Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The lexer_process_char_literal function in jerry-core/parser/js/js-lexer.c in JerryScript 1.0 does not skip memory allocation for empty strings, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via malformed JavaScript source code, related to the jmem_heap_free_block function.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
JerryScript 安全漏洞
Vulnerability Description
JerryScript是一款轻量级的JavaScript引擎。 JerryScript 1.0版本中的jerry-core/parser/js/js-lexer.c文件的‘lexer_process_char_literal’函数存在安全漏洞,该漏洞源于程序没有正确分配内存。攻击者可借助畸形的JavaScript源代码利用该漏洞造成拒绝服务(空指针逆向引用和应用程序崩溃)。
CVSS Information
N/A
Vulnerability Type
N/A