6.8
CVSSv2

CVE-2022-22895

Published: 21/01/2022 Updated: 26/01/2022
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 606
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Jerryscript 3.0.0 exists to contain a heap-buffer-overflow via ecma_utf8_string_to_number_by_radix in /jerry-core/ecma/base/ecma-helpers-conversion.c.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

jerryscript jerryscript 3.0.0

Vendor Advisories

Debian Bug report logs - #1004298 iotjs: 8 new CVEs 2022-22892 to 2022-2292 Package: src:iotjs; Maintainer for src:iotjs is Debian Javascript Maintainers <pkg-javascript-devel@listsaliothdebianorg>; Reported by: Neil Williams <codehelp@debianorg> Date: Mon, 24 Jan 2022 14:21:01 UTC Severity: important Tags: secur ...