Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Sunlili

#26060de 53,633
9.8CVSS total
Vulnerabilidades · 1
PT-2019-14646
9.8
2019-09-16
Moddable · Moddable Sdk · CVE-2019-16366
**Name of the Vulnerable Software and Affected Versions** Moddable SDK OS180329 version 9.0.0 **Description** The issue is a heap-based buffer overflow in the `fxBeginHost` function in `xsAPI.c` when called from `fxRunDefine` in `xsRun.c`. This can be triggered by crafted JavaScript code sent to `xst`. **Recommendations** For Moddable SDK OS180329 version 9.0.0, consider restricting access to the `fxBeginHost` function in `xsAPI.c` until a patch is available. As a temporary workaround, avoid using the `fxRunDefine` function in `xsRun.c` that calls `fxBeginHost` to minimize the risk of exploitation.