Cesanta Mongoose Web Server是爱尔兰Cesanta公司的一款使用C语言编写的、跨平台的嵌入式服务器和网络库。 Cesanta Mongoose Web Server v7.14版本存在安全漏洞,该漏洞源于存在超出范围的指针偏移,攻击者可以发送意外的TLS数据包,并强制应用程序读取非预期的堆内存空间。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Cesanta | Mongoose Web Server | 0 ~ 7.14 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-42386 | 8.2 HIGH | Use of Out-of-range Pointer Offset in Mongoose Web Server library |
| CVE-2024-42384 | 7.5 HIGH | Integer Overflow or Wraparound in Mongoose Web Server library |
| CVE-2024-42387 | 5.3 MEDIUM | Use of Out-of-range Pointer Offset in Mongoose Web Server library |
| CVE-2024-42388 | 5.3 MEDIUM | Use of Out-of-range Pointer Offset in Mongoose Web Server library |
| CVE-2024-42390 | 4.3 MEDIUM | Use of Out-of-range Pointer Offset in Mongoose Web Server library |
| CVE-2024-42391 | 4.3 MEDIUM | Use of Out-of-range Pointer Offset in Mongoose Web Server library |
| CVE-2024-42383 | 4.2 MEDIUM | Use of Out-of-range Pointer Offset in Mongoose Web Server library |
| CVE-2024-42392 | 4.0 MEDIUM | Improper Neutralization of Delimiters in Mongoose Web Server library |
| CVE-2024-42385 | 4.0 MEDIUM | Improper Neutralization of Delimiters in Mongoose Web Server library |
No comments yet