CVE-2024-42390
MEDIUMDescription
Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space.
Is your site exposed to CVE-2024-42390?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| cesanta | mongoose |
References
Frequently Asked Questions
What is CVE-2024-42390? +
How severe is CVE-2024-42390? +
What products are affected by CVE-2024-42390? +
How do I check if I'm vulnerable to CVE-2024-42390? +
Related Vulnerabilities
A Use of Out-of-range Pointer Offset vulnerability in sslh leads to denial of service on some architectures.This issue affects sslh …
UCanCode E-XD++ Visualization Enterprise Suite contains an untrusted pointer dereference vulnerability via the TKDRAWCAD.TKDrawCADCtrl.1 ActiveX control. This is because it …
On some hardware revisions where VP9 decoding is hardware-accelerated, the frame size is not programmed correctly into the decoder hardware …
Memory corruption while parsing beacon/probe response frame when AP sends more supported links in MLIE.
The ctl_report_supported_opcodes function did not sufficiently validate a field provided by userspace, allowing an arbitrary write to a limited amount …
Memory corruption while performing SCM call.