ZeroHour

Vulnerabilities

53 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-65570
A type confusion in jsish 2.0 allows incorrect control flow during execution of the OP_NEXT opcode.

A type confusion in jsish 2.0 allows incorrect control flow during execution of the OP_NEXT opcode. When an “instanceof” expression uses an array element access as the left-hand operand inside a for-in loop, the instructions implementation leaves an additional array reference on the stack rather than consuming it during OP_INSTANCEOF. As a result, OP_NEXT interprets the array as an iterator object and reads the iterCmd function pointer from an invalid structure, potentially causing a crash or enabling code execution depending on heap layout.

NVD description · AI analysis pending
9.8<1% PoC
  • jsish jsish
CVE-2024-24186
+2 in the same advisory: …24188 …24189
Jsish v3.5.0 (commit 42c694c) was discovered to contain a stack-overflow via the component IterGetKeysCallback at /jsish/src/jsiValue.c.

Jsish v3.5.0 (commit 42c694c) was discovered to contain a stack-overflow via the component IterGetKeysCallback at /jsish/src/jsiValue.c.

NVD description · AI analysis pending
9.8<1% PoC
  • jsish jsish
CVE-2020-23258
+2 in the same advisory: …23259 …23260
An issue found in Jsish v.3.0.11 allows a remote attacker to cause a denial of service via the Jsi_ValueIsNumber function in ./src/jsiValue.c file.

An issue found in Jsish v.3.0.11 allows a remote attacker to cause a denial of service via the Jsi_ValueIsNumber function in ./src/jsiValue.c file.

NVD description · AI analysis pending
7.5<1% PoC
  • jsish jsish
CVE-2021-46502
Jsish v3.5.0 was discovered to contain a heap-use-after-free via /usr/lib/x86_64-linux-gnu/libasan.so.4+0x5166d.

Jsish v3.5.0 was discovered to contain a heap-use-after-free via /usr/lib/x86_64-linux-gnu/libasan.so.4+0x5166d. This vulnerability can lead to a Denial of Service (DoS).

NVD description · AI analysis pending
5.5<1% PoC
  • jsish jsish
CVE-2021-46483
Jsish v3.5.0 was discovered to contain a heap buffer overflow via BooleanConstructor at src/jsiBool.c.

Jsish v3.5.0 was discovered to contain a heap buffer overflow via BooleanConstructor at src/jsiBool.c.

NVD description · AI analysis pending
7.8
group max
<1% PoC
  • jsish jsish
CVE-2020-22875
+3 in the same advisory: …22874 …22873 …22907
Integer overflow vulnerability in function Jsi_ObjSetLength in jsish before 3.0.6, allows remote attackers to execute arbitrary code.

Integer overflow vulnerability in function Jsi_ObjSetLength in jsish before 3.0.6, allows remote attackers to execute arbitrary code.

NVD description · AI analysis pending
9.8
group max
3% PoC
  • jsish jsish
CVE-2019-1010172
Jsish 2.4.84 2.0484 is affected by:

Jsish 2.4.84 2.0484 is affected by: Uncontrolled Resource Consumption. The impact is: denial of service. The component is: function jsiValueGetString (jsiUtils.c). The attack vector is: executing crafted javascript code. The fixed version is: after commit f3a8096e0ce44bbf36c1dcb6e603adf9c8670c39.

NVD description · AI analysis pending
7.51%
  • jsish jsish
CVE-2019-1010177
Jsish 2.4.70 2.047 is affected by:

Jsish 2.4.70 2.047 is affected by: Use After Free. The impact is: denial of service and possibly arbitrary code execution. The component is: function Jsi_RegExpNew (jsi/jsiRegexp.c:39). The attack vector is: executing crafted javascript code. The fixed version is: after commit 48a66c798d.

NVD description · AI analysis pending
9.82% PoC
  • jsish jsish
CVE-2019-1010169
Jsish 2.4.77 2.0477 is affected by:

Jsish 2.4.77 2.0477 is affected by: Out-of-bounds Read. The impact is: denial of service. The component is: function lexer_getchar (jsiLexer.c:9). The attack vector is: executing crafted javascript code. The fixed version is: 2.4.78.

NVD description · AI analysis pending
7.5
group max
1% PoC
  • jsish jsish
CVE-2018-1000668
jsish version 2.4.70 2.047 contains a CWE-125:

jsish version 2.4.70 2.047 contains a CWE-125: Out-of-bounds Read vulnerability in function jsi_ObjArrayLookup (jsiObj.c:274) that can result in Crash due to segmentation fault. This attack appear to be exploitable via The victim must execute crafted javascript code. This vulnerability appears to have been fixed in 2.4.71.

NVD description · AI analysis pending
6.5<1%
  • jsish jsish