Dmitry Volyntsev

14 exploits Active since Feb 2022
CVE-2022-25139 WRITEUP CRITICAL WRITEUP
F5 Njs < 0.7.2 - Use After Free
njs through 0.7.0, used in NGINX, was discovered to contain a heap use-after-free in njs_await_fulfilled.
CVSS 9.8
CVE-2022-27007 WRITEUP CRITICAL WRITEUP
F5 Njs - Use After Free
nginx njs 0.7.2 is affected suffers from Use-after-free in njs_function_frame_alloc() when it try to invoke from a restored frame saved with njs_function_frame_save().
CVSS 9.8
CVE-2022-27008 WRITEUP HIGH WRITEUP
F5 Njs - Buffer Overflow
nginx njs 0.7.2 is vulnerable to Buffer Overflow. Type confused in Array.prototype.concat() when a slow array appended element is fast array.
CVSS 7.5
CVE-2022-28049 WRITEUP MEDIUM WRITEUP
F5 Njs - NULL Pointer Dereference
NGINX NJS 0.7.2 was discovered to contain a NULL pointer dereference via the component njs_vmcode_array at /src/njs_vmcode.c.
CVSS 5.5
CVE-2022-29369 WRITEUP HIGH WRITEUP
Nginx NJS <0.7.2 - Memory Corruption
Nginx NJS v0.7.2 was discovered to contain a segmentation violation via njs_lvlhsh_bucket_find at njs_lvlhsh.c.
CVSS 7.5
CVE-2022-29379 WRITEUP CRITICAL WRITEUP
Nginx NJS v0.7.3 - Buffer Overflow
Nginx NJS v0.7.3 was discovered to contain a stack overflow in the function njs_default_module_loader at /src/njs/src/njs_module.c. NOTE: multiple third parties dispute this report, e.g., the behavior is only found in unreleased development code that was not part of the 0.7.2, 0.7.3, or 0.7.4 release
CVSS 9.8
CVE-2022-29779 WRITEUP MEDIUM WRITEUP
Nginx NJS <0.7.2 - Memory Corruption
Nginx NJS v0.7.2 was discovered to contain a segmentation violation in the function njs_value_own_enumerate at src/njs_value.c.
CVSS 5.5
CVE-2022-29780 WRITEUP MEDIUM WRITEUP
Nginx NJS <0.7.2 - Buffer Overflow
Nginx NJS v0.7.2 was discovered to contain a segmentation violation in the function njs_array_prototype_sort at src/njs_array.c.
CVSS 5.5
CVE-2022-30503 WRITEUP MEDIUM WRITEUP
Nginx NJS <0.7.2 - Memory Corruption
Nginx NJS v0.7.2 was discovered to contain a segmentation violation in the function njs_set_number at src/njs_value.h.
CVSS 5.5
CVE-2022-31306 WRITEUP MEDIUM WRITEUP
Nginx NJS <0.7.2 - Memory Corruption
Nginx NJS v0.7.2 was discovered to contain a segmentation violation in the function njs_array_convert_to_slow_array at src/njs_array.c.
CVSS 5.5
CVE-2022-31307 WRITEUP MEDIUM WRITEUP
Nginx NJS <0.7.2 - Memory Corruption
Nginx NJS v0.7.2 was discovered to contain a segmentation violation in the function njs_string_offset at src/njs_string.c.
CVSS 5.5
CVE-2022-32414 WRITEUP MEDIUM WRITEUP
F5 Njs - Use After Free
Nginx NJS v0.7.2 was discovered to contain a segmentation violation in the function njs_vmcode_interpreter at src/njs_vmcode.c.
CVSS 5.5
CVE-2022-35173 WRITEUP HIGH WRITEUP
Nginx Njs - Improper Condition Check
An issue was discovered in Nginx NJS v0.7.5. The JUMP offset for a break instruction was not set to a correct offset during code generation, leading to a segmentation violation.
CVSS 7.5
CVE-2022-43286 WRITEUP CRITICAL WRITEUP
Nginx NJS <0.7.2 - Use After Free
Nginx NJS v0.7.2 was discovered to contain a heap-use-after-free bug caused by illegal memory copy in the function njs_json_parse_iterator_call at njs_json.c.
CVSS 9.8