Vulnerabilities > Cesanta > Mongoose Embedded WEB Server Library > 6.8

DATE CVE VULNERABILITY TITLE RISK
2019-06-10 CVE-2018-20352 Use After Free vulnerability in Cesanta Mongoose Embedded web Server Library
Use-after-free vulnerability in the mg_cgi_ev_handler function in mongoose.c in Cesanta Mongoose Embedded Web Server Library 6.13 and earlier allows a denial of service (application crash) or remote code execution.
network
cesanta CWE-416
6.8
2017-09-07 CVE-2017-11567 Cross-Site Request Forgery (CSRF) vulnerability in Cesanta Mongoose Embedded web Server Library
Cross-site request forgery (CSRF) vulnerability in Mongoose Web Server before 6.9 allows remote attackers to hijack the authentication of users for requests that modify Mongoose.conf via a request to __mg_admin?save.
network
cesanta CWE-352
6.8