Buffer-overflow in jsdtoa.c in Artifex MuJS in versions 1.0.1 to 1.1.1. An integer overflow happens when js_strtod() reads in floating point exponent, which leads to a buffer overflow in the pointer *d.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HArtifex Mujs
APPArtifex1.0.1 – 1.1.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Memory
Related vulnerabilities
CVE-2021-33796CRITICAL10.0PL ✓same product
Use-after-free w MuJS — błąd dostępu do właściwości source wyrażenia regularnego
CVE-2021-45005CRITICAL9.8PL ✓same product
Heap buffer overflow w Artifex MuJS — zagnieżdżone bloki try/finally
CVE-2019-12798CRITICAL9.8PL ✓same product
Przepełnienie bufora w MuJS 1.0.5 przez nieograniczony rozmiar wyrażenia regularnego
CVE-2019-11411CRITICAL9.8PL ✓same product
Stack-based buffer overflow w Artifex MuJS — funkcje Number#toFixed() i numtostr
CVE-2016-10133CRITICAL9.8PL ✓same product
Heap-based buffer overflow w MuJS — przepełnienie bufora na stercie