Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Moddable Subscribe
Filtered by product Moddable
Total 15 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-29368 1 Moddable 1 Moddable 2023-01-24 5.8 MEDIUM 7.1 HIGH
Moddable commit before 135aa9a4a6a9b49b60aa730ebc3bcc6247d75c45 was discovered to contain an out-of-bounds read via the function fxUint8Getter at /moddable/xs/sources/xsDataView.c.
CVE-2021-29329 1 Moddable 1 Moddable 2022-05-03 6.8 MEDIUM 7.8 HIGH
OpenSource Moddable v10.5.0 was discovered to contain a stack overflow in the fxBinaryExpressionNodeDistribute function at /moddable/xs/sources/xsTree.c.
CVE-2021-29324 1 Moddable 1 Moddable 2022-05-03 6.8 MEDIUM 7.8 HIGH
OpenSource Moddable v10.5.0 was discovered to contain a stack overflow via the component /moddable/xs/sources/xsScript.c.
CVE-2021-29323 1 Moddable 1 Moddable 2021-11-23 4.3 MEDIUM 5.5 MEDIUM
OpenSource Moddable v10.5.0 was discovered to contain a heap buffer overflow via the component /modules/network/wifi/esp/modwifi.c.
CVE-2021-29325 1 Moddable 1 Moddable 2021-11-23 6.8 MEDIUM 7.8 HIGH
OpenSource Moddable v10.5.0 was discovered to contain a heap buffer overflow in the fx_String_prototype_repeat function at /moddable/xs/sources/xsString.c.
CVE-2021-29326 1 Moddable 1 Moddable 2021-11-23 6.8 MEDIUM 7.8 HIGH
OpenSource Moddable v10.5.0 was discovered to contain a heap buffer overflow in the fxIDToString function at /moddable/xs/sources/xsSymbol.c.
CVE-2021-29327 1 Moddable 1 Moddable 2021-11-23 6.8 MEDIUM 7.8 HIGH
OpenSource Moddable v10.5.0 was discovered to contain a heap buffer overflow in the fx_ArrayBuffer function at /moddable/xs/sources/xsDataView.c.
CVE-2021-29328 1 Moddable 1 Moddable 2021-11-23 5.8 MEDIUM 7.1 HIGH
OpenSource Moddable v10.5.0 was discovered to contain buffer over-read in the fxDebugThrow function at /moddable/xs/sources/xsDebug.c.
CVE-2019-16366 1 Moddable 2 Moddable, Xs 2021-07-21 7.5 HIGH 9.8 CRITICAL
In XS 9.0.0 in Moddable SDK OS180329, there is a heap-based buffer overflow in fxBeginHost in xsAPI.c when called from fxRunDefine in xsRun.c, as demonstrated by crafted JavaScript code to xst.
CVE-2020-22882 1 Moddable 1 Moddable 2021-07-16 5.0 MEDIUM 7.5 HIGH
Issue was discovered in the fxParserTree function in moddable, allows attackers to cause denial of service via a crafted payload. Fixed in commit 723816ab9b52f807180c99fc69c7d08cf6c6bd61.
CVE-2020-25465 1 Moddable 1 Moddable 2020-12-04 5.0 MEDIUM 7.5 HIGH
Null Pointer Dereference. in xObjectBindingFromExpression at moddable/xs/sources/xsSyntaxical.c:3419 in Moddable SDK before OS200908 causes a denial of service (SEGV).
CVE-2020-25464 1 Moddable 1 Moddable 2020-12-04 5.0 MEDIUM 7.5 HIGH
Heap buffer overflow at moddable/xs/sources/xsDebug.c in Moddable SDK before before 20200903. The top stack frame is only partially initialized because the stack overflowed while creating the frame. This leads to a crash in the code sending the stack frame to the debugger.
CVE-2020-25463 1 Moddable 1 Moddable 2020-12-04 5.0 MEDIUM 7.5 HIGH
Invalid Memory Access in fxUTF8Decode at moddable/xs/sources/xsCommon.c:916 in Moddable SDK before OS200908 causes a denial of service (SEGV).
CVE-2020-25462 1 Moddable 1 Moddable 2020-12-04 7.5 HIGH 9.8 CRITICAL
Heap buffer overflow in the fxCheckArrowFunction function at moddable/xs/sources/xsSyntaxical.c:3562 in Moddable SDK before OS200903.
CVE-2020-25461 1 Moddable 1 Moddable 2020-12-04 5.0 MEDIUM 7.5 HIGH
Invalid Memory Access in the fxProxyGetter function in moddable/xs/sources/xsProxy.c in Moddable SDK before OS200908 causes a denial of service (SEGV).