cbcvebase.

Debian Mujs vulnerabilities

8 known vulnerabilities affecting debian/mujs.

Total CVEs
8
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH4MEDIUM1

Vulnerabilities

Page 1 of 1
CVE-2021-33797P3CRITICALCVSS 9.8fixed in mujs 1.1.3-2 (bookworm)2021
CVE-2021-33797 [CRITICAL] CVE-2021-33797: mujs - Buffer-overflow in jsdtoa.c in Artifex MuJS in versions 1.0.1 to 1.1.1. An integ... Buffer-overflow in jsdtoa.c in Artifex MuJS in versions 1.0.1 to 1.1.1. An integer overflow happens when js_strtod() reads in floating point exponent, which leads to a buffer overflow in the pointer *d. Scope: local bookworm: resolved (fixed in 1.1.3-2) bullseye: resolved (fixed in 1.1.0-1+deb11u3) forky: resolved (fixed in 1.1.3-2) sid: resolved (fixed in 1.1.3-2)
debian
CVE-2022-44789P3HIGHCVSS 8.8fixed in mujs 1.3.2-1 (bookworm)2022
CVE-2022-44789 [HIGH] CVE-2022-44789: mujs - A logical issue in O_getOwnPropertyDescriptor() in Artifex MuJS 1.0.0 through 1.... A logical issue in O_getOwnPropertyDescriptor() in Artifex MuJS 1.0.0 through 1.3.x before 1.3.2 allows an attacker to achieve Remote Code Execution through memory corruption, via the loading of a crafted JavaScript file. Scope: local bookworm: resolved (fixed in 1.3.2-1) bullseye: resolved (fixed in 1.1.0-1+deb11u2) forky: resolved (fixed in 1.3.2-1) sid: resolved (fi
debian
CVE-2021-45005P3CRITICALCVSS 9.8fixed in mujs 1.1.3-4 (bookworm)2021
CVE-2021-45005 [CRITICAL] CVE-2021-45005: mujs - Artifex MuJS v1.1.3 was discovered to contain a heap buffer overflow which is ca... Artifex MuJS v1.1.3 was discovered to contain a heap buffer overflow which is caused by conflicting JumpList of nested try/finally statements. Scope: local bookworm: resolved (fixed in 1.1.3-4) bullseye: resolved (fixed in 1.1.0-1+deb11u1) forky: resolved (fixed in 1.1.3-4) sid: resolved (fixed in 1.1.3-4) trixie: resolved (fixed in 1.1.3-4)
debian
CVE-2020-22885P3HIGHCVSS 7.5fixed in mujs 1.0.9-1 (bookworm)2020
CVE-2020-22885 [HIGH] CVE-2020-22885: mujs - Buffer overflow vulnerability in mujs before 1.0.8 due to recursion in the GC sc... Buffer overflow vulnerability in mujs before 1.0.8 due to recursion in the GC scanning phase, allows remote attackers to cause a denial of service. Scope: local bookworm: resolved (fixed in 1.0.9-1) bullseye: resolved (fixed in 1.0.9-1) forky: resolved (fixed in 1.0.9-1) sid: resolved (fixed in 1.0.9-1) trixie: resolved (fixed in 1.0.9-1)
debian
CVE-2021-33796P3CRITICALCVSS 10.0fixed in mujs 1.1.3-2 (bookworm)2021
CVE-2021-33796 [CRITICAL] CVE-2021-33796: mujs - In MuJS before version 1.1.2, a use-after-free flaw in the regexp source propert... In MuJS before version 1.1.2, a use-after-free flaw in the regexp source property access may cause denial of service. Scope: local bookworm: resolved (fixed in 1.1.3-2) bullseye: open forky: resolved (fixed in 1.1.3-2) sid: resolved (fixed in 1.1.3-2) trixie: resolved (fixed in 1.1.3-2)
debian
CVE-2020-22886P4HIGHCVSS 7.5fixed in mujs 1.0.9-1 (bookworm)2020
CVE-2020-22886 [HIGH] CVE-2020-22886: mujs - Buffer overflow vulnerability in function jsG_markobject in jsgc.c in mujs befor... Buffer overflow vulnerability in function jsG_markobject in jsgc.c in mujs before 1.0.8, allows remote attackers to cause a denial of service. Scope: local bookworm: resolved (fixed in 1.0.9-1) bullseye: resolved (fixed in 1.0.9-1) forky: resolved (fixed in 1.0.9-1) sid: resolved (fixed in 1.0.9-1) trixie: resolved (fixed in 1.0.9-1)
debian
CVE-2022-30974P4HIGHCVSS 7.5fixed in mujs 1.2.0-3 (bookworm)2022
CVE-2022-30974 [HIGH] CVE-2022-30974: mujs - compile in regexp.c in Artifex MuJS through 1.2.0 results in stack consumption b... compile in regexp.c in Artifex MuJS through 1.2.0 results in stack consumption because of unlimited recursion, a different issue than CVE-2019-11413. Scope: local bookworm: resolved (fixed in 1.2.0-3) bullseye: resolved (fixed in 1.1.0-1+deb11u2) forky: resolved (fixed in 1.2.0-3) sid: resolved (fixed in 1.2.0-3) trixie: resolved (fixed in 1.2.0-3)
debian
CVE-2022-30975P4MEDIUMCVSS 5.5fixed in mujs 1.2.0-3 (bookworm)2022
CVE-2022-30975 [MEDIUM] CVE-2022-30975: mujs - In Artifex MuJS through 1.2.0, jsP_dumpsyntax in jsdump.c has a NULL pointer der... In Artifex MuJS through 1.2.0, jsP_dumpsyntax in jsdump.c has a NULL pointer dereference, as demonstrated by mujs-pp. Scope: local bookworm: resolved (fixed in 1.2.0-3) bullseye: resolved (fixed in 1.1.0-1+deb11u2) forky: resolved (fixed in 1.2.0-3) sid: resolved (fixed in 1.2.0-3) trixie: resolved (fixed in 1.2.0-3)
debian
Debian Mujs vulnerabilities | cvebase