Vulnerabilidades en cesanta
40 resultadosAnálisis Vexday
Cesanta apresenta 8 vulnerabilidades catalogadas, todas publicadas nos últimos 90 dias, indicando risco recente e em evolução. Embora 4 sejam críticas (CVSS alto), nenhuma está sob exploração ativa conhecida (KEV), reduzindo a urgência imediata. A fraqueza dominante é validação inadequada de certificados (CWE-295), típica de falhas em verificação TLS/SSL que podem comprometer a segurança de comunicações.
CVE-2017-2894CRITICALAn exploitable stack buffer overflow vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8. A specially crafEPSS 31.0%CVE-2017-2893HIGHAn exploitable NULL pointer dereference vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8. An MQTT SUBSCEPSS 24.9%CVE-2017-2892CRITICALAn exploitable arbitrary memory read vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8. A specially crafEPSS 3.0%CVE-2017-2891CRITICALAn exploitable use-after-free vulnerability exists in the HTTP server implementation of Cesanta Mongoose 6.8. An ordinary HTTP POST request EPSS 2.8%CVE-2017-2922CRITICALAn exploitable memory corruption vulnerability exists in the Websocket protocol implementation of Cesanta Mongoose 6.8. A specially crafted EPSS 2.6%CVE-2017-2921HIGHAn exploitable memory corruption vulnerability exists in the Websocket protocol implementation of Cesanta Mongoose 6.8. A specially crafted EPSS 2.4%CVE-2017-2909HIGHAn infinite loop programming error exists in the DNS server functionality of Cesanta Mongoose 6.8 library. A specially crafted DNS request cEPSS 1.4%CVE-2017-2895HIGHAn exploitable arbitrary memory read vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8. A specially crafEPSS 1.3%CVE-2023-2905—Cesanta Mongoose MQTT Message Parsing Heap OverflowEPSS 1.0%CVE-2026-5244MEDIUMCesanta Mongoose TLS 1.3 mongoose.c mg_tls_recv_cert heap-based overflowEPSS 0.7%CVE-2026-5245MEDIUMCesanta Mongoose mDNS Record mongoose.c handle_mdns_record stack-based overflowEPSS 0.7%CVE-2026-5246MEDIUMCesanta Mongoose P-384 Public Key mongoose.c mg_tls_verify_cert_signature authorizationEPSS 0.6%CVE-2026-11404HIGHCesanta Mongoose Out-of-Bounds Read in MG_TLS_BUILTIN ClientHello Session ID ParsingEPSS 0.6%CVE-2026-73255MEDIUMMongoose: Path traversal in SSI #include directives enables arbitrary file readEPSS 0.6%CVE-2026-6985MEDIUMCesanta Mongoose TCP Option net_builtin.c handle_opt infinite loopEPSS 0.6%CVE-2026-2967MEDIUMCesanta Mongoose TCP Sequence Number net_builtin.c getpeer verification of sourceEPSS 0.5%CVE-2026-73257CRITICALMongoose: Content-Length + Transfer-Encoding coexistence enables request smugglingEPSS 0.5%CVE-2024-42384HIGHInteger Overflow or Wraparound in Mongoose Web Server libraryEPSS 0.5%CVE-2026-73256CRITICALMongoose: HTTP/1.0 detection off-by-one enables request smuggling via chunked TEEPSS 0.4%CVE-2026-2966MEDIUMCesanta Mongoose DNS Transaction ID dns.c mg_sendnsreq random valuesEPSS 0.4%