Vulnerabilities > CVE-2020-13649 - NULL Pointer Dereference vulnerability in Jerryscript 2.2.0

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
PARTIAL
network
low complexity
jerryscript
CWE-476

Summary

parser/js/js-scanner.c in JerryScript 2.2.0 mishandles errors during certain out-of-memory conditions, as demonstrated by a scanner_reverse_info_list NULL pointer dereference and a scanner_scan_all assertion failure.

Vulnerable Configurations

Part Description Count
Application
Jerryscript
1

Common Weakness Enumeration (CWE)