← לוח פגיעויות

CVE-2024-42391

בינונית 5.3

תיאור (מקור, אנגלית)

Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space.

מדדים

CVSS 3.1
5.3 (MEDIUM) מקור הציון: NVD CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS — סבירות ניצול
0% (אחוזון 000) נכון ל-9/10/2026
CWE
CWE-823

מוצרים מושפעים

cesanta: mongoose

קישורים