CVE-2016-9108: Artifex Mujs

High severity, CVSS 7.5. EPSS: 2.8% chance of exploitation in the next 30 days.

Integer overflow in the js_regcomp function in regexp.c in Artifex Software, Inc. MuJS before commit b6de34ac6d8bb7dd5461c57940acfbd3ee7fd93e allows attackers to cause a denial of service (application crash) via a crafted regular expression.

Affected products

  • Artifex Mujs: up to and including 2016-10-31
  • Fedoraproject Fedora: version 23 only; version 24 only; version 25 only

Published 2017-02-03. Last modified 2026-06-17.