CVE-2024-42391

Medium4.3Published on November 18, 2024

Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space.

CVSS score4.3 / 10CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Weakness type (CWE)CWE-823
Vendorscesanta

Affected products

VendorsProductVersions
cesantamongoose<= 7.14

Related articles

This product uses the NVD API but is not endorsed or certified by the NVD.

CVE database