Vulnerabilities > Moddable > High

DATE CVE VULNERABILITY TITLE RISK
2022-05-12 CVE-2022-29368 Out-of-bounds Read vulnerability in Moddable
Moddable commit before 135aa9a4a6a9b49b60aa730ebc3bcc6247d75c45 was discovered to contain an out-of-bounds read via the function fxUint8Getter at /moddable/xs/sources/xsDataView.c.
local
low complexity
moddable CWE-125
7.1
2020-12-04 CVE-2020-25462 Out-of-bounds Write vulnerability in Moddable
Heap buffer overflow in the fxCheckArrowFunction function at moddable/xs/sources/xsSyntaxical.c:3562 in Moddable SDK before OS200903.
network
low complexity
moddable CWE-787
7.5
2019-09-16 CVE-2019-16366 Classic Buffer Overflow vulnerability in Moddable and XS
In XS 9.0.0 in Moddable SDK OS180329, there is a heap-based buffer overflow in fxBeginHost in xsAPI.c when called from fxRunDefine in xsRun.c, as demonstrated by crafted JavaScript code to xst.
network
low complexity
moddable CWE-120
7.5