Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2722▼ 6 respecto a la semana anterior
Críticas / altas1451▲ 315 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
–

31 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.34%—Artifex MujsAI24/9/202625/9/2026
MuJS e892c9fdb contains an incorrect numeric conversion vulnerability in jsR_isindex() in jsrun.c. A specially crafted JavaScript input containing an excessively large numeric array index can cause an out-of-range floating-point value to be converted to an integer without proper range validation. This results in…
ModificadaAlta (7.5)0.71%—Artifex Mujs7/7/202317/6/2026
In MuJS before version 1.1.2, a use-after-free flaw in the regexp source property access may cause denial of service.
ModificadaCrítica (9.8)0.81%—Artifex Mujs17/4/202317/6/2026
Buffer-overflow in jsdtoa.c in Artifex MuJS in versions 1.0.1 to 1.1.1. An integer overflow happens when js_strtod() reads in floating point exponent, which leads to a buffer overflow in the pointer *d.
ModificadaAlta (8.8)2.5%—Artifex MujsDebian LinuxFedoraproject Fedora23/11/202217/6/2026
A logical issue in O_getOwnPropertyDescriptor() in Artifex MuJS 1.0.0 through 1.3.x before 1.3.2 allows an attacker to achieve Remote Code Execution through memory corruption, via the loading of a crafted JavaScript file.
ModificadaMedia (5.5)1.1%—Artifex MujsDebian LinuxFedoraproject Fedora18/5/202217/6/2026
In Artifex MuJS through 1.2.0, jsP_dumpsyntax in jsdump.c has a NULL pointer dereference, as demonstrated by mujs-pp.
ModificadaMedia (5.5)1.1%—Artifex MujsDebian LinuxFedoraproject Fedora18/5/202217/6/2026
compile in regexp.c in Artifex MuJS through 1.2.0 results in stack consumption because of unlimited recursion, a different issue than CVE-2019-11413.
ModificadaCrítica (9.8)1.4%—Artifex Mujs14/2/202217/6/2026
Artifex MuJS v1.1.3 was discovered to contain a heap buffer overflow which is caused by conflicting JumpList of nested try/finally statements.
ModificadaAlta (7.5)1.6%—Artifex Mujs13/7/202117/6/2026
Buffer overflow vulnerability in function jsG_markobject in jsgc.c in mujs before 1.0.8, allows remote attackers to cause a denial of service.
ModificadaAlta (7.5)1.6%—Artifex Mujs13/7/202117/6/2026
Buffer overflow vulnerability in mujs before 1.0.8 due to recursion in the GC scanning phase, allows remote attackers to cause a denial of service.
ModificadaAlta (7.8)0.83%—Artifex Mujs13/8/202017/6/2026
Artifex MuJS through 1.0.7 has a use-after-free in jsrun.c because of unconditional marking in jsgc.c.
ModificadaCrítica (9.8)1.7%—Artifex Mujs13/6/201917/6/2026
An issue was discovered in Artifex MuJS 1.0.5. regcompx in regexp.c does not restrict regular expression program size, leading to an overflow of the parsed syntax list size.
ModificadaAlta (7.5)2.3%—Artifex Mujs22/4/201917/6/2026
An issue was discovered in Artifex MuJS 1.0.5. It has unlimited recursion because the match function in regexp.c lacks a depth check.
ModificadaAlta (7.5)2.1%—Artifex MujsFedoraproject Fedora22/4/201917/6/2026
An issue was discovered in Artifex MuJS 1.0.5. jscompile.c can cause a denial of service (invalid stack-frame jump) because it lacks an ENDTRY opcode call.
ModificadaCrítica (9.8)3.3%—Artifex Mujs22/4/201917/6/2026
An issue was discovered in Artifex MuJS 1.0.5. The Number#toFixed() and numtostr implementations in jsnumber.c have a stack-based buffer overflow.
ModificadaMedia (5.5)5.2%—Artifex Mujs24/1/201817/6/2026
The js_strtod function in jsdtoa.c in Artifex MuJS through 1.0.2 has an integer overflow because of incorrect exponent validation.
ModificadaMedia (5.5)5.1%—Artifex Mujs24/1/201817/6/2026
jsparse.c in Artifex MuJS through 1.0.2 does not properly maintain the AST depth for binary expressions, which allows remote attackers to cause a denial of service (excessive recursion) via a crafted file.
ModificadaCrítica (9.8)2.4%—Artifex Mujs24/3/201717/6/2026
Heap-based buffer overflow in the js_stackoverflow function in jsrun.c in Artifex Software, Inc. MuJS allows attackers to have unspecified impact by leveraging an error when dropping extra arguments to lightweight functions.
ModificadaAlta (7.5)2.2%—Artifex MujsFedoraproject Fedora24/3/201717/6/2026
regexp.c in Artifex Software, Inc. MuJS allows attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to regular expression compilation.
ModificadaAlta (7.5)2.8%—Fedoraproject FedoraArtifex Mujs3/2/201717/6/2026
Integer overflow in the js_regcomp function in regexp.c in Artifex Software, Inc. MuJS before commit b6de34ac6d8bb7dd5461c57940acfbd3ee7fd93e allows attackers to cause a denial of service (application crash) via a crafted regular expression.
ModificadaAlta (7.8)1.0%—Artifex Mujs30/1/201717/6/2026
An issue was discovered in Artifex Software, Inc. MuJS before 8f62ea10a0af68e56d5c00720523ebcba13c2e6a. The MakeDay function in jsdate.c does not validate the month, leading to an integer overflow when parsing a specially crafted JS file.
ModificadaAlta (7.8)1.3%—Artifex Mujs30/1/201717/6/2026
An issue was discovered in Artifex Software, Inc. MuJS before 4006739a28367c708dea19aeb19b8a1a9326ce08. The jsR_setproperty function in jsrun.c lacks a check for a negative array length. This leads to an integer overflow in the js_pushstring function in jsrun.c when parsing a specially crafted JS file.
ModificadaAlta (7.5)2.2%—Artifex Mujs18/1/201717/6/2026
Artifex Software MuJS allows attackers to cause a denial of service (crash) via vectors related to incomplete escape sequences. NOTE: this vulnerability exists due to an incomplete fix for CVE-2016-7563.
ModificadaAlta (7.5)1.7%—Artifex Mujs18/1/201717/6/2026
Heap-based buffer overflow in the Fp_toString function in jsfunction.c in Artifex Software MuJS allows attackers to cause a denial of service (crash) via crafted input.
ModificadaAlta (7.5)1.5%—Artifex Mujs18/1/201717/6/2026
The chartorune function in Artifex Software MuJS allows attackers to cause a denial of service (out-of-bounds read) via a * (asterisk) at the end of the input.
ModificadaCrítica (9.8)3.6%—Artifex Mujs13/1/201717/6/2026
An integer overflow vulnerability was observed in the regemit function in regexp.c in Artifex Software, Inc. MuJS before fa3d30fd18c348bb4b1f3858fb860f4fcd4b2045. The attack requires a regular expression with nested repetition. A successful exploitation of this issue can lead to code execution or a denial of service…