CVSS v3
9.8
CRITICAL
EPSS Score
1.3 %
exploit probability
CISA KEV
No
known exploited
Exploitation
—
SSVC status
Description
Jsish 2.4.70 2.047 is affected by: Use After Free. The impact is: denial of service and possibly arbitrary code execution. The component is: function Jsi_RegExpNew (jsi/jsiRegexp.c:39). The attack vector is: executing crafted javascript code. The fixed version is: after commit 48a66c798d.
Technical details
- Published
- 2019-07-24
Frequently asked questions
What is CVE-2019-1010177?
Jsish 2.4.70 2.047 is affected by: Use After Free. The impact is: denial of service and possibly arbitrary code execution. The component is: function Jsi_RegExpNew (jsi/jsiRegexp.c:39). The attack vector is: executing crafted javascript code. The fixed version is: after commit 48a66c798d.
Is CVE-2019-1010177 actively exploited?
Active exploitation of CVE-2019-1010177 has not been confirmed. The EPSS score is 1.3%, indicating the estimated probability of exploitation in the next 30 days.
What is the CVSS score for CVE-2019-1010177?
CVE-2019-1010177 has a CVSS v3 base score of 9.8 (CRITICAL severity).
Is CVE-2019-1010177 affecting your environment?
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.
No credit card required · 500 free checks/month · Free API key
Other 2019 vulnerabilities worth triaging
Ranked by exploit probability (EPSS).