Search CVE reports


Toggle filters

1 – 10 of 20 results


CVE-2026-3979

Medium priority
Needs evaluation

A flaw has been found in quickjs-ng quickjs up to 0.12.1. This affects the function js_iterator_concat_return of the file quickjs.c. This manipulation causes use after free. The attack requires local access. The exploit has been...

1 affected package

quickjs

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
quickjs Needs evaluation Not in release
Show less packages

CVE-2025-69654

Medium priority
Needs evaluation

A crafted JavaScript input executed with the QuickJS release 2025-09-13, fixed in commit fcd33c1afa7b3028531f53cd1190a3877454f6b3 (2025-12-11),`qjs` interpreter using the `-m` option and a low memory limit can cause...

1 affected package

quickjs

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
quickjs Needs evaluation Not in release
Show less packages

CVE-2025-69653

Medium priority
Needs evaluation

A crafted JavaScript input can trigger an internal assertion failure in QuickJS release 2025-09-13, fixed in commit 1dbba8a88eaa40d15a8a9b70bb1a0b8fb5b552e6 (2025-12-11), in file gc_decref_child in quickjs.c, when executed with...

1 affected package

quickjs

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
quickjs Needs evaluation Not in release
Show less packages

CVE-2026-1144

Medium priority
Needs evaluation

A vulnerability was detected in quickjs-ng quickjs up to 0.11.0. Affected is an unknown function of the file quickjs.c of the component Atomics Ops Handler. The manipulation results in use after free. The attack can be executed...

1 affected package

quickjs

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
quickjs Needs evaluation Not in release
Show less packages

CVE-2026-0822

Medium priority
Vulnerable

A vulnerability was identified in quickjs-ng quickjs up to 0.11.0. This issue affects the function js_typed_array_sort of the file quickjs.c. The manipulation leads to heap-based buffer overflow. Remote exploitation of the attack...

1 affected package

quickjs

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
quickjs Vulnerable Not in release
Show less packages

CVE-2026-0821

Medium priority
Vulnerable

A vulnerability was determined in quickjs-ng quickjs up to 0.11.0. This vulnerability affects the function js_typed_array_constructor of the file quickjs.c. Executing a manipulation can lead to heap-based buffer overflow. The...

1 affected package

quickjs

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
quickjs Vulnerable Not in release
Show less packages

CVE-2025-12745

Medium priority
Needs evaluation

A weakness has been identified in QuickJS up to eb2c89087def1829ed99630cb14b549d7a98408c. This affects the function js_array_buffer_slice of the file quickjs.c. This manipulation causes buffer over-read. The attack is restricted...

1 affected package

quickjs

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
quickjs Needs evaluation Not in release
Show less packages

CVE-2025-62496

Medium priority
Needs evaluation

A vulnerability exists in the QuickJS engine's BigInt string parsing logic (js_bigint_from_string) when attempting to create a BigInt from a string with an excessively large number of digits. The function calculates the necessary...

1 affected package

quickjs

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
quickjs Needs evaluation Not in release
Show less packages

CVE-2025-62495

Medium priority
Needs evaluation

An integer overflow vulnerability exists in the QuickJS regular expression engine (libregexp) due to an inconsistent representation of the bytecode buffer size. * The regular expression bytecode is stored in a DynBuf structure,...

1 affected package

quickjs

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
quickjs Needs evaluation Not in release
Show less packages

CVE-2025-62494

Medium priority
Needs evaluation

A type confusion vulnerability exists in the handling of the string addition (+) operation within the QuickJS engine. * The code first checks if the left-hand operand is a string. * It then attempts to convert the right-hand...

1 affected package

quickjs

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
quickjs Needs evaluation Not in release
Show less packages