CVE-2024-42391
Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4.3
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
- EPSS probability
- 0.28%
- CWE
- CWE-823
- Published
- 2024-11-18
- Last modified
- 2026-09-08
Affected products
- Cesanta Mongoose Web Server
Weakness type
Related vulnerabilities
- CVE-2023-33106 — Use of Out-of-range Pointer Offset in Graphics
- CVE-2023-43553 — Use of Out-of-range Pointer Offset in WLAN HOST
- CVE-2023-24855 — Use of Out-of-range Pointer Offset in Modem
- CVE-2023-22388 — Use of Out-of-range Pointer Offset in Multi-mode Call Processor
- CVE-2026-21732 — GPU DDK - libusc OOB write at ConvertSwitchToArrayLookupBP during WebGPU shader compilation
- CVE-2017-11076 — Use of Out-of-range Pointer Offset in Video
- CVE-2025-27059 — Use of Out-of-range Pointer Offset in TZ Firmware
- CVE-2020-6112 — An exploitable code execution vulnerability exists in the JPEG2000 Stripe Decoding functionality of Nitro Software, Inc.