CVE-2022-29379
published 2022-05-25CVE-2022-29379: Nginx NJS v0.7.3 was discovered to contain a stack overflow in the function njs_default_module_loader at /src/njs/src/njs_module.c. NOTE: multiple third…
PriorityP351critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.69%
74.4th percentile
Nginx NJS v0.7.3 was discovered to contain a stack overflow in the function njs_default_module_loader at /src/njs/src/njs_module.c. NOTE: multiple third parties dispute this report, e.g., the behavior is only found in unreleased development code that was not part of the 0.7.2, 0.7.3, or 0.7.4 release
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | njs | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
arXiv
Mono: Is Your "Clean" Vulnerability Dataset Really Solvable? Exposing and Trapping Undecidable Patches and Beyond
arxiv_fulltext·2025-06-11
Mono: Is Your "Clean" Vulnerability Dataset Really Solvable? Exposing and Trapping Undecidable Patches and Beyond
: Is Your "Clean" Vulnerability Dataset Really Solvable?
Exposing and Trapping Undecidable Patches and Beyond
@IEEEauthorhalign
@IEEEauthorhalign
Zeyu Gao1 1Equal contribution
Tsinghua University
[email protected]
Junlin Zhou1
Sichuan University
[email protected]
Bolun Zhang
Institute of Information Engineering,
Chinese Academy of Sciences
[email protected]
Yi He
Wuhan University
[email protected]
Chao Zhang22Corresponding author
Tsinghua University
[email protected]
Yuxin Cui
Tsinghua University
[email protected]
Hao Wang
Tsinghua University
[email protected]
## Abstract
The quantity and quality of vulnerability datasets are essential for developing deep learning solutions to vulnerability-related tasks. Due
arXiv
Systematic Assessment of Fuzzers using Mutation Analysis
arxiv_fulltext·2023-07-25
Systematic Assessment of Fuzzers using Mutation Analysis
[1]Philipp G\"orz
[1]Bj\"orn Mathis
[1]Keno Hassler
[2]Emre G\"uler
[1]\ Holz
[1]Andreas Zeller
[3]Rahul Gopinath
[1]CISPA Helmholtz Center for Information Security, Germany
[2]Ruhr-Universität Bochum, Germany
[3]University of Sydney, Australia
## Abstract
Fuzzing is an important method to discover vulnerabilities in programs.
Despite considerable progress in this area in the past years, measuring and comparing the effectiveness of fuzzers is still an open research question.
In software testing, the gold standard for evaluating test quality is mutation analysis, which evaluates a test's ability to detect synthetic bugs: If a set of tests fails to detect such mutations, it is expected to also fail to detect real bugs.
Mutation analysis subsumes various coverage measures and provide
https://github.com/nginx/njs/commit/ab1702c7af9959366a5ddc4a75b4357d4e9ebdc1https://github.com/nginx/njs/issues/491https://github.com/nginx/njs/issues/493https://github.com/nginx/njs/commit/ab1702c7af9959366a5ddc4a75b4357d4e9ebdc1https://github.com/nginx/njs/issues/491https://github.com/nginx/njs/issues/493
2022-05-25
Published