🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
🕴 Security Service Edge: 4 Core Tenets for Your SASE Journey 🕴

Historically we've held network conversations to address security problems, but that doesn't work in a cloud-based world.

📖 Read

via "Dark Reading".
‼ CVE-2021-46519 ‼

Cesanta MJS v2.20.0 was discovered to contain a heap buffer overflow via mjs_array_length at src/mjs_array.c.

📖 Read

via "National Vulnerability Database".
‼ CVE-2021-46507 ‼

Jsish v3.5.0 was discovered to contain a stack overflow via Jsi_LogMsg at src/jsiUtils.c.

📖 Read

via "National Vulnerability Database".
‼ CVE-2021-46505 ‼

Jsish v3.5.0 was discovered to contain a stack overflow via /usr/lib/x86_64-linux-gnu/libasan.so.4+0x5b1e5.

📖 Read

via "National Vulnerability Database".
‼ CVE-2021-46515 ‼

There is an Assertion `mjs_stack_size(&mjs->scopes) >= scopes_len' failed at src/mjs_exec.c in Cesanta MJS v2.20.0.

📖 Read

via "National Vulnerability Database".
‼ CVE-2021-46517 ‼

There is an Assertion `mjs_stack_size(&mjs->scopes) > 0' failed at src/mjs_exec.c in Cesanta MJS v2.20.0.

📖 Read

via "National Vulnerability Database".
‼ CVE-2021-46495 ‼

Jsish v3.5.0 was discovered to contain a heap-use-after-free via DeleteTreeValue in src/jsiObj.c. This vulnerability can lead to a Denial of Service (DoS).

📖 Read

via "National Vulnerability Database".
‼ CVE-2021-46511 ‼

There is an Assertion `m->len >= sizeof(v)' failed at src/mjs_core.c in Cesanta MJS v2.20.0.

📖 Read

via "National Vulnerability Database".
‼ CVE-2021-46549 ‼

Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via parse_cval_type at src/mjs_ffi.c. This vulnerability can lead to a Denial of Service (DoS).

📖 Read

via "National Vulnerability Database".
‼ CVE-2021-46514 ‼

There is an Assertion 'ppos != NULL && mjs_is_number(*ppos)' failed at src/mjs_core.c in Cesanta MJS v2.20.0.

📖 Read

via "National Vulnerability Database".
‼ CVE-2021-46498 ‼

Jsish v3.5.0 was discovered to contain a heap-use-after-free via jsi_wswebsocketObjFree in src/jsiWebSocket.c. This vulnerability can lead to a Denial of Service (DoS).

📖 Read

via "National Vulnerability Database".
‼ CVE-2021-46497 ‼

Jsish v3.5.0 was discovered to contain a heap-use-after-free via jsi_UserObjDelete in src/jsiUserObj.c. This vulnerability can lead to a Denial of Service (DoS).

📖 Read

via "National Vulnerability Database".
‼ CVE-2021-46509 ‼

Cesanta MJS v2.20.0 was discovered to contain a stack overflow via snquote at mjs/src/mjs_json.c.

📖 Read

via "National Vulnerability Database".
‼ CVE-2021-46523 ‼

Cesanta MJS v2.20.0 was discovered to contain a heap buffer overflow via to_json_or_debug at mjs/src/mjs_json.c.

📖 Read

via "National Vulnerability Database".
‼ CVE-2021-46518 ‼

Cesanta MJS v2.20.0 was discovered to contain a heap buffer overflow via mjs_disown at src/mjs_core.c.

📖 Read

via "National Vulnerability Database".
‼ CVE-2021-46499 ‼

Jsish v3.5.0 was discovered to contain a heap-use-after-free via jsi_ValueCopyMove in src/jsiValue.c. This vulnerability can lead to a Denial of Service (DoS).

📖 Read

via "National Vulnerability Database".
‼ CVE-2021-46510 ‼

There is an Assertion `s < mjs->owned_strings.buf + mjs->owned_strings.len' failed at src/mjs_gc.c in Cesanta MJS v2.20.0.

📖 Read

via "National Vulnerability Database".
‼ CVE-2021-46512 ‼

Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via mjs_apply at src/mjs_exec.c. This vulnerability can lead to a Denial of Service (DoS).

📖 Read

via "National Vulnerability Database".
‼ CVE-2021-46504 ‼

There is an Assertion 'vp != resPtr' failed at jsiEval.c in Jsish v3.5.0.

📖 Read

via "National Vulnerability Database".
‼ CVE-2021-46541 ‼

Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via /usr/local/bin/mjs+0x2c6ae. This vulnerability can lead to a Denial of Service (DoS).

📖 Read

via "National Vulnerability Database".
‼ CVE-2021-46503 ‼

Jsish v3.5.0 was discovered to contain a heap-use-after-free via /usr/lib/x86_64-linux-gnu/libasan.so.4+0x79732. This vulnerability can lead to a Denial of Service (DoS).

📖 Read

via "National Vulnerability Database".