Vulnerabilidades en cesanta

40 resultados
Análisis Vexday

Cesanta apresenta 8 vulnerabilidades catalogadas, todas publicadas nos últimos 90 dias, indicando risco recente e em evolução. Embora 4 sejam críticas (CVSS alto), nenhuma está sob exploração ativa conhecida (KEV), reduzindo a urgência imediata. A fraqueza dominante é validação inadequada de certificados (CWE-295), típica de falhas em verificação TLS/SSL que podem comprometer a segurança de comunicações.

CVE-2024-42386HIGHUse of Out-of-range Pointer Offset in Mongoose Web Server libraryEPSS 0.4%CVE-2025-0695MEDIUMAn Allocation of Resources Without Limits or Throttling vulnerability in Cesanta Frozen versions less than 1.7 allows an attacker to induce EPSS 0.4%CVE-2025-0696MEDIUMA NULL Pointer Dereference vulnerability in Cesanta Frozen versions less than 1.7 allows an attacker to induce a crash of the component embeEPSS 0.4%CVE-2026-86716MEDIUMCesanta mJS mjs_tok.c skip_spaces_and_comments heap-based overflowEPSS 0.3%CVE-2018-25193HIGHMongoose Web Server 6.9 Denial of Service via Socket ConnectionEPSS 0.3%CVE-2026-73258MEDIUMMongoose: Multipart boundary/header scan logic error in mg_http_next_multipartEPSS 0.3%CVE-2024-42388MEDIUMUse of Out-of-range Pointer Offset in Mongoose Web Server libraryEPSS 0.3%CVE-2024-42389MEDIUMUse of Out-of-range Pointer Offset in Mongoose Web Server libraryEPSS 0.3%CVE-2024-42387MEDIUMUse of Out-of-range Pointer Offset in Mongoose Web Server libraryEPSS 0.3%CVE-2024-42391MEDIUMUse of Out-of-range Pointer Offset in Mongoose Web Server libraryEPSS 0.3%CVE-2024-42390MEDIUMUse of Out-of-range Pointer Offset in Mongoose Web Server libraryEPSS 0.3%CVE-2026-73259MEDIUMMongoose: Reflected XSS via decoded URI in directory listing renderEPSS 0.3%CVE-2024-42383MEDIUMUse of Out-of-range Pointer Offset in Mongoose Web Server libraryEPSS 0.3%CVE-2026-73254MEDIUMMongoose: Stored XSS via unescaped filenames in directory listingEPSS 0.2%CVE-2024-42392MEDIUMImproper Neutralization of Delimiters in Mongoose Web Server libraryEPSS 0.2%CVE-2026-2968MEDIUMCesanta Mongoose Poly1305 Authentication Tag tls_chacha20.c mg_chacha20_poly1305_decrypt signature verificationEPSS 0.2%CVE-2026-6986MEDIUMCesanta Mongoose GCM Authentication Tag tls_aes128.c mg_aes_gcm_decrypt signature verificationEPSS 0.2%CVE-2026-73253CRITICALMongoose: TLS Hostname Verification Bypass via Overly Permissive Wildcard MatchingEPSS 0.2%CVE-2026-73251CRITICALMongoose Built-in TLS: CA-bundle certificate chain accepted without any signature verificationEPSS 0.2%CVE-2024-42385MEDIUMImproper Neutralization of Delimiters in Mongoose Web Server libraryEPSS 0.1%