CVE-2017-14749: Jerryscript
High severity, CVSS 7.8. EPSS: 2.1% chance of exploitation in the next 30 days.
JerryScript 1.0 allows remote attackers to cause a denial of service (jmem_heap_alloc_block_internal heap memory corruption) or possibly execute arbitrary code via a crafted .js file, because unrecognized \ characters cause incorrect 0x00 characters in bytecode.literal data.
Affected products
- Jerryscript Jerryscript: version 1.0 only
Published 2017-09-26. Last modified 2026-06-17.