CVE-2024-42386
Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and produce a segmentation fault on the application.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.2
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
- EPSS probability
- 0.38%
- CWE
- CWE-823
- Published
- 2024-11-18
- Last modified
- 2026-09-08
Affected products
- Cesanta Mongoose Web Server
Weakness type
Related vulnerabilities
- CVE-2026-31912 — OOBR in libpcap before 1.10.7
- CVE-2026-45199 — GPU DDK - rgxfw_to_ptr() does not reject FW private data pointers
- CVE-2026-72642 — Use of Out-of-range Pointer Offset in the Elasticsearch Machine Learning Native Inference Process
- CVE-2026-49746 — GPU DDK - Dimension Mismatch and Integer Truncation in PMRDevPhysAddrOSMem
- CVE-2026-49745 — GPU DDK - Unvalidated sHWPerfCtlDMABuf GPU-VA, DMA-write into FW privdata via MMU ctx 0
- CVE-2026-49744 — GPU DDK - Unchecked ui32TracePointer in rgxfw_log_ex()
- CVE-2026-21734 — GPU DDK - libusc OOB write at TreeRemove during WebGPU shader compilation
- CVE-2026-34193 — GPU DDK - Arbitrary write via UFO updates due insufficient pointer validation in rgxfw_to_ptr()