00

    Espruino before 1.99 allows attackers to cause a denial of service (application crash) with a user crafted input file via an integer overflow during syntax parsing. This was addressed by fixing stack size detection on Linux in jsutils.c.

  • CVE-2018-11593May 31, 2018
    risk 0.00cvss epss 0.00

    Espruino before 1.99 allows attackers to cause a denial of service (application crash) and potential Information Disclosure with a user crafted input file via a Buffer Overflow during syntax parsing because strncpy is misused in jslex.c.

  • CVE-2018-11594May 31, 2018
    risk 0.00cvss epss 0.00

    Espruino before 1.99 allows attackers to cause a denial of service (application crash) with a user crafted input file via a Buffer Overflow during syntax parsing of "VOID" tokens in jsparse.c.

  • CVE-2018-11597May 31, 2018
    risk 0.00cvss epss 0.00

    Espruino before 1.99 allows attackers to cause a denial of service (application crash) with a user crafted input file via a Buffer Overflow during syntax parsing because of a missing check for stack exhaustion with many '{' characters in jsparse.c.

  • CVE-2018-11591May 31, 2018
    risk 0.00cvss epss 0.00

    Espruino before 1.98 allows attackers to cause a denial of service (application crash) with a user crafted input file via a NULL pointer dereference during syntax parsing. This was addressed by adding validation for a debug trace print statement in jsvar.c.

  • CVE-2018-11598May 31, 2018
    risk 0.00cvss epss 0.00

    Espruino before 1.99 allows attackers to cause a denial of service (application crash) and a potential Information Disclosure with user crafted input files via a Buffer Overflow or Out-of-bounds Read during syntax parsing of certain for loops in jsparse.c.

  • CVE-2018-11596May 31, 2018
    risk 0.00cvss epss 0.00

    Espruino before 1.99 allows attackers to cause a denial of service (application crash) with a user crafted input file via a Buffer Overflow during syntax parsing because a check for '\0' is made for the wrong array element in jsvar.c.

  • CVE-2018-11595May 31, 2018
    risk 0.00cvss epss 0.00

    Espruino before 1.99 allows attackers to cause a denial of service (application crash) and a potential Escalation of Privileges with a user crafted input file via a Buffer Overflow during syntax parsing, because strncat is misused.

  • CVE-2018-11592May 31, 2018
    risk 0.00cvss epss 0.00

    Espruino before 1.98 allows attackers to cause a denial of service (application crash) with a user crafted input file via an Out-of-bounds Read during syntax parsing in which certain height validation is missing in libs/graphics/jswrap_graphics.c.