Vulnerabilities > Moddable > High

DATE CVE VULNERABILITY TITLE RISK
2021-11-19 CVE-2021-29329 Allocation of Resources Without Limits or Throttling vulnerability in Moddable 10.5.0
OpenSource Moddable v10.5.0 was discovered to contain a stack overflow in the fxBinaryExpressionNodeDistribute function at /moddable/xs/sources/xsTree.c.
local
low complexity
moddable CWE-770
7.8
2021-07-13 CVE-2020-22882 Type Confusion vulnerability in Moddable Os180328/Os180329
Issue was discovered in the fxParserTree function in moddable, allows attackers to cause denial of service via a crafted payload.
network
low complexity
moddable CWE-843
7.5
2020-12-04 CVE-2020-25465 NULL Pointer Dereference vulnerability in Moddable
Null Pointer Dereference.
network
low complexity
moddable CWE-476
7.5
2020-12-04 CVE-2020-25464 Out-of-bounds Write vulnerability in Moddable Os180328/Os180329/Os200831
Heap buffer overflow at moddable/xs/sources/xsDebug.c in Moddable SDK before before 20200903.
network
low complexity
moddable CWE-787
7.5
2020-12-04 CVE-2020-25463 Unspecified vulnerability in Moddable
Invalid Memory Access in fxUTF8Decode at moddable/xs/sources/xsCommon.c:916 in Moddable SDK before OS200908 causes a denial of service (SEGV).
network
low complexity
moddable
7.5
2020-12-04 CVE-2020-25461 Unspecified vulnerability in Moddable
Invalid Memory Access in the fxProxyGetter function in moddable/xs/sources/xsProxy.c in Moddable SDK before OS200908 causes a denial of service (SEGV).
network
low complexity
moddable
7.5