Vulnerability Description
In XS 9.0.0 in Moddable SDK OS180329, there is a heap-based buffer overflow in fxBeginHost in xsAPI.c when called from fxRunDefine in xsRun.c, as demonstrated by crafted JavaScript code to xst.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Moddable | Moddable | os180329 |
| Moddable | Xs | 9.0.0 |
Related Weaknesses (CWE)
References
- https://github.com/Moddable-OpenSource/moddable/issues/235ExploitIssue TrackingThird Party Advisory
- https://github.com/Moddable-OpenSource/moddable/issues/235ExploitIssue TrackingThird Party Advisory
FAQ
What is CVE-2019-16366?
CVE-2019-16366 is a vulnerability with a CVSS score of 9.8 (CRITICAL). In XS 9.0.0 in Moddable SDK OS180329, there is a heap-based buffer overflow in fxBeginHost in xsAPI.c when called from fxRunDefine in xsRun.c, as demonstrated by crafted JavaScript code to xst.
How severe is CVE-2019-16366?
CVE-2019-16366 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-16366?
Check the references section above for vendor advisories and patch information. Affected products include: Moddable Moddable, Moddable Xs.