Known Vulnerabilities for Njs by Nginx
Listed below are 10 of the newest known vulnerabilities associated with "Njs" by "Nginx".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2022-25139 | njs through 0.7.0, used in NGINX, was discovered to contain a heap use-after-free in njs_await_fulfilled. | 9.8 - CRITICAL | 2022-02-14 | 2022-03-24 |
| CVE-2020-24349 | njs through 0.4.3, used in NGINX, allows control-flow hijack in njs_value_property in njs_value.c. NOTE: the vendor considers... | 5.5 - MEDIUM | 2020-08-13 | 2022-10-05 |
| CVE-2020-24348 | njs through 0.4.3, used in NGINX, has an out-of-bounds read in njs_json_stringify_iterator in njs_json.c. | 5.5 - MEDIUM | 2020-08-13 | 2022-04-15 |
| CVE-2020-24347 | njs through 0.4.3, used in NGINX, has an out-of-bounds read in njs_lvlhsh_level_find in njs_lvlhsh.c. | 5.5 - MEDIUM | 2020-08-13 | 2022-04-15 |
| CVE-2020-24346 | njs through 0.4.3, used in NGINX, has a use-after-free in njs_json_parse_iterator_call in njs_json.c. | 7.8 - HIGH | 2020-08-13 | 2022-04-15 |
| CVE-2020-19695 | Buffer Overflow found in Nginx NJS allows a remote attacker to execute arbitrary code via the njs_object_property parameter o... | 9.8 - CRITICAL | 2023-04-04 | 2023-04-10 |
| CVE-2020-19692 | Buffer Overflow vulnerabilty found in Nginx NJS v.0feca92 allows a remote attacker to execute arbitrary code via the njs_modu... | 9.8 - CRITICAL | 2023-04-04 | 2023-04-10 |
| CVE-2019-11839 | njs through 0.3.1, used in NGINX, has a heap-based buffer overflow in Array.prototype.push after a resize, related to njs_arr... | 9.8 - CRITICAL | 2019-05-09 | 2022-03-24 |
| CVE-2019-11838 | njs through 0.3.1, used in NGINX, has a heap-based buffer overflow in Array.prototype.splice after a resize, related to njs_a... | 9.8 - CRITICAL | 2019-05-09 | 2022-03-24 |
| CVE-2019-11837 | njs through 0.3.1, used in NGINX, has a segmentation fault in String.prototype.toBytes for negative arguments, related to nxt... | 7.5 - HIGH | 2019-05-09 | 2022-03-24 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Nginx | Njs | 0.4.3 | All | All | All |
| Application | Nginx | Njs | 0.4.2 | All | All | All |
| Application | Nginx | Njs | 0.4.1 | All | All | All |
| Application | Nginx | Njs | 0.4.0 | All | All | All |
| Application | Nginx | Njs | 0.3.9 | All | All | All |
| Application | Nginx | Njs | 0.3.8 | All | All | All |
| Application | Nginx | Njs | 0.3.7 | All | All | All |
| Application | Nginx | Njs | 0.3.6 | All | All | All |
| Application | Nginx | Njs | 0.3.5 | All | All | All |
| Application | Nginx | Njs | 0.3.4 | All | All | All |
| Application | Nginx | Njs | 0.3.3 | All | All | All |
| Application | Nginx | Njs | 0.3.2 | All | All | All |
| Application | Nginx | Njs | 0.3.1 | All | All | All |
| Application | Nginx | Njs | 0.3.0 | All | All | All |
| Application | Nginx | Njs | 0.2.8 | All | All | All |
| Application | Nginx | Njs | 0.2.7 | All | All | All |
| Application | Nginx | Njs | 0.2.6 | All | All | All |
| Application | Nginx | Njs | 0.2.5 | All | All | All |
| Application | Nginx | Njs | 0.2.4 | All | All | All |
| Application | Nginx | Njs | 0.2.3 | All | All | All |