CVE-2018-1000636

MEDIUM

JerryScript - NULL Pointer Dereference

Title source: llm
STIX 2.1

Description

JerryScript version Tested on commit f86d7459d195c8ba58479d1861b0cc726c8b3793. Analysing history it seems that the issue has been present since commit 64a340ffeb8809b2b66bbe32fd443a8b79fdd860 contains a CWE-476: NULL Pointer Dereference vulnerability in Triggering undefined behavior at jerry-core/ecma/builtin-objects/typedarray/ecma-builtin-typedarray-prototype.c:598 (passing NULL to memcpy as 2nd argument) results in null pointer dereference (segfault) at jerry-core/jmem/jmem-heap.c:463 that can result in Crash due to segmentation fault. This attack appear to be exploitable via The victim must execute specially crafted javascript code. This vulnerability appears to have been fixed in after commit 87897849f6879df10e8ad68a41bf8cf507edf710.

References (1)

Core 1
Core References
Patch, Third Party Advisory x_refsource_confirm
https://github.com/jerryscript-project/jerryscript/issues/2435

Scores

CVSS v3 6.5
EPSS 0.0111
EPSS Percentile 61.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Details

CWE
CWE-476
Status published
Products (1)
jerryscript/jerryscript 1.0
Published Aug 20, 2018
Tracked Since Feb 18, 2026