Vulnerabilities > F5 > NJS > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-09-15 | CVE-2022-38890 | Out-of-bounds Read vulnerability in F5 NJS 0.7.7 Nginx NJS v0.7.7 was discovered to contain a segmentation violation via njs_utf8_next at src/njs_utf8.h | 5.5 |
2022-06-21 | CVE-2022-31306 | Use After Free vulnerability in F5 NJS 0.7.2 Nginx NJS v0.7.2 was discovered to contain a segmentation violation in the function njs_array_convert_to_slow_array at src/njs_array.c. | 5.5 |
2022-06-21 | CVE-2022-31307 | Use After Free vulnerability in F5 NJS 0.7.2 Nginx NJS v0.7.2 was discovered to contain a segmentation violation in the function njs_string_offset at src/njs_string.c. | 5.5 |
2022-06-21 | CVE-2022-32414 | Use After Free vulnerability in F5 NJS 0.7.2 Nginx NJS v0.7.2 was discovered to contain a segmentation violation in the function njs_vmcode_interpreter at src/njs_vmcode.c. | 5.5 |
2022-04-15 | CVE-2022-28049 | NULL Pointer Dereference vulnerability in F5 NJS 0.7.2 NGINX NJS 0.7.2 was discovered to contain a NULL pointer dereference via the component njs_vmcode_array at /src/njs_vmcode.c. | 5.5 |
2020-08-13 | CVE-2020-24349 | Use After Free vulnerability in F5 NJS njs through 0.4.3, used in NGINX, allows control-flow hijack in njs_value_property in njs_value.c. | 5.5 |
2020-08-13 | CVE-2020-24348 | Out-of-bounds Read vulnerability in F5 NJS njs through 0.4.3, used in NGINX, has an out-of-bounds read in njs_json_stringify_iterator in njs_json.c. | 5.5 |
2020-08-13 | CVE-2020-24347 | Out-of-bounds Read vulnerability in F5 NJS njs through 0.4.3, used in NGINX, has an out-of-bounds read in njs_lvlhsh_level_find in njs_lvlhsh.c. | 5.5 |
2019-07-16 | CVE-2019-13617 | Out-of-bounds Read vulnerability in F5 NJS njs through 0.3.3, used in NGINX, has a heap-based buffer over-read in nxt_vsprintf in nxt/nxt_sprintf.c during error handling, as demonstrated by an njs_regexp_literal call that leads to an njs_parser_lexer_error call and then an njs_parser_scope_error call. | 6.5 |