Vulnerabilities > F5 > NJS
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-04-14 | CVE-2022-27007 | Use After Free vulnerability in F5 NJS 0.7.2 nginx njs 0.7.2 is affected suffers from Use-after-free in njs_function_frame_alloc() when it try to invoke from a restored frame saved with njs_function_frame_save(). | 9.8 |
2022-04-14 | CVE-2022-27008 | Classic Buffer Overflow vulnerability in F5 NJS 0.7.2 nginx njs 0.7.2 is vulnerable to Buffer Overflow. | 7.5 |
2022-02-14 | CVE-2021-46462 | Unspecified vulnerability in F5 NJS njs through 0.7.1, used in NGINX, was discovered to contain a segmentation violation via njs_object_set_prototype in /src/njs_object.c. | 7.5 |
2022-02-14 | CVE-2021-46463 | Type Confusion vulnerability in F5 NJS njs through 0.7.1, used in NGINX, was discovered to contain a control flow hijack caused by a Type Confusion vulnerability in njs_promise_perform_then(). | 9.8 |
2022-02-14 | CVE-2022-25139 | Use After Free vulnerability in F5 NJS njs through 0.7.0, used in NGINX, was discovered to contain a heap use-after-free in njs_await_fulfilled. | 9.8 |
2020-08-13 | CVE-2020-24349 | Use After Free vulnerability in F5 NJS njs through 0.4.3, used in NGINX, allows control-flow hijack in njs_value_property in njs_value.c. | 5.5 |
2020-08-13 | CVE-2020-24348 | Out-of-bounds Read vulnerability in F5 NJS njs through 0.4.3, used in NGINX, has an out-of-bounds read in njs_json_stringify_iterator in njs_json.c. | 5.5 |
2020-08-13 | CVE-2020-24347 | Out-of-bounds Read vulnerability in F5 NJS njs through 0.4.3, used in NGINX, has an out-of-bounds read in njs_lvlhsh_level_find in njs_lvlhsh.c. | 5.5 |
2020-08-13 | CVE-2020-24346 | Use After Free vulnerability in F5 NJS njs through 0.4.3, used in NGINX, has a use-after-free in njs_json_parse_iterator_call in njs_json.c. | 7.8 |
2019-07-16 | CVE-2019-13617 | Out-of-bounds Read vulnerability in F5 NJS njs through 0.3.3, used in NGINX, has a heap-based buffer over-read in nxt_vsprintf in nxt/nxt_sprintf.c during error handling, as demonstrated by an njs_regexp_literal call that leads to an njs_parser_lexer_error call and then an njs_parser_scope_error call. | 6.5 |